DATA & ISOLATION

Will AI leak your business data?

Shadow AI already shows what happens when nobody designs for isolation: 68% of employees use personal accounts for work AI, and over half of them paste in sensitive information. Kernos is the opposite design — agents that run inside your boundary, on your models, writing to your database.

68%of employees use personal AI accounts for work
57%of those admit pasting sensitive info into them
22%of files uploaded to GenAI tools contain sensitive data
0copies of your data on a provider you don't control (self-hosted)
The problem nobody approved

Shadow AI is already pasting your data somewhere.

Sources: TELUS Digital AI at Work 2025 survey; Harmonic Security 2025 data exposure report; LayerX browser-extension telemetry. Third-party industry research — not Kernos customer data. The exposure is happening whether or not a sanctioned AI tool exists.

68% / 57%

Personal accounts, sensitive inputs

TELUS Digital's 2025 survey: 68% of employees work with public GenAI tools using personal accounts (ChatGPT, Copilot, Gemini) — and 57% of them acknowledge entering sensitive information.

22% / 4.4%

Files and prompts carry secrets

Harmonic Security's analysis of real usage: 22% of files uploaded to AI tools contain sensitive data; 4.37% of prompts include sensitive content. One prompt is one exfiltration event.

77% / 22%

The clipboard is the highway

LayerX telemetry: 77% of employees paste data into GenAI platforms, and 22% of that pasted data includes PII or PCI data. Copy-paste bypasses every network control you configured.

The Kernos answer

Four boundaries you control.

Kernos is architected so the parts that hold your data can run entirely inside your perimeter. Each boundary is a deployment decision, not a promise.

Boundary 1

The loop runs on your hardware

Self-hosted: the whole orchestration stack — agents, rules engine, approvals, audit — runs where you put it: your Kubernetes, your VPC, your bare metal. Single-command deploy by design. Managed SaaS is planned if you'd rather not operate it.

Boundary 2

Models are pluggable

Bring any OpenAI-compatible endpoint: Anthropic, Azure OpenAI, or local/private models. With local models a self-hosted deployment is fully air-gapped — prompts and documents never cross your network edge.

Boundary 3

Memory and audit stay in your DB

Agent memory (bi-temporal, provenance-tracked) and the append-only audit chain run against the Postgres you provision. No provider-side copy, no telemetry dependency — deleting the instance deletes the history.

Boundary 4

Credentials never leave the instance

System credentials (e.g. SAP RFC/ODATA logons) are stored inside your deployment's secret store and used in-loop only. Agents reference credentials by alias; values are never placed in prompts or sent to model endpoints.

Egress control

Bounded, inspectable, honest.

Where agents can send requests is a configuration surface you own — stated plainly, including its limits.

Allowlist

Host allowlist

Outbound hosts (model endpoints, integrations) are bounded by a configurable allowlist. Anything not on the list doesn't get a connection.

Optional gate

Egress authentication gate

For stricter environments, an optional egress gate requires signed approval before external calls. Enable it per deployment; it is off by default — your call, based on your threat model.

Verify it

Don't take our word

The deployment topology is documented and inspectable: run it self-hosted, watch the network edges, read the audit chain. Trust comes from verification, not badges.

FAQ

Security questions we get.

Does my business data leave my environment when Kernos agents run?

Not if you self-host or run the private-cloud deployment: the orchestration loop, agent memory, audit chain, and business ontology all run inside your boundary. The only external calls are the model endpoints you configure — and with local models, none leave at all.

Which AI models can Kernos use?

Pluggable: any OpenAI-compatible endpoint — Anthropic, Azure OpenAI, or local/private models. Self-hosted deployments can run fully air-gapped with local models.

Where does agent memory and audit history live?

In your database. Memory extraction, the bi-temporal memory store, and the append-only audit chain run against the Postgres instance you provision. There is no provider-side copy.

How do you control where agents can send requests?

Outbound requests are bounded by a configurable host allowlist; an optional egress authentication gate adds signed approval for external calls. These are configuration options — review them against your own threat model before production.

Can your audit evidence satisfy EU AI Act or SOX requirements?

We don't sell compliance, and certifications aren't claimed here. What the platform produces is provable trust: an append-only, replayable audit chain — cryptographically verifiable evidence that answers the three questions every framework asks — who authorized this action, what data the agent accessed, and what reasoning led to it. Map that evidence to your own obligations (EU AI Act logging, SOX controls, internal policy); the chain lives in your database, exportable and inspectable.

Are you SOC 2 or ISO certified?

Not yet, and we won't put a badge we don't hold on this page. Instead: documented deployment topology, inspectable data-flow boundaries, and hands-on access to verify everything in your own environment.

Run the security review on your terms.

We'll walk your security team through the deployment topology, the egress surface, and the credential path — then hand them a self-hosted instance to verify. No trust required up front.