KEZEL® by DBTEZ · The Platform

Real-time answers inside your firewall.

KEZEL orchestrates analytics and AI inside your approved environment. Raw records and results stay in place; people and systems reach the intelligence through policy-based access.

01Zero Trust Orchestration (ZTO)

How a question becomes an answer, in four moves.

Zero Trust Orchestration replaces trust-based data handling with metadata-driven instructions, executed directly inside your environment.

01

Deploy inside the boundary

A lightweight Data Streamer runs in your environment (on-prem, your cloud, or hybrid) and connects to approved sources. It ships as a Docker or Kubernetes container, a VM, or a system service.

02

Orchestrate with metadata

The control plane works from schema and context metadata, user intent and policy. It generates encrypted instructions. Raw records never travel upward.

03

Compute where data lives

SQL, transformation and ML execute next to your systems. Every action is verified against policy; nothing operates implicitly.

04

Access results under policy

Results remain in-boundary. Dashboards, predictions, alerts and APIs reach them through policy-based access, with a complete audit trail of who saw what, when, and against which sources.

KEZEL control planemetadata · intent · policyinstruction generatorvault & cryptoNO RAW DATA ACCESSCUSTOMER-APPROVED ENVIRONMENTENCRYPTEDINSTRUCTIONSStreaming Agentlocal SQL · transformation · MLDatabases & applicationsraw records never leavePolicy gateverification · masking · access policyDashboards & APIsread under policyCUSTOMER USERSPOLICY-BASED ACCESSRESULTS REMAIN INSIDECOMPLETE AUDIT TRAIL OF ORCHESTRATION ACTIVITY
02The moving parts

Six components. One boundary rule.

Every component exists to keep one promise: raw sensitive records remain inside the approved execution boundary, and every crossing is explicit and auditable.

ZTO-01

Metadata Engine

Captures schema definitions and contextual metadata from source systems.

ZTO-02

Instruction Generator

Builds orchestration instructions from metadata, user intent and policy.

ZTO-03

Vault & Crypto Services

Manages cryptographic protection of instructions and configuration.

ZTO-04

Streaming Agent

Runs SQL, data and ML operations inside the customer environment.

ZTO-05

Orchestration Controller

Manages instruction lifecycle and dispatch across environments.

ZTO-06

Monitoring & Audit Engine

Records orchestration activity for traceability and compliance.

Transport

TLS 1.3

Encryption

AES-256

Secrets

Vault-based key management

Attestation

SOC 2 Type II attested

Audit

Complete trail of orchestration activity

Access

Least-privilege, policy-bound

Deploys on-premises, in your cloud, or hybrid: Docker or Kubernetes containers, virtual machines, or system services. Connects to Snowflake, BigQuery, Redshift, Salesforce, HubSpot, Zendesk and custom systems through standards-based connectors.

03What changed

The end of the speed-or-control tradeoff.

Traditional stacks made you choose: keep everything locked down, or copy data into someone else's platform. KEZEL is built for the case both assumptions fail.

Traditional on-premSaaS analyticsKEZEL
Raw data stays in placeYesNo: copied or uploadedYes: execution moves instead
Real-time querying~Often delayedYesYes: live on your systems
Exposure surfaceLow, but rigidExpanded: third-party pipelinesReduced: no raw-data movement
Setup & maintenanceHighLowLow: lightweight agent only
Planning & forecasting~Manual and limited~Prebuilt, not adaptableBuilt in, scenario-driven
AI & natural-language queryingNot nativeOften includedNative, schema-aware
Compliance controlFullShared responsibilityYou own the boundary lines
Trust modelInternal ITVendor-managedOrg-owned, agent-enforced
04Introduced at Bengaluru Tech Summit 2025

KEZEL Insights Studio

A command centre for real-time decisions.

Insights Studio replaces fragmented tools with one decision workspace for modelling trade-offs and simulating what-ifs. Everything runs against the same in-boundary architecture as the rest of KEZEL.

How much?

Regression Engine

Optimize strategy through simulation on live, in-boundary data.

Which one?

Classification Engine

Predict and prevent risk: surface the accounts, claims or events that need attention first.

When?

Time Series Engine

Forecast with context: demand, capacity and cash, timed to the decisions they feed.

secQR™ · operational trust, powered by KEZEL

Every scan is a policy decision.

secQR turns QR interactions into governed, auditable trust events: it evaluates who is acting, what the code represents and what should happen next. It detects and challenges fraudulent scan attempts in real time, and extends the in-boundary philosophy into the physical world.

KEZELby DBTEZ

KEZEL leaves your systems of record in place and operates as the intelligence layer around them, built and run by the DBTEZ engineering team.

A different first question

Show us the data you are not allowed to move.

That's the workload we should discuss. A 45-minute boundary discovery maps your boundaries, the policies that govern access, and the evidence you need on day one.