Arqen Kernel Engine
Your applications. Our kernel. Every operation signed, audited, and running even offline.
One platform. Two systems. One protocol.
Arqen Edge
Arqen Edge is the manifest-driven runtime your development team builds on: they declare business logic in a signed JSON manifest, the kernel executes it deterministically on any node — at the customer's site, on a mini PC, even with no connectivity.
Manifest-driven
Your team declares behavior in a signed JSON manifest following our technical specs — new version, not redeploy.
5 integrated engines
Formula, Action/FSM, Data-Link, RBAC and Constraint compose every action in a single transaction.
Offline-first runtime
Login, actions and transactions run autonomously: Internet down, full operations.
Immutable audit
Every action enters an append-only SHA-256 hash chain, verified on schedule.
Resilient sync
Transactional CDC outbox with retry, circuit breaker and dead-letter: events are never lost.
Plugins & verticals
Your developers build the application; the same engine runs any domain — retail and field service are our reference manifests.
Arqen Control Plane
The Control Plane is the command center on the central VPS: it governs tenants, manifests, licenses and billing while edges stay autonomous in the field.
Zero-touch provisioning
A single-use TTL token: the edge self-registers at first boot and receives its identity.
Native Stripe billing
Signed, deduplicated webhooks turn payments into the tenant's contract state.
Real metering
Monthly events, active edges and contract caps measured on synced data, not estimates.
Fleet heartbeat
Every edge reports alive at each sync cycle: online, delayed or offline at a glance.
Contract enforcement
Ed25519-signed licenses: past the grace period, the edge blocks only new writes.
Native multi-tenant
Different companies and verticals on the same control plane, isolated by PostgreSQL RLS.
Arqen Trust Protocol
The Trust Protocol is the cryptographic contract between edge and cloud: Ed25519-signed manifests, verifiable contract licenses and append-only audit make every exchange provable.
Ed25519 signatures
Every manifest and license is signed by the Control Plane; the edge verifies before executing.
Audit hash chain
Events and admin actions in a SHA-256 chain: one altered row invalidates the whole chain.
Telemetry
Prometheus metrics, fleet heartbeat and readiness probes in real time.
Fail-closed guards
Rate limiting, SQL guard, FORCE RLS and manifest validation block what isn't authorized.
Grace & recovery
The grace period shields paying customers from cloud outages; reactivation is automatic.
Governance
Persistent admin sessions, RBAC roles and append-only audit: every action is traced.
Data Residency & Security
Data stays where your applications generate it: on the edge node, on the customer's premises. The cloud only receives what governance and synchronization need, over TLS channels.
PostgreSQL with RLS
Row-level tenant isolation with FORCE ROW LEVEL SECURITY — enforced by the database, not by code.
Data sovereignty
The edge runs on-premise on your hardware; the Control Plane on a VPS you control. Your data stays yours.
TLS & protected secrets
TLS on every edge ↔ cloud channel, credentials persisted with restrictive permissions, no secrets in the repository.
Privacy by design
Strict per-tenant separation, data minimization toward the cloud, and an audit trail for reporting.
Your data stays yours.
Your edge stays autonomous.
Every operation stays verifiable.
Pricing
A transparent model that scales with edge nodes and managed event volume, without surprises or hidden costs.
Transparent pricing.
No hidden fees.
Scale only when you grow.
Scalability
A natively multi-tenant architecture: from a single pilot site to a distributed edge fleet, without ever changing platform.
Horizontal scaling
New clients and divisions are new rows in the Control Plane, not new infrastructure.
Lightweight edge
The same binary runs on field mini PCs and site servers: Docker, PostgreSQL, a single container.
Multi-site
Multiple deployments per tenant, each with its own autonomous edge node and identity.
Proven under load
20 VU × 10 min load test: 21,500+ actions, 0 errors, p95 of 233 ms, zero dead-letter.
Start small.
Scale globally.
Same kernel, same protocol.