Use cases
Find the StreamKernel scenario that already looks like your environment.
Different industries, one recurring problem: a decision executes, something acts on it, and nobody can prove afterwards which policy applied, which model ran, or what the decision saw. Each scenario below governs that moment. None of them require replacing the platform that produces the decision.
Vertical scenarios
Buyer language first, runtime mechanics underneath.
Each scenario maps a familiar operational job onto the same execution boundary: admission, policy decision, permitted model or action, provenance, evidence, routing, and governed delivery.
Financial Services
Fraud, AML, sanctions, credit, risk, compliance, and platform teams that need enforceable policy and reconstructable evidence around decisions their existing engines already make. StreamKernel governs the execution path; it does not replace the decision engine.
Credit / fraud / AML decision event
Bind credit, fraud, and AML evidence to a single governed decision record carrying the final decision, route, case priority, domain reason codes, thresholds, policy version, model version, and provenance — so the decision can be reconstructed later without stitching three systems together.
AML / sanctions screening evidence
Run screening at execution time behind mTLS, OIDC, and fail-closed OPA, and emit sanctions-hit status, typology labels, case priority, reason codes, and SHA-256 provenance on every record before it reaches a case system.
AI-assisted investigation workflows
Control which model or agent may act on an alert, keep sensitive customer and transaction fields from reaching the wrong model, and preserve what the model saw and produced as part of the case record.
Pre-trade and order-flow governance
Apply policy to enriched order flow before it reaches an execution venue, and attach provenance labels that support the audit trail rather than reconstructing it afterwards.
Model risk and decision reconstruction
Give model risk and second-line reviewers a per-decision artifact with model identity, policy identity, transform chain, and audit-chain reference, instead of a reconstruction exercise across logs and warehouses.
Healthcare
Privacy, security, AI governance, clinical, and device data teams that need PHI-aware inference and governed routing inside their own runtime boundary.
PHI-aware governed AI pipeline
Detect sensitive fields, emit redaction and tokenization evidence, add local AI labels, and route synthetic healthcare-shaped events with provenance.
Lab result AI classification
Classify HL7/FHIR event streams with in-JVM ONNX inference without sending PHI to an external inference endpoint.
Clinical alert enrichment
Score patient telemetry against anomaly models in the event path before routing enriched alerts to EMR or alerting sinks.
Medical device data pipelines
Govern ingestion from device event sources with model versioning, MLflow-backed promotion, and rollback when clinical models change.
National Defense
Disconnected, restricted, and edge environments where telemetry and sensor streams need local inference, policy denial paths, route labels, and record-level provenance without a call out to a hosted control plane.
Air-gapped defense telemetry governance
Evaluate synthetic operational telemetry with guardrail decisions, intended routes, allowed and denied sinks, reason codes, sensitivity scores, and provenance.
UAV / edge telemetry enrichment
Run real-time inference on sensor telemetry in air-gapped edge environments with single-JAR deployment and no cloud dependency.
Satellite downlink processing
Handle burst ingestion with backpressure management, ONNX scoring, and policy-controlled multi-sink delivery. Cross-domain transfer between security domains is the accredited guard's responsibility, not StreamKernel's.
SIGINT / ISR stream processing
Enforce policy before delivery, using OPA-based deny paths to keep sensitive records off the wrong sinks.
Public Sector
Public-sector AI, compliance, security, lakehouse, and data engineering teams that need inference requests to leave with evidence envelopes.
Inference provenance for FedRAMP-track systems
Attach model registry identity, run ID, input and output hashes, routing decisions, policy versions, consumer contracts, and provenance headers to every request.
Benefits / permit / public health triage
Package synthetic agency requests for regulated triage workflows where audit teams need the decision context without reconstructing it from logs.
Production posture mapping for an agency assessment
Map the same use case toward SASL_SSL/OIDC Kafka, fail-closed OPA, authenticated Prometheus, retention tiers, non-root deployment, and NetworkPolicy controls. StreamKernel holds no FedRAMP authorization; this supports the customer's own assessment.
Agentic AI
AI platform, security, compliance, enterprise architecture, and risk teams that need governed event boundaries around tool activity.
Governed agent tool audit
Normalize agent tool calls, classify risk, emit policy decisions, route labels, audit records, optional escalation details, and provenance before actions affect systems.
High-impact action review
Route customer-record access, refund approvals, patient-record access, workflow execution, and notification actions to operational, alert, review, analytics, or DLQ paths.
Local MCP agent control
Expose status, config validation, dependency health, benchmark evidence, audit verification, and dry-run mutation tools through an opt-in local MCP surface.
Enterprise Data Platform
Platform and data engineering teams modernizing event movement, pre-ingest AI, observability intake, model operations, and multi-destination fan-out.
Pulsar -> Kafka migration
Swap sources without rewriting transform or sink logic, keeping the same pipeline config while the transport changes.
Pre-ingest AI enrichment
Score and label records before they land in the lakehouse, with MongoDB Vector, Delta Lake, and Snowflake delivery in one runtime.
PostgreSQL pgvector RAG path
Land text, embeddings, metadata, and lineage into a self-managed Postgres vector table for buyers already standardizing on PostgreSQL.
OpenTelemetry programmable intake
Accept OTLP logs, metrics, or traces and keep policy, redaction, enrichment, routing, and DLQ behavior available through the pipeline contract.
MLflow live rollback evidence
Promote a fresh model during a benchmark row, watch health degrade deterministically, roll back to the prior approved version, and capture the control log.
Real-time feature generation
Compute features on live event streams and deliver them to a feature store alongside the raw record.
Multi-destination fan-out
Run one pipeline with consistent DLQ, retry, and metrics behavior across Kafka, MongoDB, Postgres, Delta Lake, and Snowflake.
Buyer triggers
When StreamKernel should enter the conversation.
The strongest fit is a team trying to score, govern, and deliver sensitive event streams without adding another fragile chain of services.
- Credit, fraud, AML, sanctions, pre-trade, or reporting flows need model scores and policy evidence before records leave controlled finance systems.
- Clinical, HL7/FHIR, claim, note, or device streams need PHI-aware inference without routing sensitive records to unmanaged model endpoints.
- Defense telemetry must keep inference, policy, route labels, and provenance inside disconnected or restricted environments with no call out to a hosted control plane.
- Public-sector inference programs need model identity, input/output hashes, retention posture, and audit evidence attached to every request.
- Agentic AI programs need tool calls captured as governed events before actions affect enterprise systems.
- Enterprise migration, OpenTelemetry, pgvector, lakehouse, or MCP control-plane teams need one path with consistent DLQ, retry, metrics, and sink behavior.
Proof-first review
Pair any use case with a sample receipt.
The Governed Event Receipt turns a use-case story into an inspectable proof envelope for one event: policy decision, route, provenance, model context, and audit-chain reference.
Commercial path
Bring the scenario closest to your environment.
A short architecture review maps one decision path to the governed execution boundary, and says plainly which controls are enforceable today and which need pilot work.