Drop-in proxy - no SDK rewrite

Four steps from your API calls to a model you own.

Point your live OpenAI and Anthropic traffic at Kolm. It captures the behavior you already use, compiles it into a signed model in one portable file, and runs it on your own hardware. Capture, compile, sign, deploy - no rewrite to get here, no lock-in once you have it.

Point your existing calls · 12 ways to capture them Compile a signed model in one file Ed25519-signed · verify it yourself Run it on the hardware you already have
REG-04 claims-redactor.kolm TOL ±0.2 · v3.3
Latency
388ms
Artifact
142MB
Targets
5runtimes ranked
Signature
sha256:a1f0…
In spec

Capture from the tools you use. Run on the hardware you have.

12ways to capture your calls
5runtimes to run it on
Ed25519signed · verify it yourself
10ways to export your proof

Capture → compile → compose → deploy

Four verbs, eight readouts, one model you own.

The four-verb loop expands into eight concrete steps, each with the kind of readout you actually see. The numbers below come from one worked example: a redaction model compiled from one week of claims-redactor traffic. Every step leaves you something you can open, check, and keep.

COMPILE LOOP / claims-redactor.kolmlive
Capture

Point your calls in

Drop Kolm in front of your OpenAI- or Anthropic-compatible calls; traffic streams in with secrets stripped before write.

12,400calls in, 1 week
Classify

Sort what came in

Calls are grouped by request shape so you can see what your agents actually do, and what does not fit a known pattern.

3 schemas1 unknown flagged
Rules

Set the policy once

Choose redaction, retention, and which providers are allowed. The rules then follow every captured call.

redact PIIallow GPT-4 only
Evaluate

Replay and grade

A held-back sample is rerun against your evals; anything that drops below the bar is flagged before it can ship.

99% passrerun 100, 1 regression
Compile

Pack one file

Model, recipe, evals, hashes and a verifier receipt compile into one portable .kolm you own.

one .kolm142 MB
Run

Fit the hardware

The same file is ranked across runtimes by cost and latency, then runs on the smallest target that fits.

laptop / edgeserver / phone
Verify

Seal and check

The file is hashed and signed; anyone can re-hash it and check the signature without contacting Kolm.

hash + signatureEd25519
Operate

Deploy and export

Promote, roll back, and export the proof straight into the systems your team already runs.

deploy+ export proof
OUTCOME one portable .kolm verified

Go deeper: the platform overview, the runtime targets the model can deploy to, the .kolm spec, the capture integrations, and pricing.

Capture

Point your existing calls at Kolm. No rewrite.

Keep your SDK as it is. Set your boundary once - workspace, project, environment, source, owner and retention - and every call after that flows in with its rules attached. The behavior you already pay for becomes the model you'll own.

There are twelve ways in, and they sort into four buckets. Whether you speak MCP (the Model Context Protocol)MCP is the Model Context Protocol, a standard way for an agent to call out to tools and data sources., A2A (agent-to-agent)A2A is agent-to-agent messaging, where one agent hands work to another over a shared protocol., or emit OTEL (OpenTelemetry traces)OTEL is OpenTelemetry, the open standard for traces and metrics that most observability stacks already produce., the same boundary and rules apply.

  • Drop-in proxy · keep your provider keys in one vault
  • Secrets stripped before anything is written to disk
  • Set retention, budget and provider rules once · they follow every call
INGRESS / FOUR BUCKETSlive
01Real-time

Live agent traffic

For calls you make right now and want captured as they happen.

  • REST
  • GraphQL
  • gRPC
  • streaming
02Batch

History in bulk

For backfilling behavior you already logged or stored.

  • batch
  • object storage
  • warehouse
03Observability

Signals you already emit

For traffic that already shows up in your traces and events.

  • OTEL
  • webhooks
  • queues
04Custom

Your own path in

For anything bespoke, scripted from a terminal or wired by hand.

  • browser
  • CLI
  • adapters
TWELVE WAYS IN one boundary, one ruleset applied
capture · stream.kolmlive

Compile & compose

Buy the model once. Run it forever.

Your evals decide what ships - human labels, a failure taxonomy, protected slices, drift checks and regression replay. What passes compiles into one .kolm file: the model, recipes, examples, evals, hashes and a verifier receipt. One portable artifact you own and can move anywhere.

  • Reproducible build · content-addressed receipts
  • Nothing ships until your evals pass · replay must not degrade
  • Open the file - every layer is yours to inspect
Inside a .kolmexploded view

Deploy

Run it on the laptop you have, the cloud you trust.

Pick the smallest runtime that fits, with the real limits shown for each - not a marketing promise. Receipts, manifests, eval reports, event streams, log drains, warehouse exports and webhook callbacks all stay useful outside the UI, in the systems your team already runs.

  • Detects your device · ranks targets by cost and latency
  • One file, many targets · hosted or run it yourself
  • Rollback, receipts and 10 export modes included
runtime · claims-redactor.kolmfit

API Control Center

Capture, compile, and ship from one place.

Take one source all the way to a signed model you own - without losing the rules or the proof along the way. Capture, control, improve, release: the whole path is in front of you, and every step leaves you something you can keep.

Reg · capture

Connect your source

Set the source, owner, environment and connector, plus how to handle the data Kolm can't read - once, up front.

Reg · control

Set the rules once

Choose redaction, retention, which providers are allowed, export destinations, budget, approvals and per-tenant cache isolation.

Reg · improve

Ship only what passes

Cluster failures, add labels, build protected regression slices, and hold a model back the moment replay degrades.

Reg · release

Own it and prove it

Compile target receipts, generate runtime recipes, and export the proof straight into the systems your team already runs.

Where Kolm fits

Keep your stack. Kolm turns its traffic into a model you own.

Your gateways still route, your workflow tools still orchestrate, your pipelines still move data, your eval tools still score, and your runtimes still run. Kolm does the one thing none of them do: turn the behavior they carry into a signed, portable model you can run anywhere.

Reg · gateway

Your provider gateways and routing

Keep them routing exactly as they do; Kolm turns the calls they carry into model inputs.

source + route

Reg · workflow

Your workflow and approval tools

Keep your triggers and approvals; Kolm sends receipts and callbacks right back into them.

approval + callback

Reg · pipeline

Your pipelines, streams and warehouses

Keep moving data as you do; Kolm binds policy, lineage and export manifests to what you move.

lineage

Reg · trust

Your inventory, SIEM and assurance tools

Keep them current with signed receipts, logs and verifiable proof - not screenshots.

evidence

Run one capture. Own the model it makes.

Start with one namespace: point your calls at Kolm, set your rules, capture real behavior, keep what passes your evals, compile a signed model, and run it on your own hardware. Ready to own what you're renting?