What you can do

Everything it takes to own the AI you're renting.

Point your OpenAI and Anthropic calls at Kolm - no SDK rewrite. Kolm captures the behavior you already use, compiles it into a signed .kolm model in one portable file, and runs it on your own hardware. Here is exactly what you can capture, compile, deploy, and verify offline.

capture what you already use compile to one signed file run on your own hardware verify it yourself
REG-08 capability-matrix.kolm TOL ±0.2 · v3.3
Domains
8lifecycle
Channels
17families
Ingress
12modes
Export
10modes
In spec

What you get out of the box

17sources you can capture from
12ways to bring traffic in
10ways to take your proof out
1signed file you own

01 · The path

From your live calls to a model you own, in eight moves.

Each stage takes the stage before it as input and hands its output to the next, so you can trace one record end to end. Below, follow a single capture - one production redaction call - as it moves through all eight stages.

LIFECYCLE / OUTPUT FEEDS NEXT INPUTlive
Capture

Bring in what you use

Point your traffic at Kolm; it records the real call - prompt, tool calls, outcome.

12408calls recordedfeeds → 1 raw record with source + timestamp
Classify

Know what you captured

Tag each record's source, schema, tenant, environment, and sensitivity.

PIIfield flaggedfeeds → a labeled record the rules can act on
Set rules

Decide what is allowed

Redaction, retention, allowed providers, export boundaries, budgets.

redacton PII fieldfeeds → a governed record, safe to reuse
Evaluate

Catch regressions first

Build evals and drift checks; lock a regression set; block bad releases.

98%pass, 1 heldfeeds → a locked eval gate the compile must clear
Compile

Get one portable file

Bundle model, recipe, evals, and receipt into one signed artifact.

142MB .kolmfeeds → a signed artifact ready to run
Run

Run on the hardware you have

Ship to the smallest runtime that fits - laptop, edge, server.

71ms p50, laptopfeeds → a live endpoint plus its receipt
Verify

Prove what you shipped

Each release carries a receipt, checksum, version, and eval result.

Ed25519verifiedfeeds → a receipt anyone can check offline
Operate

Stay in control after launch

Audit events, connector health, cost controls, exports, owners.

100%changes loggedfeeds → back to Capture as drift is found
END TO END one record, traced through eight stages verified

01b · Each stage, in detail

What each of the eight stages actually does.

Every step does real work and leaves proof behind - so you can trace exactly how your traffic became a signed .kolm model on your own hardware. See the end-to-end picture on the compiler overview, the file itself in the .kolm spec, and where it runs in runtime targets.

Reg · 1 capture

Bring in what you already use

Point your traffic at Kolm and it captures the real behavior: provider logs, gateway events, app traces, agent tool calls, labels, failures, warehouse rows, CI events, and custom API records.

Reg · 2 classify

Know exactly what you captured

See the source, schema, tenant, environment, sensitivity, retention window, and owner of every record - and catch anything with an unknown shape before it moves on.

Reg · 3 set the rules

Decide what is allowed before it runs

Set redaction, retention, and purge rules, pick which providers and models you allow, draw export boundaries, scope keys, and cap budgets and rate limits.

Reg · 4 evaluate

Catch regressions before your users do

Build evals, threshold checks, and drift checks, route edge cases to human review, lock a regression set, and block any release that does not pass.

Reg · 5 compile

Get one portable file you own

Compile your behavior into a signed artifact - model, recipe, evals, and receipt - with source hash, output hash, approval state, and the runtime it fits.

Reg · 6 run

Run it on the hardware you have

Ship to a laptop, your private cloud, the edge, a server, or a managed host - the smallest runtime that fits, with the limits shown up front.

Reg · 7 verify

Prove what you shipped

Every release carries a verifier receipt, checksum, artifact and policy version, eval result, and runtime target - so anyone can check it without trusting us.

Reg · 8 operate

Stay in control after launch

Keep audit events, admin analytics, connector health, cost and usage controls, exports, owner assignments, and incident-ready logs at hand.

02 · Coverage

Capture from the tools you already use.

Bring in your traffic from the sources you already run, take your proof out to the systems your team already trusts - with each one's state shown plainly.

17 sources you can capture fromsources
Provider logs · application events 2
Gateway records · agent tool calls 2
Observability spans · eval data · labels 3
Analytics · warehouses · CI/CD · repos 4
Support · GRC · files · runtime telemetry 4
Cost events · customer-system actions 2
12 ways to bring traffic incontrol
REST · GraphQL · gRPC 3
Webhooks · streaming · batch files 3
Object storage · warehouse queries 2
Queues · browser events 2
Local CLI · custom adapter manifests 2
10 ways to take your proof outexports
Signed artifact · verifier receipt signed
Eval report · evidence bundle 2
JSON API · warehouse export 2
Webhook · CI status 2
SIEM/GRC event · admin analytics 2
8 steps, traffic to owned modelplatform
Register source · capture event 1-2
Classify schema · apply redaction 3-4
Build eval · lock regression set 5-6
Compile artifact · export proof 7-8

03 · Every capability, provable

Nothing ships without proof you can check.

Every action you take leaves a trail you can follow end to end - what went in, what controlled it, what came out, and the proof that ties it together.

  • Input · what data came in, which tenant owns it, which environment it ran in, and where it came from
  • Control · the policy, role, retention, redaction, eval, budget, and release gate that ran on it
  • Output · the artifact, report, receipt, export, runtime target, or audit event you got back
  • Proof · the checksum, receipt ID, version, route, and test that let anyone verify the claim
one action, end to endverifiable
input · tenant + environment retained
control · policy + eval gate versioned
output · artifact + receipt emitted
proof · checksum + object version verifiable

04 · Built for the whole team

Controls your team can delegate, audit, and revoke.

When the AI bill and the trust story are yours to own, you need controls you can hand out, watch, export, and pull back - without a ticket queue.

Reg · identity

Hand out access, take it back

Create, scope, rotate, expire, and revoke API keys and service accounts by tenant, workspace, project, environment, and connector.

Reg · source

Know who owns every source

See source health, connector owner, allowed source type, ingress mode, retention window, redaction rule, and export scope at a glance.

Reg · policy

Set the rules for every call

Pick which providers and models you allow, route traffic, cap budgets and rate limits, draw data-use boundaries, and set fallback behavior.

Reg · export

Send your proof where it lives

Push to webhooks, your warehouse, SIEM/GRC events, CI status, admin analytics, evidence bundles, and verifier receipts.

Reg · trust

An audit trail for every change

Every write leaves an audit event, every claim ships with proof, and anything still in progress is shown plainly - never hidden.

05 · Who it is for

Whatever you own, you get the controls for it.

Everyone who has to sign off gets exactly what they need to say yes - the controls and the proof, in one place.

Reg · connect

Platform engineering

You wire it up and keep it running. Sources, keys, environments, quotas, connector health, ingress modes, and runtime targets.

Reg · evaluate

AI & ML teams

You make sure the behavior holds. Traces, labels, evals, regression sets, drift checks, compile runs, and release gates.

Reg · govern

Security

You draw the boundaries. Retention, redaction, unknown-schema handling, provider policy, access scope, audit events, and purge workflows.

Reg · export

Compliance

You need proof you can hand over. Receipts, evidence bundles, versions, audit trail, status, and anything still in progress, stated plainly.

Reg · build

Developers

You want to ship fast. API docs, OpenAPI, examples, test payloads, a CLI path, clear errors, and verification you can repeat locally.

Ready to own what you're renting?

Start with one capture. Own the model it makes.

Pick one source, one policy, one eval gate. Capture it, compile it into one signed .kolm model, and run it on your own hardware - then do it for everything else.