Skip to content
Kernyl

Your data stays in your own cloud.

Kernyl is installed in your cloud, not ours. This page is written for your security review: the architecture, where data goes, and what we can and can't see.

Architecture

Kernyl architecture: Kernyl runs inside your own cloudYour peopleweb, Mac, mobile soonYour SSOGoogle, OIDCYour cloudany region you chooseKernylchat, issues, docs and AI
Kernyl runs entirely inside your own cloud, in the region you choose. People use it in a browser or the Mac app, with a mobile app coming soon, and sign in through your identity provider.

Where your data goes

People open Kernyl in a browser or the Mac app and connect to your installation over HTTPS. They sign in through your identity provider, and sessions expire after inactivity or a maximum age.

Messages, issues, pages and settings are stored in a database in your account, and uploaded files in your account's file storage. Both are encrypted at rest by your cloud, with keys you control.

Kernyl checks its license with us on a regular schedule. That check-in carries the version, a health flag and the number of active and named users. It never includes messages, issues, documents, files or names.

What happens when someone asks Kernyl

  1. A person asks a question, or asks for a summary.
  2. Kernyl checks, at that moment, which channels, issues and pages that person can open.
  3. It retrieves relevant passages from those sources only.
  4. It sends the question and those passages to an AI model in your own cloud.
  5. The answer comes back with numbered sources that link to the originals.

@Kernyl in a channel goes one step further: it only uses content every member of that channel can see. More on how Kernyl AI works.

For your security questionnaire

Short answers you can copy. We'll go deeper on a call.

Deployment model
Installed in your own cloud. We don't operate a hosted version.
Components
Kernyl, its database, file storage and AI models, all managed services in your own cloud.
Data location
Your cloud, in the region you choose.
Data sent to the vendor
License check-ins only: version, a health flag, and active and named user counts.
Vendor access to production
None. We hold no login to your installation; you decide what to share for support.
Authentication
Single sign-on with Google Workspace or OpenID Connect, restricted to your domains.
SAML and SCIM
Not available yet.
Session management
Idle and maximum session lifetimes, a device list for each person, and sign out everywhere for admins.
Audit logging
An audit log of administrative actions.
Encryption in transit
HTTPS between clients and your installation.
Encryption at rest
Your cloud's encryption for the database and file storage, with keys you control.
AI processing
AI models in your own cloud. Permissions checked at question time. Content is not sent to us.
Third-party services
Google, only if you connect Google Calendar or use Google sign-in.
Clients
Web browsers and a Mac desktop app. No mobile apps yet.

FAQ

Is our data used to train AI models?

Not by us: we never receive it. Kernyl calls AI models that run in your own cloud, under your own agreement with your cloud provider.

Who installs and updates Kernyl?

We set it up with your team during the install. Releases and model updates are included in your subscription.

Bring your security team to the demo.