Security
Where we are, stated plainly.
K3rnel is a pre-launch company in private beta. This page describes how we build and what we practise today — not certifications we have not earned yet.
What we do and do not claim.
- Fail-closed execution: any error, timeout or unresolved check ends a run without acting.
- Signed, replayable certificates for every execution.
- Least-privilege access to internal systems, reviewed when roles change.
- Secrets held in managed secret storage, never in source control.
- Dependency and container scanning on every build.
- Encryption in transit and at rest across our infrastructure.
- A formal SOC 2 Type II readiness programme, ahead of an external audit.
- A published subprocessor list, to accompany general availability.
- A coordinated vulnerability disclosure policy with defined response targets.
- We hold no SOC 2, ISO 27001 or HIPAA attestation today, and we will not imply otherwise.
- We have not completed an independent third-party penetration test.
- We are not offering a public bug bounty yet.
The security argument is the product.
Most of what makes an agent dangerous comes from the same source: the decision about what to do and the act of doing it happen at the same moment, inside a model, with no artefact in between. There is nothing to review because there is nothing fixed to review, and nothing to sign because there was never a stable thing to sign.
K3rnel's answer is structural rather than probabilistic. Because a plan is fixed and inspectable before it runs, checking it is a statement about what will happen rather than a guess about what might. Because execution is deterministic, the record of a run is reproducible instead of merely descriptive.
That shapes our failure modes. The system is built so that the safe outcome is the automatic one: when something is unclear, the action does not happen. We would rather refuse a legitimate request and make you ask again than take an action nobody can account for.
What this website collects.
This site has no accounts, no analytics product, no advertising trackers and no third-party embeds. It sets no cookies of its own.
The only information we receive from it is what you type into the contact form and choose to send us: your name, your email address and your message. That goes to our email so we can reply, and nowhere else. We do not sell it, and we do not add you to a marketing list you did not ask for.
The site is hosted on Vercel, which processes standard request data such as IP address and user agent in order to serve pages and defend against abuse.
Found something? Tell us directly.
If you believe you have found a vulnerability in this site or in K3rnel, email us and say so in the subject line. We will acknowledge you, keep you updated while we investigate, and credit you if you want the credit. We will not threaten you for reporting in good faith.
ammar@k3rnel.ioAsk us the hard questions.
We would rather answer a security review honestly nowthan surprise you with the answer later.