The decision ledger for enterprise AI
Every decision, on the record.
Kernl turns operating policy into deterministic code. Every decision a human or AI agent makes is authorized, signed, and replayable.
An AI agent just refunded $4,000. Which policy authorized it?
For most companies the honest answer is nobody knows. Policy lives in macros, spreadsheets, and someone’s memory. Agents act in milliseconds.
- AGENTS ACT
- AI agents already resolve most support conversations at leading companies. Refunds included.
- ADOPTION COMPOUNDS
- Gartner expects 40% of enterprise apps to embed task-specific agents by the end of 2026.
- THE LAW ARRIVED
- EU AI Act high-risk enforcement began August 2, 2026. Regulators now ask for decision trails, not intentions.
Logs tell you what happened. Not what was allowed.
- 01
Vendor self-attestation.
Your agent platform grades its own homework. A trail signed by the party being audited is testimony, not evidence.
- 02
Prompts as policy.
A system prompt cannot be versioned, diffed, tested, or cited when finance asks why.
- 03
Logs without lineage.
A log line records an outcome. It cannot prove which rule, which version, which authority produced it.
Kernl is the system of record for decisions.
Policy becomes code: typed, versioned, cited to its source. Decisions become ledger entries: signed and append-only. Changes become replays: tested against history first.
Three primitives. No magic.
Everything downstream is a view of these three. Determinism, replay, and the audit trail all fall out of getting them right.
Policy as code
Typed conditions, priorities, and override rules. Every rule cites its source document, byte for byte. No citation, no publish.
Deterministic decision
Same facts, same policy, same answer. Zero LLM calls on the decision path. Ambiguity escalates to a human instead of guessing.
Append-only ledger
Every decision becomes a signed, hash-chained entry. Change one byte and every hash after it breaks.
A policy, in full
Same facts. Same policy. Same answer.
Probabilistic systems are impressive and unaccountable. Kernl keeps the model where it belongs: proposing drafts and explaining outcomes. Never deciding.
The evaluator is differential-tested against an independent Rust implementation. Determinism here is not a promise. It is a test suite.
Ship policy like you ship code.
Every change replays against your golden cases and decision history before it can publish. See which past decisions flip. Acknowledge the blast radius, or don’t ship.
Append-only. Hash-chained. Signed.
Append-only is enforced by the database, not by promise. Bundles are Ed25519-signed at publish. Anyone can verify the chain without trusting us. That is the point.
- #4819decisionrefund.annual_full_14dprev ⟶ e5f2…b1
- #4820decisiondiscount.startup_20prev ⟶ 77ac…04
- #4821decisionrefund.high_valueprev ⟶ c19d…7a
- #4822adjudicationhuman ruling · links #4821prev ⟶ 9b12…dc
INFRASTRUCTURE
Built like infrastructure, because it is.
- Deterministic core
- Zero LLM calls on the decision path.
- Append-only ledger
- Enforced by a database trigger, not convention.
- Ed25519 signatures
- Verify any bundle independently of Kernl.
- Replay-gated publishing
- No policy change ships untested.
- Evidence-cited policy
- Every rule traces to its source document.
- API-first
- REST, tenant-isolated, role-scoped keys.
DESIGN PARTNER PROGRAM
Five partners. Ninety days. Zero workflow change.
We shadow your existing refund and credit decisions, read-only. We encode your policies for you. You get the Leakage Report: what inconsistent decisions actually cost.
You get
- Your policies encoded as cited, versioned code
- The Leakage Report on your own decision history
- A replay run on a real policy change
- An audit-trail pack your finance team can hold
We need
- A read-only export from your help desk
- One 45-minute call a week
- Honest feedback
Free for the ninety days. If the report doesn’t find more than the year-one price, we’ll tell you so ourselves.
Questions a careful buyer asks.
Is Kernl another AI agent?
No. Kernl is the neutral layer that decides and records. Your agents, human or AI, ask Kernl what policy allows, then act. Kernl never executes anything.
Do we have to change our support workflow?
No. Design partnerships run in shadow mode: read-only ingestion of decisions you already make. Your team changes nothing while the ledger builds.
What does deterministic actually mean here?
Same facts plus same policy version always produce the same decision. No model on the decision path. Ambiguous cases escalate to humans instead of guessing.
Is our data safe with a young company?
Shadow mode is read-only. A data processing agreement comes standard, deletion on request, and every bundle is cryptographically verifiable without trusting us.
The ledger starts when you do.
Every decision before Kernl is unprovable history. Every decision after is on the record.