Shadow AI already shows what happens when nobody designs for isolation: 68% of employees use personal accounts for work AI, and over half of them paste in sensitive information. Kernos is the opposite design — agents that run inside your boundary, on your models, writing to your database.
Sources: TELUS Digital AI at Work 2025 survey; Harmonic Security 2025 data exposure report; LayerX browser-extension telemetry. Third-party industry research — not Kernos customer data. The exposure is happening whether or not a sanctioned AI tool exists.
TELUS Digital's 2025 survey: 68% of employees work with public GenAI tools using personal accounts (ChatGPT, Copilot, Gemini) — and 57% of them acknowledge entering sensitive information.
Harmonic Security's analysis of real usage: 22% of files uploaded to AI tools contain sensitive data; 4.37% of prompts include sensitive content. One prompt is one exfiltration event.
LayerX telemetry: 77% of employees paste data into GenAI platforms, and 22% of that pasted data includes PII or PCI data. Copy-paste bypasses every network control you configured.
Kernos is architected so the parts that hold your data can run entirely inside your perimeter. Each boundary is a deployment decision, not a promise.
Self-hosted: the whole orchestration stack — agents, rules engine, approvals, audit — runs where you put it: your Kubernetes, your VPC, your bare metal. Single-command deploy by design. Managed SaaS is planned if you'd rather not operate it.
Bring any OpenAI-compatible endpoint: Anthropic, Azure OpenAI, or local/private models. With local models a self-hosted deployment is fully air-gapped — prompts and documents never cross your network edge.
Agent memory (bi-temporal, provenance-tracked) and the append-only audit chain run against the Postgres you provision. No provider-side copy, no telemetry dependency — deleting the instance deletes the history.
System credentials (e.g. SAP RFC/ODATA logons) are stored inside your deployment's secret store and used in-loop only. Agents reference credentials by alias; values are never placed in prompts or sent to model endpoints.
Where agents can send requests is a configuration surface you own — stated plainly, including its limits.
Outbound hosts (model endpoints, integrations) are bounded by a configurable allowlist. Anything not on the list doesn't get a connection.
For stricter environments, an optional egress gate requires signed approval before external calls. Enable it per deployment; it is off by default — your call, based on your threat model.
The deployment topology is documented and inspectable: run it self-hosted, watch the network edges, read the audit chain. Trust comes from verification, not badges.
Not if you self-host or run the private-cloud deployment: the orchestration loop, agent memory, audit chain, and business ontology all run inside your boundary. The only external calls are the model endpoints you configure — and with local models, none leave at all.
Pluggable: any OpenAI-compatible endpoint — Anthropic, Azure OpenAI, or local/private models. Self-hosted deployments can run fully air-gapped with local models.
In your database. Memory extraction, the bi-temporal memory store, and the append-only audit chain run against the Postgres instance you provision. There is no provider-side copy.
Outbound requests are bounded by a configurable host allowlist; an optional egress authentication gate adds signed approval for external calls. These are configuration options — review them against your own threat model before production.
We don't sell compliance, and certifications aren't claimed here. What the platform produces is provable trust: an append-only, replayable audit chain — cryptographically verifiable evidence that answers the three questions every framework asks — who authorized this action, what data the agent accessed, and what reasoning led to it. Map that evidence to your own obligations (EU AI Act logging, SOX controls, internal policy); the chain lives in your database, exportable and inspectable.
Not yet, and we won't put a badge we don't hold on this page. Instead: documented deployment topology, inspectable data-flow boundaries, and hands-on access to verify everything in your own environment.
We'll walk your security team through the deployment topology, the egress surface, and the credential path — then hand them a self-hosted instance to verify. No trust required up front.