THE PLATFORM

Eighteen modules. One repository. One command.

Most agent platforms are a demo with a waitlist. Kernos is the whole lifecycle — model, build, approve, execute, audit, improve — as one deployable system. Here's what's actually inside, in engineering numbers instead of adjectives.

253OpenAPI endpoints in one contract surface
364typed schemas behind them
18modules in a single repository
1command from zero to running stack
The lifecycle

Six stages. Agents ship through all of them.

Every agent action travels the same path — from a typed definition of your business to an audited, improved loop. The stages are enforced by the platform, not by convention.

01 MODEL

Model your business as data

Objects, relations, and rules become typed ontology definitions with bi-temporal versioning. Evolution is additive — new types version forward without breaking running agents or audit history.

02 BUILD

Build agents against contracts

An agent studio defines chatbots and function agents over MCP tools. Agent-to-agent calls are cryptographically signed, and every action clears runtime policy enforcement before it executes. Memory is extracted with provenance into a columnar store you host.

03 APPROVE

Approve before anything ships

Write-side actions stage as proposals evaluated against your rules. Multi-node approval DAGs enforce segregation of duties; batch decisions and delegation keep humans in the loop at volume.

04 EXECUTE

Execute against real systems

Governed runs reach SAP (OData, IDoc, BAPI), databases, and event streams — with CDC. Execution is confirmed authoritative, so "done" means the system of record changed.

05 AUDIT

Audit everything, forever

An append-only, bi-temporal audit chain records every action with correlation IDs. Replay any decision causally — what the agent saw, which rule fired, who approved.

06 IMPROVE

Improve without regressions

Evals run workflows against known scenarios before changes ship. Template packs turn one team's working pattern into the next team's starting point.

What you own

Built to be verified, not trusted.

Self-hosting isn't an enterprise tier here — it's the default. The parts that hold your data are the parts you run.

Your database

Postgres, open formats

The ontology, memory store, and audit chain run on the Postgres instance you provision, backed by a self-contained columnar memory format. Delete the instance and the data is gone — there is no provider-side copy.

Your models

Any endpoint, including local

Bring any OpenAI-compatible endpoint — Anthropic, Azure OpenAI, or a local model on your own GPUs. With local models, the deployment is fully air-gapped.

Your perimeter

Single machine to start

Docker Compose bootstraps the full stack on one machine — no Kubernetes required for a pilot. Scale by module when the workload asks for it.

Open core

Inspect before you commit

The core platform is open to inspect and verify — contract surface, audit chain, rule engine. License finalization is in progress and on the roadmap; your data is never the lock.

FAQ

Architecture questions we get.

What exactly runs when I self-host Kernos?

The full governance stack: typed ontology, agent runtime with memory and audit, rules engine, approval workflow, and module UIs — bootstrapped with Docker Compose against a Postgres you provision. No external service is required for the loop to run.

Is the business ontology customizable?

Yes — it is the point. Objects, relations, and rules are typed definitions you model. Evolution is additive: new types version forward without breaking running agents, audit history, or workflows.

How does data flow between the modules?

Through the shared ontology and the shared audit chain — not point-to-point integrations. A proposal staged by an agent, approved, executed against SAP, and replayed in audit is the same object moving through one contract surface.

What does "open core" mean for Kernos?

The core platform is open to inspect and verify — contract surface, audit chain, rule engine. License finalization is in progress; we won't publish a license file before it's real. Your data is never the lock: it lives in your Postgres, in open formats.

Can Kernos run air-gapped?

Yes. The loop, memory, audit, and rules run inside your perimeter; models are pluggable — point them at a local endpoint and no request leaves your network. The only reason to open a connection is a model or integration you chose.

Run it before you believe any of this.

Early access starts with a self-hosted pilot on your stack: your Postgres, your model endpoints, one workflow that writes to a system of record. We'll be on the call, not in the loop.