# Kernos — full landing page text (en + zh-CN + SAP page) Generated 2026-09-27 from index.html + zh.html + sap-integration.html. Canonical facts: llms.txt. ===== EN HOME ===== Enterprise AI agent platform Go beyond chat. Agents that act — under governance . Kernos is the open, governed alternative to Palantir: enterprise AI agents grounded in your business ontology, where every action is proposed, approved, audited, and reversible. POLICY AGENT AUDIT Request early access See the governance loop Self-hosted today · Managed SaaS planned Governance loop — every write-side action 01 PROPOSE Agent stages a typed action — objects, fields, rule set attached 02 APPROVE Human quorum decides · segregation of duties enforced in code 03 AUDIT Append-only, bi-temporal trail · replayable by causation chain Action record Object Payment run Rule set Policy engine · pre-approval Approvals 2-of-3 quorum SAP write-back Await authoritative event Status Executed · replayable 253 OpenAPI endpoints 364 Typed schemas 18 Modules, one repo Bi-temporal Full audit trail SAP-native OData · IDoc · BAPI · CDC 1 command Self-host bootstrap The problem Enterprise AI dies in one of two places. Failure mode 1 It can't see your business Chatbots bolted onto documents don't know your objects, your rules, or your SAP transactions. Kernos models your business as a typed ontology — objects, links, actions — so agents reason over the same truth your systems run on. Failure mode 2 Nobody trusts it to act An agent that writes to production without oversight is a liability. Kernos wraps every write-side action in a governance loop: staged proposals, multi-node approval workflows, segregation of duties, and a bi-temporal audit trail that can replay any decision. Platform From ontology to audit: one governed lifecycle. Six stages, one platform — every stage reads and writes the same ontology and the same audit trail. Eighteen modules ship in a single repository, so deployment is one command, not an integration project. 01 MODEL Model your business as a typed ontology Objects, links, actions with bi-temporal versioning. Additive evolution — extend the model without migrations. 02 BUILD Build agents against real objects Agent studio and workshops publish via MCP and signed A2A. Memory carries provenance on columnar storage. 03 APPROVE Humans decide what ships Staged proposals, multi-node approval DAG, segregation of duties — batch decisions and delegation for scale. 04 EXECUTE Act across systems, SAP included Governed runs over OData, IDoc, BAPI, events, and CDC — authoritative events confirm every write. 05 AUDIT Replay any decision Append-only bi-temporal trail with correlation IDs. Causal-chain queries and funnel views built in. 06 IMPROVE Get better with every run Evals, an evolution flywheel, and template packs — all inside your deployment, all reading the same ontology. Governance loop Propose. Approve. Audit. Every time. Where other platforms print "human operators review outputs" as a slogan, Kernos ships it as a mechanism — three frames you can verify in your own deployment. FRAME 01 — PROPOSE Agents stage, never write AI agents produce staged proposals against typed actions, carrying full context: which objects, which fields, which rule set. Write-side actions staged by default Rule engine evaluates policy pre-approval FRAME 02 — APPROVE Humans decide, with teeth Multi-node approval workflows with segregation of duties — initiators cannot approve their own proposals. Four-eye constraint enforced in code APPROVE / REJECT / RETURN / DELEGATE FRAME 03 — AUDIT Replayable, bi-temporal history Every decision lands in an append-only audit trail with correlation IDs, queryable by causation chain. Full-chain causal queries Nothing deleted, everything diffable Deployment Runs where you decide. Your data never needs to leave your perimeter. Start self-hosted today; a managed cloud option is on the roadmap. Available today Self-hosted Docker Compose bootstrap — the full eighteen-module stack on a single machine or your own Kubernetes. ./scripts/bootstrap.sh Available today Private cloud, with us Early-access deployments land in your VPC with our team. Single-tenant by design; your data stays in your instance. Talk to us Planned Managed SaaS Multi-tenant managed cloud opens after our early-access program — not before. We won't ship it half-governed. Join the waitlist Pricing Palantir-grade outcomes. Startup-grade prices. Transparent tiers during early access. Enterprise AI platforms average five figures per month per customer; we think the governed layer should be priced for the teams actually building. Starter $500 /mo 3 agents 10K action tokens/mo Community support Self-hosted license Start with Starter Professional $2,000 /mo 10 agents 100K action tokens/mo Private-cloud deployment assist Template packs included Go Professional Enterprise Custom Unlimited agents Air-gapped / on-prem options SAP landscape integration Committed SLA Contact us FAQ Questions procurement and engineers actually ask. What is Kernos in one sentence? Kernos is an open, self-hostable enterprise AI agent platform that grounds agents in a typed business ontology and wraps every write-side action in an approval-and-audit governance loop — a governable alternative to Palantir Foundry/AIP. How is it different from Dify or n8n? Dify and n8n are excellent horizontal agent/workflow builders; their governance story starts and ends at logs. Kernos is vertical by design: typed ontology modeling, multi-node approval DAGs with segregation of duties, bi-temporal audit, and SAP-grade reconciliation. Use them to prototype flows; use Kernos when an agent must safely touch systems of record. How is it different from Palantir Foundry/AIP? Same architectural DNA — ontology-first, decision-centric — but open and self-hostable, priced for SMBs and platform teams, with your data never leaving your perimeter. Palantir contracts start where most mid-market budgets end; Kernos is the layer you can actually procure. Does it integrate with SAP? Yes — connectors for OData, IDoc, BAPI, events, and CDC, with idempotent retries, dead-letter queues, and three-way reconciliation. Kernos never claims a write succeeded until SAP's authoritative event says so. Can it run air-gapped? Yes. The full stack bootstraps on a single machine via Docker Compose and runs without external services. Model access is pluggable, so on-prem or private endpoints work. Do you train models on our data? No. Kernos does not train foundation models and does not send your data to third parties for training. Model access is pluggable — bring your own endpoints — and memory, provenance, and audit trails stay inside your deployment. Where does my data live when Kernos connects to SAP? In your perimeter. Kernos runs in your environment; SAP credentials and business data stay inside your instance. And no write is claimed until SAP’s authoritative event confirms it. With self-hosting, data sovereignty is an architectural property — not a contract clause. What's on the roadmap? Near term: English documentation site, open-source license finalization, template packs, managed SaaS after the early-access program. This page's "last updated" date is maintained with each release. Ready to see agents act — under governance? Get the bootcamp kit: a working session from zero to a governed agent workflow, on your own machine. Request the bootcamp kit Talk to us ===== ZH-CN HOME ===== 企业 AI Agent 平台 别停在聊天。 让 Agent 动手—— 在治理之下 。 Kernos 是 Palantir 的开放替代:企业 AI Agent 锚定在你的业务本体上,每个动作先提议、再审批、全程留痕、可回放。 POLICY AGENT AUDIT 申请早期接入 看治理闭环 自托管(现已可用)· 托管 SaaS(规划中) 治理闭环——每个写侧动作 01 提议 Agent 暂存类型化动作——对象、字段、规则集随身携带 02 审批 人工法定人数拍板 · 职责分离由代码强制 03 审计 只增双时态留痕 · 按因果链可回放 动作记录 对象 付款运行 规则集 策略引擎 · 审批前求值 审批 3 选 2 法定人数 SAP 回写 待权威事件确认 状态 已执行 · 可回放 253 OpenAPI 端点 364 类型化 Schema 18 模块 · 单仓六带 双时态 全程审计留痕 SAP 原生 OData · IDoc · BAPI · CDC 1 条命令 自托管一键起 问题 企业 AI 死在两个地方。 失败模式一 看不见你的业务 挂在文档上的聊天机器人不懂你的对象、规则和 SAP 事务。Kernos 把业务建模成类型化本体——对象、链接、动作——让 Agent 在和系统同一份事实上推理。 失败模式二 没人敢让它动手 不经监督就写生产系统的 Agent 是一颗雷。Kernos 把每个写侧动作包进治理闭环:暂存提议、多节点审批流、职责分离、双时态审计可回放任一次决策。 平台 从本体到审计:一条受治理的生命周期。 六个阶段,一个平台——每个阶段读写同一份本体、同一条审计链。18 个模块单仓交付,部署是一条命令,不是一个集成项目。 18 个模块在单仓内按六个发布带交付——从本体内核到 AI 层——部署是一条命令,不是一个集成项目。 01 建模 把业务建模成类型化本体 对象、链接、动作,双时态版本管理。加法式演进——扩模型不做迁移。 02 构建 让 Agent 操作真实业务对象 智能体工场经 MCP 与签名 A2A 发布,记忆带出处落在列式存储上。 03 审批 人来决定什么能上线 暂存提议、多节点审批 DAG、职责分离——量大走批量,链长走委托。 04 执行 跨系统动手,SAP 在内 OData、IDoc、BAPI、事件、CDC 上的受治理执行——权威事件确认每笔写入。 05 审计 任一决策都可回放 只增双时态留痕带因果 ID,因果链反查与漏斗视图开箱即用。 06 进化 每次运行都在变强 评测、进化飞轮、模板包——全在你自己的部署里,读的都是同一份本体。 治理闭环 提议。审批。审计。每一次。 别家把「有人工复核」印在口号里,Kernos 把它做成机制——三帧画面,你可以在自己的部署里逐帧验证。 第一帧 · 提议 Agent 只暂存,不直写 AI Agent 对类型化动作产出暂存提议,自带完整上下文:动哪些对象、改哪些字段、套哪套规则。 写侧动作默认暂存 规则引擎在审批前先过策略 第二帧 · 审批 人来拍板,硬约束兜底 多节点审批工作流 + 职责分离——发起人不能批自己的单。 四眼硬约束由代码强制 批准 / 驳回 / 退回 / 委托 第三帧 · 审计 双时态历史,可回放 每个决策落入只增审计链,带因果 ID,可按因果链反查。 全链因果双向反查 不做物理删除,一切可 diff 部署 数据在哪,部署在哪,你说了算。 你的数据无需离开你的边界。今天就能自托管;托管云在路线图上。 现已可用 自托管 Docker Compose 一键起——完整 18 模块栈跑在一台机器或你自己的 Kubernetes 上。 ./scripts/bootstrap.sh 现已可用 私有云 · 我们陪跑 早期接入部署落在客户自己的环境里,我们的团队负责落地。单租户设计;数据不出你的实例。 联系我们 规划中 托管 SaaS 多租户托管云在早期接入计划完成后开放——不会提前。没治理好的东西我们不发。 加入等候名单 定价 Palantir 级的产出,创业公司级的价。 早期接入期透明定价。企业 AI 平台行业均价每月五位数起;我们认为治理这一层应该按真正在用它的团队来定价。 Starter 起步 $500 /月 3 个 Agent 每月 1 万动作 tokens 社区支持 自托管授权 从 Starter 开始 Professional 专业 $2,000 /月 10 个 Agent 每月 10 万动作 tokens 私有云部署陪跑 含模板包 选 Professional Enterprise 定制 定制 Agent 数量不限 air-gapped / 完全离线可选 SAP 全景集成 承诺 SLA 联系销售 常见问题 采购和工程师真正会问的问题。 一句话说清 Kernos 是什么? Kernos 是开放、可自托管的企业 AI Agent 平台:把 Agent 锚定在类型化业务本体上,并把每个写侧动作包进「审批 + 审计」治理闭环——可治理的 Palantir Foundry/AIP 替代品。 和 Dify、n8n 有什么区别? Dify 和 n8n 是优秀的横向 Agent/工作流构建器,它们的治理到日志就结束了。Kernos 是纵向设计:类型化本体建模、带职责分离的多节点审批 DAG、双时态审计、SAP 级对账。用它们做流程原型;当 Agent 要安全触碰记录系统时,用 Kernos。 和 Palantir Foundry/AIP 有什么区别? 同样的架构基因——本体优先、决策中心——但开放且可自托管,按中小企业和平台团队的预算定价,数据永不离开你的边界。Palantir 的合同起点是多数中型预算的终点;Kernos 是你真的买得起的那一层。 能对接 SAP 吗? 能——OData、IDoc、BAPI、事件、CDC 连接器,幂等重试、死信队列、三方对账。在 SAP 的权威事件确认之前,Kernos 绝不宣称写入成功。 看 SAP 集成专页 → 支持完全离线(air-gapped)吗? 支持。全栈经 Docker Compose 在单机起步,不依赖外部服务。模型接入可插拔,本地或私有端点都可用。 你们会用我们的数据训练模型吗? 不会。Kernos 不训练基础模型,也不把你的数据送去第三方训练。模型接入可插拔——用你自己的端点;记忆、出处与审计留痕都留在你的部署内。 Kernos 对接 SAP 时,数据存在哪里? 在你的边界内。Kernos 部署在你自己的环境,SAP 凭证与业务数据不出你的实例;SAP 权威事件确认之前,Kernos 绝不宣称写入成功。自托管让数据主权成为架构属性,而不是合同条款。 路线图上有什么? 近期:英文文档站、开源许可证定稿、模板包、早期接入计划完成后的托管 SaaS。本页「最后更新」时间随每次发布维护。 想看 Agent 在治理之下真正动手? 拿走 Bootcamp 套件:一次工作会话,从零跑通一条受治理的 Agent 工作流,就在你自己的机器上。 申请 Bootcamp 套件 联系演示 ===== EN SAP INTEGRATION ===== SAP integration SAP is the system of record. Kernos is the system of governance. Most tools pipe data between systems and hope. Kernos wraps every SAP write-side action in the governance loop — staged, approved, audited — and never claims success until SAP itself confirms it. Talk to us about SAP Read the three iron laws Standard interfaces: OData · IDoc · BAPI · Events · CDC — no custom ABAP in your core. The three iron laws Boring rules. On purpose. Integration failures destroy trust in AI faster than missing features ever will. Kernos encodes three non-negotiable laws into the runtime — they are not configurable away. Law 01 A command is not a success Kernos dispatches the command, then waits for SAP's authoritative result event. Until that event arrives, the action stays staged or pending — never optimistically marked done. No optimistic write-back status Intermediate states are explicit Law 02 Degrade safely, never bypass If SAP is unreachable, actions queue for recovery or hard-stop at critical control points. The approval loop is never bypassed to keep things moving. Recoverable hold vs strict block, by control point Governance continuity over throughput Law 03 Every write is reconciled Three-way reconciliation compares platform state, SAP state, and field evidence. Discrepancies become tracked items — not silent drift. Idempotent retries with exponential backoff Dead-letter queues, nothing lost Coverage Standard interfaces. Full write path. Kernos connects through standard SAP interface families — read, write, and change-data-capture — and maps external keys to your ontology so agents act on the same objects your business runs on. Read & write OData services Structured reads and governed writes against S/4HANA OData services — schema-aware, typed, and approval-gated on the write path. Documents IDoc Document exchange with status tracking — intermediate states visible, failures land in the dead-letter queue with replay. Functions BAPI Business API calls wrapped as governed actions: staged, approved, executed, reconciled. Events Event streams SAP events land as authoritative confirmations — the signal that turns a staged action into a completed one. Change capture CDC Change data capture keeps your ontology projections current without full-table polling. Identity MDM external-ID mapping External keys map to ontology objects, so "customer 1000123" and your customer object are the same thing — with lineage. Data & trust Your SAP credentials never leave your perimeter. Kernos deploys in your environment. Connection settings, credentials, and business data stay inside your instance; what crosses to us is a support conversation, not your data. Every connection is visible, every action is attributable, and the whole chain is auditable — because it is stored where you control it. Plan an SAP pilot with us See the governance loop