Skip to content

The decision ledger for enterprise AI

Every decision, on the record.

Kernl turns operating policy into deterministic code. Every decision a human or AI agent makes is authorized, signed, and replayable.

An AI agent just refunded $4,000. Which policy authorized it?

For most companies the honest answer is nobody knows. Policy lives in macros, spreadsheets, and someone’s memory. Agents act in milliseconds.

AGENTS ACT
AI agents already resolve most support conversations at leading companies. Refunds included.
ADOPTION COMPOUNDS
Gartner expects 40% of enterprise apps to embed task-specific agents by the end of 2026.
THE LAW ARRIVED
EU AI Act high-risk enforcement began August 2, 2026. Regulators now ask for decision trails, not intentions.

Logs tell you what happened. Not what was allowed.

  1. 01

    Vendor self-attestation.

    Your agent platform grades its own homework. A trail signed by the party being audited is testimony, not evidence.

  2. 02

    Prompts as policy.

    A system prompt cannot be versioned, diffed, tested, or cited when finance asks why.

  3. 03

    Logs without lineage.

    A log line records an outcome. It cannot prove which rule, which version, which authority produced it.

Kernl is the system of record for decisions.

Policy becomes code: typed, versioned, cited to its source. Decisions become ledger entries: signed and append-only. Changes become replays: tested against history first.

Three primitives. No magic.

Everything downstream is a view of these three. Determinism, replay, and the audit trail all fall out of getting them right.

01

Policy as code

Typed conditions, priorities, and override rules. Every rule cites its source document, byte for byte. No citation, no publish.

02

Deterministic decision

Same facts, same policy, same answer. Zero LLM calls on the decision path. Ambiguity escalates to a human instead of guessing.

03

Append-only ledger

Every decision becomes a signed, hash-chained entry. Change one byte and every hash after it breaks.

A policy, in full

Same facts. Same policy. Same answer.

Probabilistic systems are impressive and unaccountable. Kernl keeps the model where it belongs: proposing drafts and explaining outcomes. Never deciding.

The evaluator is differential-tested against an independent Rust implementation. Determinism here is not a promise. It is a test suite.

Ship policy like you ship code.

Every change replays against your golden cases and decision history before it can publish. See which past decisions flip. Acknowledge the blast radius, or don’t ship.

replaysample replay
refund.annual_full_14d
-days_since_purchase <= 14
+days_since_purchase <= 7
0
decisions replayed
0
flips
0
golden failures
locked
publish gate
Publish unlocks only when a human acknowledges the blast radius.

Append-only. Hash-chained. Signed.

Append-only is enforced by the database, not by promise. Bundles are Ed25519-signed at publish. Anyone can verify the chain without trusting us. That is the point.

INFRASTRUCTURE

Built like infrastructure, because it is.

Deterministic core
Zero LLM calls on the decision path.
Append-only ledger
Enforced by a database trigger, not convention.
Ed25519 signatures
Verify any bundle independently of Kernl.
Replay-gated publishing
No policy change ships untested.
Evidence-cited policy
Every rule traces to its source document.
API-first
REST, tenant-isolated, role-scoped keys.

DESIGN PARTNER PROGRAM

Five partners. Ninety days. Zero workflow change.

We shadow your existing refund and credit decisions, read-only. We encode your policies for you. You get the Leakage Report: what inconsistent decisions actually cost.

You get

  • Your policies encoded as cited, versioned code
  • The Leakage Report on your own decision history
  • A replay run on a real policy change
  • An audit-trail pack your finance team can hold

We need

  • A read-only export from your help desk
  • One 45-minute call a week
  • Honest feedback

Free for the ninety days. If the report doesn’t find more than the year-one price, we’ll tell you so ourselves.

Questions a careful buyer asks.

Is Kernl another AI agent?

No. Kernl is the neutral layer that decides and records. Your agents, human or AI, ask Kernl what policy allows, then act. Kernl never executes anything.

Do we have to change our support workflow?

No. Design partnerships run in shadow mode: read-only ingestion of decisions you already make. Your team changes nothing while the ledger builds.

What does deterministic actually mean here?

Same facts plus same policy version always produce the same decision. No model on the decision path. Ambiguous cases escalate to humans instead of guessing.

Is our data safe with a young company?

Shadow mode is read-only. A data processing agreement comes standard, deletion on request, and every bundle is cryptographically verifiable without trusting us.

The ledger starts when you do.

Every decision before Kernl is unprovable history. Every decision after is on the record.