Architecture

Kestri
Kestri.com
Architecture
Evidence before inference · AI inside the system of record

Retrieval should live where governed data already lives.

Language models generate answers. Agent frameworks execute workflows. Kestri retrieves governing evidence inside the system of record—without moving source data or surrendering authority to a model.

Three architectures

Same question. Different authority.

Language Model
Prompt

LLM
Generated answer
Agent Framework
Goal

Model + tools
Executed workflow
Kestri
Question

System of record
Verified evidence
Model-centered AI
Retrieval supports a model-generated response. The answer remains dependent on model behavior.
System-of-record AI
Retrieval returns the governing source directly. The evidence remains the authority.
Oracle-powered. System-of-record neutral.

Your system of record stays the system of record.

Oracle powers Kestri. Governed data stays where authority, permissions, and lineage already exist.

Oracle
Kestri Engine
Snowflake
Governed data
SQL Server
Enterprise records
Postgres
Operational data
Databricks
Lakehouse evidence
Oracle
Systems of record
Governing Evidence
Governed evidence remains where authority, permissions, and lineage already exist. Kestri retrieves what governs the answer and preserves the source.
Kestri architecture

Six controls. One responsibility boundary.

Kestri controls where execution occurs, what may be retrieved, and how every result is verified.

1
Execution locality
Runs inside customer-controlled infrastructure.
2
Deterministic retrieval
Exact identifiers, clauses, citations, and source anchors.
3
Probabilistic retrieval
Similarity expands discovery without becoming authority.
4
Permission enforcement
Existing access controls remain in force.
5
Evidence provenance
Every result remains linked to its governing source.
6
Authority integrity
The source is preserved—not rewritten by the model.

The LLM is optional. The evidence is not.

Kestri does not require an LLM to perform its primary job.
Retrieval, alignment, permissions, evidence linking, and verification occur inside the governed environment. A language model may explain evidence—but it does not become the source of authority.
No model broadcast
No uncontrolled connectors
No rewritten governing record
No black-box authority expansion
Evidence generated during execution
Human authority remains intact
One engine. Three domains.

Same architectural proof.

Do not move the truth to the model. Bring the question to the governed record—and preserve the evidence required to verify the answer.

Evidence first. Inference second.

See Kestri operate inside the system of record.