KEZEL® by DBTEZ · The Platform
Real-time answers inside your firewall.
KEZEL orchestrates analytics and AI inside your approved environment. Raw records and results stay in place; people and systems reach the intelligence through policy-based access.
How a question becomes an answer, in four moves.
Zero Trust Orchestration replaces trust-based data handling with metadata-driven instructions, executed directly inside your environment.
Deploy inside the boundary
A lightweight Data Streamer runs in your environment (on-prem, your cloud, or hybrid) and connects to approved sources. It ships as a Docker or Kubernetes container, a VM, or a system service.
Orchestrate with metadata
The control plane works from schema and context metadata, user intent and policy. It generates encrypted instructions. Raw records never travel upward.
Compute where data lives
SQL, transformation and ML execute next to your systems. Every action is verified against policy; nothing operates implicitly.
Access results under policy
Results remain in-boundary. Dashboards, predictions, alerts and APIs reach them through policy-based access, with a complete audit trail of who saw what, when, and against which sources.
Six components. One boundary rule.
Every component exists to keep one promise: raw sensitive records remain inside the approved execution boundary, and every crossing is explicit and auditable.
Metadata Engine
Captures schema definitions and contextual metadata from source systems.
Instruction Generator
Builds orchestration instructions from metadata, user intent and policy.
Vault & Crypto Services
Manages cryptographic protection of instructions and configuration.
Streaming Agent
Runs SQL, data and ML operations inside the customer environment.
Orchestration Controller
Manages instruction lifecycle and dispatch across environments.
Monitoring & Audit Engine
Records orchestration activity for traceability and compliance.
Transport
TLS 1.3
Encryption
AES-256
Secrets
Vault-based key management
Attestation
SOC 2 Type II attested
Audit
Complete trail of orchestration activity
Access
Least-privilege, policy-bound
Deploys on-premises, in your cloud, or hybrid: Docker or Kubernetes containers, virtual machines, or system services. Connects to Snowflake, BigQuery, Redshift, Salesforce, HubSpot, Zendesk and custom systems through standards-based connectors.
The end of the speed-or-control tradeoff.
Traditional stacks made you choose: keep everything locked down, or copy data into someone else's platform. KEZEL is built for the case both assumptions fail.
| Traditional on-prem | SaaS analytics | KEZEL | |
|---|---|---|---|
| Raw data stays in place | Yes | ✕No: copied or uploaded | Yes: execution moves instead |
| Real-time querying | ~Often delayed | Yes | Yes: live on your systems |
| Exposure surface | Low, but rigid | ✕Expanded: third-party pipelines | Reduced: no raw-data movement |
| Setup & maintenance | ✕High | Low | Low: lightweight agent only |
| Planning & forecasting | ~Manual and limited | ~Prebuilt, not adaptable | Built in, scenario-driven |
| AI & natural-language querying | ✕Not native | Often included | Native, schema-aware |
| Compliance control | Full | ✕Shared responsibility | You own the boundary lines |
| Trust model | Internal IT | ✕Vendor-managed | Org-owned, agent-enforced |
KEZEL Insights Studio
A command centre for real-time decisions.
Insights Studio replaces fragmented tools with one decision workspace for modelling trade-offs and simulating what-ifs. Everything runs against the same in-boundary architecture as the rest of KEZEL.
Regression Engine
Optimize strategy through simulation on live, in-boundary data.
Classification Engine
Predict and prevent risk: surface the accounts, claims or events that need attention first.
Time Series Engine
Forecast with context: demand, capacity and cash, timed to the decisions they feed.
secQR™ · operational trust, powered by KEZEL
Every scan is a policy decision.
secQR turns QR interactions into governed, auditable trust events: it evaluates who is acting, what the code represents and what should happen next. It detects and challenges fraudulent scan attempts in real time, and extends the in-boundary philosophy into the physical world.
KEZEL leaves your systems of record in place and operates as the intelligence layer around them, built and run by the DBTEZ engineering team.
A different first question
Show us the data you are not allowed to move.
That's the workload we should discuss. A 45-minute boundary discovery maps your boundaries, the policies that govern access, and the evidence you need on day one.