Product

An execution-time governance and evidence layer.

StreamKernel sits between your existing event, AI, and model infrastructure and the systems that act on its output. It enforces policy while the decision executes, controls what model or action is permitted, preserves provenance, binds evidence to the execution, and emits a Governed Event Receipt — without replacing the platforms that produce the decision.

What it is

Operational event execution where the runtime owns the hard parts.

StreamKernel is built for pipelines where policy enforcement, in-process enrichment, DLQ routing, metrics, provenance, cost control, local control-plane access, and multi-destination delivery need to execute together.

What it is not

Not another Kafka client, smaller Spark, connector framework, or model-serving wrapper.

The product category is a governed event execution boundary, not a replacement for transport, analytics engines, or standalone model serving.

Core capabilities

One runtime surface for the pieces that usually become custom infrastructure.

Source pluginsPolicy pluginsTransformer chainsONNX/DJL enrichmentMLflow registry integrationLive model promotionAutomated rollback guardCache-aware processingSink pluginsPostgres sinksPostgres pgvector sinksDLQ routingPrometheus metrics exportOpenTelemetry exportOpenTelemetry source intakeEmbedded MCP control planemTLS + OPA policy pathBenchmark runnerProvenance and audit headersCommercial plugin/IP boundary

Where it sits

Beside your platforms, not in place of them.

StreamKernel is not a smaller Flink, a Kafka replacement, a connector framework, or a model-serving stack. It occupies the execution boundary those systems leave open: the moment a decision is made and something is about to act on it.

Platform What it is strong at What StreamKernel adds
Kafka / Confluent Durable streaming, replay, schemas, governance, broad platform operations. Execution-time policy, provenance, and cost control on top of or beside streaming topics.
Spark / Flink Distributed analytics, SQL, windows, joins, keyed state, feature pipelines. Per-event policy enforcement, inference, routing, provenance, action audit, and sink delivery.
LangChain / LangGraph / LangSmith Agent application design, stateful workflows, tool orchestration, tracing, evals. A framework-neutral governed execution boundary around tool calls, model escalation, and action records.
MLflow Model registry, aliases, versions, experiment and lifecycle metadata. Live no-restart model swaps, guarded rollback behavior, and event-level model execution evidence.
MongoDB / Weaviate / pgvector / InfluxDB Document, vector, time-series, query, and retrieval layers. Governed embedding, policy enforcement, provenance, route, retry, DLQ, and sink contract before the write.
Fraud, AML, defense, SIEM, cloud AI platforms Systems of record, case management, managed model access, mission analytics, security operations. An inspectable event evidence lane that can feed, protect, or complement those systems.

Use those platforms where they are strongest. StreamKernel's benchmarks are single-node measurements of a compact execution boundary; they are not evidence that it outperforms a distributed cluster at that cluster's job, and they are not presented as such.

Capability boundary

Specific claims are easier to trust.

StreamKernel is deliberately explicit about what is proven in the current build, what belongs in a scoped pilot, and what is not claimed yet.

Proven today

  • Inline fail-closed authorization gates on the event-execution path.
  • Embedded MCP control plane with 22 registered tools: 16 read-only tools and 6 guarded mutations in the current codebase.
  • Per-event provenance headers for pipeline, run, transform, config, model, and policy context where configured.
  • Tamper-evident MCP audit hash chains when hash chaining is enabled.
  • CostProof-style routing, budget caps, circuit-breaker behavior, and spend audit records in the frontier-agentic benchmark lane.
  • Air-gap, on-prem, and embedded deployment posture by design with no required SaaS control plane.
  • Reproducible in-house benchmark rows with matrix files, pipeline configs, logs, metrics snapshots, and metadata.

Scoped pilot work

  • Integration into a customer's event topology, policy source, identity boundary, and downstream systems.
  • Customer-specific MCP allowlists, authorization policy, audit retention, and case-system integration.
  • Customer-specific evidence schemas, audit exports, and sink-side verification.
  • Multi-node tuning and customer-volume validation against real event shapes and real sinks.
  • Enclave-specific packaging, deployment hardening, and operational runbooks.

Not claimed yet

  • Certification, accreditation, FedRAMP authorization, SCIF approval, or NIPRNet authorization without the customer's formal assessment process.
  • Fully autonomous multi-agent handoff governance at production scale.
  • Prebuilt regulatory policy-pack libraries for EU AI Act, NIST, ISO, or agency-specific control mappings out of the box.
  • Cryptographic human-attestation binding in the hot path; AuthorityProof remains a separate sidecar proof lane.
  • Production enterprise references at scale; StreamKernel is early-stage and pre-revenue.

Use the second and third columns as public claim hygiene: pilot work should be scoped as pilot work, and certification should not be implied before the buyer's formal assessment.

Runtime boundary

One JVM. One pipeline config. One benchmark envelope.

StreamKernel collapses the operational glue around event execution, AI enrichment, policy enforcement, delivery, and evidence into a single runtime.

Execution-time enforcement

Policy, provenance, and cost controls stay attached to the executing event, not buried in one-off services.

Commercial AI path

Protected AI implementation, production packaging, redistribution, support, and negotiated rights live behind direct engagement.

Benchmarkable operations

Runtime evidence includes benchmark matrices, effective settings, logs, GC output, Prometheus/OpenTelemetry metrics, MCP audit JSONL, and replay metadata. The current governed financial-services reference is 99,102 records/sec on an Apple M5 Pro, sustained across 3 ten-minute runs at a declared 100K/s source rate with mTLS, Keycloak OIDC, fail-closed OPA, and SHA-256 provenance on every record (CV 0.827%; end-to-end batch-ack P50 114.8-126.8 ms).

See every benchmark with its hardware, date, and measurement boundary

Governed Event Receipt

A portable single-event proof artifact gives buyers a concrete envelope for policy decision, route, provenance, model context, and audit-chain reference.

Inspect the sample receipt

Commercial path

Built for teams that need policy enforcement where execution happens.

Bring a streaming, AI enrichment, OEM, or regulated delivery scenario and review the governed execution path with StreamKernel.