Ship analytics into the tenant's environment.
Your customers keep their data in their own environments; the agent runs there and serves the analytics in place. You ship intelligence without taking custody of tenant records.
Renewal is a security review the ledger answers.
One agent deploys per tenant boundary, and the product serves each tenant inside it.
Onboard
The agent deploys into the tenant's environment: container, VM or system service, their choice.
K·02 · one agent per tenant boundary
Serve
Dashboards, queries and forecasts compute in-tenant, over the tenant's own tables.
Assure
Each tenant reads its own ledger. Their security team sees every read your product made.
the ledger is tenant-facing
Expand
Usage and churn views by tier, computed without pooling tenant records anywhere.
Renew
The security review repeats at renewal. The ledger answers it before the meeting starts.
no custody of tenant records · each tenant reads its own ledger
What tenants expect the product to answer.
Scores with reasons over usage signals, computed where each tenant's data lives.
K·03 · classification
Ranked attention across accounts, explained per item, without a central copy of anyone's data.
K·03 · attention queue
The tenant's own question. Their ledger answers it: question, rule, reader, timestamp.
K·02 · audit
Where the agent sits.
KEZEL · DEPLOYMENT · SAAS PROVIDERS
- agent
- in each tenant environment
- components
- K·02 orchestration + K·03 analytics
- custody
- no tenant records held by the provider
- audit
- per-tenant ledger, tenant-readable
For a SaaS provider the boundary being protected is the customer's, and the ledger becomes part of the product.
Show us the data you are not allowed to move.
That's the workload we should discuss. Start with a demo on our sample boundary; move to a pilot in yours once your security review clears it.