Arqen

Arqen Kernel Engine

Your applications. Our kernel. Every operation signed, audited, and running even offline.

One platform. Two systems. One protocol.

Arqen Edge

Arqen Edge is the manifest-driven runtime your development team builds on: they declare business logic in a signed JSON manifest, the kernel executes it deterministically on any node — at the customer's site, on a mini PC, even with no connectivity.

Manifest-driven

Your team declares behavior in a signed JSON manifest following our technical specs — new version, not redeploy.

5 integrated engines

Formula, Action/FSM, Data-Link, RBAC and Constraint compose every action in a single transaction.

Offline-first runtime

Login, actions and transactions run autonomously: Internet down, full operations.

Immutable audit

Every action enters an append-only SHA-256 hash chain, verified on schedule.

Resilient sync

Transactional CDC outbox with retry, circuit breaker and dead-letter: events are never lost.

Plugins & verticals

Your developers build the application; the same engine runs any domain — retail and field service are our reference manifests.

Arqen Control Plane

The Control Plane is the command center on the central VPS: it governs tenants, manifests, licenses and billing while edges stay autonomous in the field.

Zero-touch provisioning

A single-use TTL token: the edge self-registers at first boot and receives its identity.

Native Stripe billing

Signed, deduplicated webhooks turn payments into the tenant's contract state.

Real metering

Monthly events, active edges and contract caps measured on synced data, not estimates.

Fleet heartbeat

Every edge reports alive at each sync cycle: online, delayed or offline at a glance.

Contract enforcement

Ed25519-signed licenses: past the grace period, the edge blocks only new writes.

Native multi-tenant

Different companies and verticals on the same control plane, isolated by PostgreSQL RLS.

Arqen Trust Protocol

The Trust Protocol is the cryptographic contract between edge and cloud: Ed25519-signed manifests, verifiable contract licenses and append-only audit make every exchange provable.

Ed25519 signatures

Every manifest and license is signed by the Control Plane; the edge verifies before executing.

Audit hash chain

Events and admin actions in a SHA-256 chain: one altered row invalidates the whole chain.

Telemetry

Prometheus metrics, fleet heartbeat and readiness probes in real time.

Fail-closed guards

Rate limiting, SQL guard, FORCE RLS and manifest validation block what isn't authorized.

Grace & recovery

The grace period shields paying customers from cloud outages; reactivation is automatic.

Governance

Persistent admin sessions, RBAC roles and append-only audit: every action is traced.

Data Residency & Security

Data stays where your applications generate it: on the edge node, on the customer's premises. The cloud only receives what governance and synchronization need, over TLS channels.

PostgreSQL with RLS

Row-level tenant isolation with FORCE ROW LEVEL SECURITY — enforced by the database, not by code.

Data sovereignty

The edge runs on-premise on your hardware; the Control Plane on a VPS you control. Your data stays yours.

TLS & protected secrets

TLS on every edge ↔ cloud channel, credentials persisted with restrictive permissions, no secrets in the repository.

Privacy by design

Strict per-tenant separation, data minimization toward the cloud, and an audit trail for reporting.

Pricing

A transparent model that scales with edge nodes and managed event volume, without surprises or hidden costs.

Arqen EdgePriced per deployed edge node, whatever application it runs.
Arqen Control PlanePer active tenant, with configurable edge-node and event-volume caps per plan.
BillingMonthly or annual, powered by Stripe with automatic invoicing and grace period.
Support & OnboardingZero-touch installer and technical assistance always included.

Scalability

A natively multi-tenant architecture: from a single pilot site to a distributed edge fleet, without ever changing platform.

Horizontal scaling

New clients and divisions are new rows in the Control Plane, not new infrastructure.

Lightweight edge

The same binary runs on field mini PCs and site servers: Docker, PostgreSQL, a single container.

Multi-site

Multiple deployments per tenant, each with its own autonomous edge node and identity.

Proven under load

20 VU × 10 min load test: 21,500+ actions, 0 errors, p95 of 233 ms, zero dead-letter.

Built for enterprise

On-premise edgePrivacy by designMulti-tenantPostgreSQL RLS

Ready to explore Arqen?

Get early access when pre-production opens.

Join the waitlist