Marrinn · The architecture · The Kernel
The Kernel.
The model, and it is your choice. OpenAI, Anthropic, Google, OpenRouter — or a private model running entirely offline on your own hardware. The kernel is swappable because the platform was never built around one vendor’s model.
Four deployments, four different models.
The question a regulated buyer asks first is not what the AI can do. It is where the inference runs, and who else sees the prompt. On most platforms that question has one answer, decided by the vendor, and the only way to change it is to change platform.
Here it is a field in the admin console. The same four deployments below run the same product, the same features and the same interface — on four different models, for four different reasons.
Same product. Different model. Different building.
Each of these is a real reason a buyer gives for saying no to an AI platform. None of them is a reason to say no to this one, because in each case the answer is a setting rather than a rebuild.
- GovernmentA private model, on their hardwareNothing leaves the network. No key, no third party, no egress.
- HealthcareAnthropic ClaudeA vendor already through their procurement and their data agreement.
- FinanceGoogle GeminiBought under an agreement the group had signed two years earlier.
- A pilot teamOpenRouterOne key fronting many models, while they work out which one they want.
One kernel, one product
Every AI feature in Marrinn runs on the same shared kernel and talks to that kernel rather than to a vendor. The assistant in a work item, the CRM features and the whole Intelligence Suite all use the one configuration. There is no per-feature API key, and switching provider is four settings — the provider, the key, the model, the endpoint.
A private deployment is not a different product
Point the kernel at a model on your own hardware and the features behave the same way. You are not choosing between privacy and the product, which is the trade every hosted-only platform asks you to make. Hosting is the same story, and it is a separate decision from the model: our cloud, your own cloud account, or your own server room, and the product does not change.
Procurement stops being the blocker
If your organisation has already cleared one AI vendor, use that one. The platform does not need you to sign a new data agreement with a company you have never heard of before you can start.
A cheaper model is a settings change
Model prices fall and capabilities move every few months. When they do, that is an afternoon in the admin console rather than a project, because no feature was written against one vendor’s API.
Only what an analysis needs is sent
The Intelligence tools send issue metadata, titles and progress, audit summaries and role lists. Descriptions and attachments are not sent unless the tool says so.
One configuration, and the features never know.
The reason a platform gets locked to a model vendor is rarely strategy. It is that fifty features were each written against one API, so the vendor became load-bearing by accident. This one has a single client underneath, because every supported provider speaks the same protocol.
One config, five providers
Provider, key, model and endpoint. That is the whole surface. Every supported provider is reached through the same OpenAI-compatible interface, which is why one client handles all of them.
Any compatible gateway
Beyond the five named providers, point the kernel at your own proxy, router or internal gateway by giving it a base URL. A provider we have never tested is still a provider you can use.
A model with no key at all
A self-hosted model needs no API key and no outbound connection. The inference runs on hardware you own, in a building you control.
The key is stored encrypted
Set the provider in the admin console rather than an environment file, and the key is stored encrypted rather than sitting in a tracked file or a log.
A feature survives the switch
Because features call the kernel and not the vendor, one you rely on keeps working when you move from a hosted model to a private one. The only thing that changes is where the inference runs.
The same kernel everywhere
Configure it once and the assistant, the CRM intelligence and every Intelligence tool use it. There is no second place to configure AI, and no feature quietly using a different model. Semantic search runs through it too — the vector index over your own content is built by an embedding model on the same kernel, so on a private deployment the index is built on your hardware and the questions never leave it.
Seven parts, one operating system.
Read the seven from the bottom and it is an operating system: a kernel, a data model, memory, a way to see, processes that do work, a place those processes meet people, and ports to everything outside.
The Core
Every module on one data model.
The Memory
One version of the truth, across systems you do not own.
The Lens
Where the records become an answer.
The Squids
The operators, and one can lead others.
The Handoff
Where an agent stops and a person decides.
The Ports
And it reaches what you already run.
The Kernel is one of seven parts.
It is the bottom of the stack: the kernel is the model you choose, the core is every module on one data model, The Memory is what they all agree on, and the ports are how it reaches the software you already run.
