# Kiro Security on Mac: Monitor Its Network Connections with FireAI > Kiro is an AWS agentic IDE. Read its documented permission model and data handling, then watch its Mac network connections with FireAI and block a first-ever destination. FireAI Security & Research Team (HisnLabs) · Published 2026-10-04 Canonical: https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai Kiro is an AI development environment from Amazon Web Services. It plans work from specifications, runs an agent that edits files and executes commands, and reaches model services over the network. People searching "is Kiro safe" or "Kiro network access" usually want two answers: what the agent is permitted to do, and where the data goes. Both are partly documented by the vendor, and this article collects what is documented before showing how to watch the connections on a Mac with FireAI. ## What Kiro is and who makes it The Kiro documentation describes it as "an AI-powered development environment that helps you build software from prototype to production", available as an IDE, a CLI, on the web, on mobile (preview) and as Kiro Crew, an autonomous agent variant ([Kiro docs](https://kiro.dev/docs/)). The privacy and security page states that "Kiro is an AWS application" ([Privacy and security](https://kiro.dev/docs/privacy-and-security/)). Project settings live in a `.kiro/` folder and sync across surfaces. ## How the agent is permitted to act Kiro documents a capability-based permission system: capabilities such as `fs_read`, `shell` and `web_fetch`, each with an effect of deny, ask or allow, resolved so that "deny > ask > allow" and a deny rule always wins. Rules are kept in YAML files, at user scope in `~/.kiro/settings/permissions.yaml` and at workspace scope under `~/.kiro/workspace-roots/` ([Permissions](https://kiro.dev/docs/permissions/)). In the IDE, autonomy is chosen under Settings, Agent, Agent Autonomy. Autopilot lets the agent proceed with allowed operations silently, and Supervised asks before any action. Until you trust a workspace, the documentation says Kiro asks before every shell command starts, even when a saved or broad rule would allow it, so that a configuration shipped inside a repository cannot bypass approval. > **Note:** A `web_fetch` capability governs fetches the agent makes as a tool. Other traffic, such as the IDE talking to its own services, or a command the agent runs that opens a connection, is a separate matter that these permissions do not describe. ## Data handling documented by the vendor - The data-protection page says communication between customers and Kiro, and between Kiro and its downstream dependencies, is protected with TLS 1.2 or higher, and that data is encrypted at rest with AWS Key Management Service. - Kiro may process content across multiple AWS regions to improve performance. For free and individual users, content is stored in US East (N. Virginia). Kiro may store questions, responses and additional context such as code and metadata about requests ([Data protection](https://kiro.dev/docs/privacy-and-security/data-protection/)). - The FAQ states that Kiro does not collect telemetry from Pro, Pro+, Pro Max or Power users who sign in through AWS IAM Identity Center or an external identity provider, and that content from free-tier or social-login users may be used for service improvement unless they opt out ([FAQ](https://kiro.dev/faq/)). - The FAQ lists a mix of models, including Claude, GPT and open-weight options. The data-protection page mentions Amazon Bedrock. The pages cited do not publish a list of network domains, so this article names none. ## Watching Kiro with FireAI FireAI is a firewall for macOS that runs on your Mac. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature recognises 19 AI agents, Kiro among them, and identifies Kiro by the app it runs from. FireAI then learns where that app normally connects. For every recognised agent it works the same way, using only metadata (host names and byte counts); FireAI never reads the payload of a connection. 1. For the first 3 days FireAI learns the destinations Kiro normally contacts, grouped by domain: api.anthropic.com becomes anthropic.com. Nothing is flagged during this learning period. 2. After that, a destination outside the learned baseline is flagged for review in Suggestions, in the AI agents card and in Quick Review. Swipe left to block, or right for "It's fine". 3. An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB. ## Set up monitoring for Kiro, step by step 1. Install and open FireAI, then use Kiro as you normally would for a few days so the 3-day learning period has real traffic to learn from. 2. Open Suggestions and look for the AI agents card. Flags from agents also appear in Quick Review, the card stack you swipe through. 3. If you use Kiro's CLI, check in the AI agents card whether its connections appear under Kiro; FireAI documents recognition of the app, and this article did not verify the CLI. 4. To keep the agent to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of being flagged. Your own allow rules still win, and DNS and your local network are never blocked. 5. When something is blocked, the AI agents card offers Allow and Keep blocked. Allow adds the destination to the baseline; Keep blocked creates a block rule, so the destination stays blocked in every mode. 6. For a precise rule, open Rules and click Add rule: choose the app, then Allow or block, then a website, a domain with its subdomains, an IP address or a range, and how long it lasts. 7. To understand a single connection, open Threats and use Investigate, or choose Investigate from a line on the World map. The page shows a risk score, the reasons behind it and what FireAI saw. > **Note:** The Agent profile mode needs FireAI 1.0.3 or later, and the 19-agent list needs 1.0.4. Version 1.0.2 flags new destinations but does not block them. ## Limits - FireAI cannot see prompts, the contents of tools, file access such as ~/.ssh, or skills. TLS hides the payload, and FireAI is not inside Kiro. - FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac. - During the 3-day learning period nothing is flagged, and in the Agent profile mode nothing is blocked while an agent is still learning. Upload spikes are flagged, never blocked. - Agents matched by app, path or script name are labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer's signature. - Child processes that exit very quickly may be missed, and they are matched by path, not by signature. The full feature description is on the [Agent profile documentation page](https://hisnlabs.com/en/docs/agent-profile). > Kiro decides what the agent may do. FireAI watches where your Mac connects while it does it. [Download FireAI for Mac](https://hisnlabs.com/en/download) Other agents in this series: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai). The catch-all guide for every other agent is [Every other AI agent on your Mac](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). ## How FireAI and HisnLabs fit in Kiro's permissions govern what the agent may do. FireAI shows where it connects and can block a new destination. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [Kiro documentation](https://kiro.dev/docs/) - [Kiro documentation: Permissions](https://kiro.dev/docs/permissions/) - [Kiro documentation: Privacy and security](https://kiro.dev/docs/privacy-and-security/) - [Kiro documentation: Data protection](https://kiro.dev/docs/privacy-and-security/data-protection/) - [Kiro FAQ](https://kiro.dev/faq/) - [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile) - [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules) - [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes) - [FireAI docs: Answer your first connection prompt](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt) - [FireAI docs: Investigate a connection](https://hisnlabs.com/en/docs/investigate-a-connection)