Skip to main content
Kernel
Self-hosted RAG

PrivateAIforthedocumentsthat

Chat with your contracts, policies, and research. Not a byte leaves your network. Deploy on your hardware. Audit every answer.

On-premises or your VPCNo data leaves your perimeterEvery answer shows its sources

The trade-off

The trade-off you shouldn't have to make

Cloud AI tools want your documents. Building your own RAG stack takes months. Kernel gives you a third option: an enterprise-grade private platform you control, deployable in a single afternoon.

Data leaves your network

ChatGPT / Copilot / Glean
Yes, vendor cloud
In-house build
No
Kernel
No

Time to deploy

ChatGPT / Copilot / Glean
Weeks of legal review
In-house build
Months of engineering
Kernel
An afternoon

Audit log + RBAC + lifecycle

ChatGPT / Copilot / Glean
Vendor's policy
In-house build
Build it
Kernel
Built in

Pick which model runs each stage

ChatGPT / Copilot / Glean
Single vendor model
In-house build
DIY
Kernel
Yes, admin UI

“Why this answer?” trace

ChatGPT / Copilot / Glean
No
In-house build
DIY
Kernel
Yes

Where your data lives

ChatGPT / Copilot / Glean
Vendor's cloud
In-house build
You decide
Kernel
You decide

Built for the buyer who has to say "yes" to compliance

Kernel was built for the team lead who's tired of telling people "we can't use AI for that."

Your data stays in your VPC. Your audit team sees every retrieval. Your users get GPT-class chat over the documents they actually work with.

Your data, your perimeter.

Runs on your own server, your EC2, or a single-tenant VPC we manage. No telemetry. No “we may use your prompts” clause.

Per-stage model routing.

Route every pipeline stage independently. Fast local model for the router, mid-size for expansion, frontier only for the final answer.

Every answer shows its work.

One click reveals the route, the chunks, the model, and whether the grounding check passed. Self-RAG flags low confidence when it can't verify.

What's inside

Production-ready out of the box.

Not a demo.

the retrieval layer

Hybrid retrieval, one router.

Vector search, knowledge graph, and structured SQL fused by an intent router. Each question gets the retrieval path that actually suits it.

RAPTOR summarisation

Hierarchical clustering so broad questions get synthesis and pointed ones get exact passages.

CRAG + Self-RAG

Chunks scored for relevance. Answers verified against context and retried on failure.

Workspaces + governance

draftpendingapproved

RBAC across owner, admin, manager, user, auditor.

Audit + backup

Tamper-evident audit chain. Encrypted backups covering vectors, graph, and metadata.

Cloud sync, your terms

Pull from Dropbox, Drive, OneDrive. Originals stay on your storage; nothing routes through us.

ClamAV scanningPrompt-injection guardField-level encryptionTLS by defaultSSO ready

How it works

How a question flows through Kernel

A user asks one question. Behind the scenes, Kernel runs a pipeline of small, specialised steps. Most run on local models. Only the final answer ever needs a frontier model, and only if you choose.

Router

local

Expansion

local

HyDE

local

Retrieval

hybrid

Rerank

local

Generation

your choice

Grounding check

local

localhybrid (vector + graph + sql)your choice (local or cloud)

Each stage is independently configurable. Run the whole thing locally for zero data egress, or route specific stages through cloud models for higher answer quality. Cloud routing is available as an add-on.

Three ways to run Kernel

Choose where it lives. Pricing is shaped to your scale, your model mix, and whether you want us to operate it for you.

Self-hosted

Run Kernel on your own infrastructure. You manage upgrades, you keep the keys. Best for teams that already operate a Linux + Docker stack and want maximum control.

Let's talk
Most popular

Self-hosted with support

Same deployment, with a support SLA, audit-log export, SSO/SAML, and assistance with upgrades. Best for compliance-driven mid-market firms.

Let's talk

Managed private cloud

We run Kernel for you on dedicated single-tenant infrastructure inside your preferred cloud region. You point a domain at it and your team starts using it. Best for regulated organisations who want the outcome without the operations.

Let's talk

Cloud-model routing (Claude, GPT, Gemini for any pipeline stage) is available as an add-on. Talk to us about your mix.

See it work

A 20-minute walkthrough on your own documents will tell you more than any datasheet. We'll set up a temporary private instance, ingest a sample of your corpus, and let you ask real questions live.

Request a demo

Trusted by teams that need to say "yes" to compliance

BlueSkyCDCLiveStyleSCS

Ready to talk?

Tell us a bit about your team, your documents, and what compliance constraints you're working under. We'll show you exactly what Kernel would look like for you.

Let's talk