Skip to content

The assurance layer for AI execution

Stop debugging your agent.
Compile it.

K3rnel is governance software for AI agents that touch money, records and infrastructure. Operations and risk teams use it to set the rules an agent must satisfy, block anything that does not, and produce a signed, replayable record of every action taken.

Private beta · Apache-2.0 open core · Cloud, VPC or on-premise

01The product

A console for everything your agents do.

Operations and risk teams watch runs, write the policies those runs are checked against, and pull the signed record of any action after the fact.

K3rnel
NBNorthwind Bank · Production

Monitor

OverviewRunsCertificates

Govern

PoliciesApprovalsAudit log

Workspace

MembersSettings
PNPriya NairRisk & Controls

Northwind Bank · Production

Overview

Assurance posture across every automated workflow.

Last 7 daysExport report

Runs certified

18,420

+12.4% · vs last week

Certified rate

97.3%

+0.6 pts · vs last week

Actions refused

312

+38 · none reached production

Median run time

0.9s

−7.2% · vs last week

Runs over time
Last 14 days
This week
Workflows in production24
Policies enforced61
Approvals pending3
Certificates issued18,420
Runs awaiting review5

Every certified run is replayable for 7 years.

Recent runs
1–6 of 18,420
WorkflowBusiness unitOutcomeStartedTime
process_refund@3Northwind BankCertified14:22:071.9s
claims_intake@7Meridian HealthRunning14:21:54—
reply_router@2Acme RetailRefused14:20:310.4s
update_address@2Northwind BankCertified14:19:020.4s
issue_credit@1Acme RetailNeeds approval14:18:120.3s
disburse_payout@4Northwind BankCertified14:16:472.4s
Every run that touched a customer record this week, and how each one ended.Illustrative interface · sample data
02Where it is used

Built for the work nobody wants an agent improvising on.

The pattern is always the same: a task that is repetitive enough to automate, and consequential enough that someone will eventually ask what happened.

Financial services

Refunds and billing adjustments

The situation
Support agents handle thousands of refund requests a week. Automating them means letting software move money.
What K3rnel does
Each refund runs against approval limits, payee checks and business-hours rules before a cent moves. Anything above the limit stops for a named approver.
What you can show afterwards
Show an auditor exactly which refunds were issued, under which limit, approved by whom.

Healthcare and insurance

Claims and document intake

The situation
Intake reads untrusted documents from outside the organisation and writes structured records into internal systems.
What K3rnel does
The workflow can only write the fields it was approved to write. Anything a document tries to trigger beyond that is refused, not sanitised and hoped for.
What you can show afterwards
Demonstrate that a document could not have caused an action outside its approved scope.

Customer operations

Actions on customer accounts

The situation
Agents update addresses, cancel orders, issue credits and close tickets — real writes to real records.
What K3rnel does
Every action is checked against the policies for that account tier, and the run stops rather than partially completing when something is unclear.
What you can show afterwards
Answer 'why did this change' with a signed record instead of a log search.

Internal platform

Provisioning and internal ops

The situation
Automating access grants, environment provisioning and configuration changes means giving software real privileges.
What K3rnel does
Privileged operations run only from a plan that was reviewed and approved, with limits on scope and blast radius enforced ahead of execution.
What you can show afterwards
Hand your security team a replayable record of every privileged action taken on their behalf.
03Capabilities

What is in the product.

Policy controls

Write limits, scopes, approvers and time windows once. They are enforced on every run — there is no path that skips them.

Human approval gates

Route anything above a threshold to a named person or team. The run holds rather than proceeding and being reversed later.

Signed certificates

Every run ends with a signed record of the workflow, its version, the decision reached and the actions taken.

Deterministic replay

Re-execute any past run and get the same result, so an incident review shows what happened instead of estimating it.

Audit export

Export runs, decisions and certificates over any date range for auditors, regulators or a customer's security team.

Roles and permissions

Scope who can author workflows, who can change policy and who can approve. Changes to policy are themselves recorded.

SSO and directory sync

SAML and OIDC single sign-on with directory-based provisioning, so access follows the systems you already run.

Deployment options

Managed cloud, your own VPC, or fully on-premise and air-gapped, for workloads that cannot leave your network.

Framework agnostic

Keep the agent framework and models you already use. K3rnel sits between what you built and the systems it acts on.

04How it works

Three steps, and a receipt.

The creative, risky work happens once — before anything touches your systems. What runs afterwards is ordinary, reviewable software.

  1. 01

    Compile

    A model reads your intent once, offline, and produces a fixed plan you can open and read. It is a document, not a conversation — the same input yields the same plan, and the plan is what ships.

  2. 02

    Verify

    Before a single action is taken, the plan is checked against your policies and constraints. Anything that cannot be shown to hold is refused outright rather than attempted and rolled back.

  3. 03

    Execute

    Only the plan that passed runs, and it runs deterministically. Every execution ends by writing a signed certificate recording exactly what was approved and what happened.

Certificate
Plan
process_refund@3
Version hash
sha256:9f3c…a17b
Issued
2026-06-10 14:22:07 UTC
Signature
Ed25519
Certificate
cert_8f31…
CertifiedVerification complete
Illustrative interface · sample data
05The problem

Capability outran assurance.

Authority delegatedTime

Prompt an agent, watch it work, and the demo is genuinely impressive. Put it in front of a customer's money and the question changes shape entirely. Not can it do this, but what exactly will it do, who approved that, and what happens the day it is wrong.

The industry's answer so far has been to watch more closely. Log every step, score every output, add a guardrail model to check the first model, and escalate when confidence drops. All of it is inspection after the fact — a way of noticing that something went wrong slightly faster than a customer would have.

Inspection cannot produce a guarantee. If the decision about what an agent may do is made in the same breath as the doing, there is no earlier moment to point at and no artefact to review. Nothing can be signed, because there was never a fixed thing to sign.

So move the decision. Let the model do its thinking once, up front, and commit the result to something concrete enough to be read, checked and approved. Then let ordinary software carry it out. The creativity stays; the uncertainty leaves the runtime.

06Where it sits

Between your agents and everything they can touch.

K3rnel is not a framework you rebuild on top of, and not a model you swap in. It is a layer your existing agents call through — so the systems on the far side only ever see verified, attributable actions.

  1. Your agents and applications

    Whatever you already build with. K3rnel does not ask you to change how your agents are written.

  2. K3rnel — compile, verify, execute

    Intent is fixed into a plan, the plan is checked, and only what passed is carried out.

  3. Signed certificate and replay log

    Every run produces a durable record: what was approved, what ran, and the result.

  4. Your systems of record

    Databases, payment rails, ticketing, internal APIs — reached only through actions that were verified first.

07Questions

The things people ask first.

No. K3rnel sits between what you already built and the systems it acts on. Your agents keep their framework, their prompts and their tools.

What changes is the boundary: instead of an agent reaching your database directly, it reaches it through a plan that was verified first.

Not on the path that decides whether something is allowed to happen. The model does its work up front, when the plan is compiled.

That is the whole point. A run that depends on a model responding correctly under load, in the moment, is a run you cannot make promises about.

It is refused. K3rnel fails closed: an error, a timeout, an unclear result and a genuine policy violation all end the same way, with the action not taken.

Refusals are recorded as first-class outcomes with a reason attached, so a rejected run is something you can investigate rather than something you have to reconstruct.

The plan that ran, its version, when it ran, the decision that was reached, and a signature over all of it.

It is designed to be useful to somebody who was not there and does not trust you — an auditor, a regulator, a customer's security team.

The ability to re-run a past execution and get the same result, rather than an approximation of it.

In practice that is the difference between explaining an incident and arguing about it. You can show what happened instead of describing what probably happened.

Private beta. We are working with a small number of design partners running real workloads rather than opening a self-serve signup.

If your agents are close to touching something that matters, we would like to hear what you are trying to put into production.

08Principles

What we refuse to compromise on.

Fail closed, always

Uncertainty is not a reason to proceed carefully. It is a reason to stop. Errors, timeouts and ambiguous results all resolve to the action not being taken — there is no configuration that makes the risky outcome the default.

Nothing executes unproven

There is no path where a plan runs because it looked fine, or because the check was slow, or because someone needed it shipped today. The verification step is not advisory and cannot be turned off for convenience.

Every run is replayable

An execution you cannot reproduce is a story, not a record. Runs are deterministic and signed so that months later, to someone who was not there, the evidence still holds up.

Put an agent into production you can defend.

We are working with a small number of teams whose agents are about totouch something that matters. If that is you, get in touch.