Kenshiki Labs

Same stack, three environments

One contract. Three environments.

Kenshiki Labs runs the same governance contract across three deployment environments. Workshop is the shared-cloud entry tier for evaluation. Refinery is private inference for production with sensitive data. Clean Room is air-gapped operation with hardware-anchored attestation for the highest-assurance contexts. Application code stays identical across tiers — only the base URL and API key change.

The boundary runs here.

Workshop

Shared cloud deployment with hosted Kadai or BYOK generation. Self-serve, no infrastructure to provision, first governed response in under five minutes. Use it to evaluate the governance contract before committing to private deployment.

Best for: Evaluating governed synthesis on shared infrastructure.

Start in Workshop

The boundary runs there.

Refinery

Private inference in Kenshiki Labs-managed AWS, your VPC, GovCloud, or connected on-prem. Same governance contract as Workshop with no public-model boundary in the runtime path. For production workloads with sensitive data or strong residency requirements.

Best for: Production with sensitive data.

Talk to us about Refinery

Nothing leaves.

Clean Room

Air-gapped operation on customer premises with hardware root of trust. Every step in the pipeline is signed and anchored to verified hardware. For regulatory, defense, and national-security contexts where the attestation record itself must survive scrutiny.

Best for: Regulatory, defense, national-security.

Talk to us about Clean Room

Same contract. Same code. Different boundary.

Application code doesn't change between tiers — only the base URL and API key. Move the boundary as your trust requirements deepen, without re-platforming.