Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion bots.mdx
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
---
title: "Bots and agents"
title: "KERNEL Bots and Agents"
sidebarTitle: "Verify KERNEL Traffic"
description: "Kernel's bots and agents, their purposes, and how to verify them with Web Bot Auth"
---

Expand Down
54 changes: 32 additions & 22 deletions docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -268,39 +268,49 @@
]
},
{
"group": "Working with your browser",
"group": "Partnering with KERNEL",
"pages": [
{
"group": "Intermediate",
"expanded": true,
"group": "Plans and Billing",
"pages": [
{
"group": "Bot Anti-Detection",
"pages": [
"bots"
]
}
"info/pricing",
"info/spending-caps",
"info/mpp"
]
},
{
"group": "Security and Trust",
"pages": [
"shared-responsibility-model",
"info/trust-center",
"security-vulnerability-reporting",
"bots"
]
},
{
"group": "Enterprise",
"pages": [
"info/enterprise",
"info/hipaa",
"info/zero-data-retention",
"info/contact-sales"
]
},
{
"group": "Support and Community",
"pages": [
"info/support",
"community/discord",
"community/github"
]
}
]
},
{
"group": "Community",
"pages": [
"community/github",
"community/discord"
]
},
{
"group": "Info",
"pages": [
"info/concepts",
"info/zero-data-retention",
"info/pricing",
"info/spending-caps",
"info/support",
"info/unikernels",
"info/mpp"
"info/unikernels"
]
}
]
Expand Down
18 changes: 18 additions & 0 deletions info/contact-sales.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
title: "Contact Sales"
description: "Talk to Kernel about an enterprise plan, custom limits, or a pilot"
---

**[Book a call](https://calendly.com/d/d3tn-5kp-5yt).**

Worth reaching out when:

- You need **custom concurrency or create-rate limits** beyond the published plans — see [concurrency and limits](/browsers/concurrency-and-limits).
- You need a **BAA, zero data retention, or continuous audit log export** — see [Enterprise](/info/enterprise).
- You're **migrating a fleet** and want help choosing between browser pools, on-demand browsers, and the [code execution platform](/apps/develop).
- You're running **thousands of end-user identities** and want the project and profile layout reviewed.
- Your target sites have **aggressive bot detection** and you want them tested before you commit.

Bring the sites you need to automate, your expected concurrency, and how the automation is triggered. That's usually enough to scope pricing and the right architecture on the first call.

Already a customer with a support question? Use [support](/info/support) instead.
39 changes: 39 additions & 0 deletions info/enterprise.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
---
title: "Enterprise Overview"
sidebarTitle: "Overview"
description: "HIPAA, zero data retention, custom limits, and support on KERNEL's Enterprise plan"
Comment thread
cursor[bot] marked this conversation as resolved.
---

What changes on the Enterprise plan.

## HIPAA

KERNEL signs a BAA on the Enterprise plan. See [HIPAA](/info/hipaa) for what KERNEL provides and what you're responsible for.

## Zero data retention

[Zero data retention](/info/zero-data-retention) is Enterprise-only and configured per organization. With it enabled, session recordings, live view streams, and telemetry aren't retained after the browser terminates.

## What else the Enterprise plan includes

| | Enterprise |
| --- | --- |
| Concurrency and rate limits | Custom limits for concurrency and browser creation. See [concurrency and limits](/browsers/concurrency-and-limits). |
| Audit logs | [Continuous export to S3](/info/audit-logs#continuous-s3-export), in addition to search and download |
| Replay retention | Custom [replay](/browsers/replays) retention |
| [Support](/info/support) | A shared Slack channel, with tiered response times |
| Data processing | [DPA](/dpa) |

The full plan comparison is on [pricing](/info/pricing). For KERNEL's security program, compliance reports, and the shared responsibility model, see [security practices](/security) and the [trust center](/info/trust-center).

## Legal

- [Terms of service](/tos)
- [Privacy policy](/privacy)
- [Acceptable use policy](/acceptable-use)
- [Data processing addendum](/dpa)
- [Vulnerability reporting](/security-vulnerability-reporting)

## Talk to us
Comment thread
cursor[bot] marked this conversation as resolved.

Scoping an enterprise deployment, a BAA, or zero data retention starts with a conversation: [contact sales](/info/contact-sales).
16 changes: 16 additions & 0 deletions info/hipaa.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
title: "HIPAA"
description: "Run browser workflows that handle protected health information on KERNEL's Enterprise plan"
---

KERNEL supports HIPAA compliance for workflows that handle protected health information (PHI), and signs a business associate agreement (BAA) on the Enterprise plan.

## What KERNEL provides

- **A BAA.** KERNEL signs a BAA with Enterprise customers. [Contact sales](/info/contact-sales) to start one.
- **Isolation per browser.** Each browser runs in its own VM with its own kernel and filesystem, isolated from other sessions at the hypervisor.
- **Zero data retention.** With [zero data retention](/info/zero-data-retention), session recordings, live view streams, and telemetry aren't retained after a browser terminates. Turn it on if PHI must not persist after a session ends.

## What you're responsible for

HIPAA compliance is shared. KERNEL secures the platform; you're responsible for how your agents use it, such as which sites they access, what data they extract, and where that data goes. See the [shared responsibility model](/shared-responsibility-model) for the full split, and [security practices](/security) for KERNEL's program and current compliance status.
71 changes: 25 additions & 46 deletions info/pricing.mdx
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
---
title: "Pricing & Limits"
title: "Pricing"
sidebarTitle: "Plans and Pricing"
---

With Kernel, you only pay for what you use and nothing more. You don't pay for idle time thanks to [Standby Mode](/browsers/standby), idle browsers in a browser pool incur no usage charges, and you're never charged for proxies.
With Kernel, you only pay for what you use and nothing more. You don't pay for idle time thanks to [Standby Mode](/browsers/standby), and idle browsers in a browser pool incur no usage charges.

## Plan Pricing
| Plan | Monthly cost | Included Credits / mo
Expand Down Expand Up @@ -55,69 +56,47 @@ import { PricingCalculator } from '/snippets/calculator.jsx';
| HIPAA compliance (BAA) | ❌ | ❌ | ❌ | ✅ |


## Concurrency limits
<span id="concurrency-limits" />
<span id="rate-limiting" />
<span id="notes" />
## Limits

Kernel enforces a single concurrency limit covering all browsers you run at once—whether created on demand with `browsers.create()` or reserved in a [browser pool](/browsers/pools/overview). Your full limit is available to either API in any mix.
Concurrency, rate limits, and per-browser resources for each plan are on [concurrency and limits](/browsers/concurrency-and-limits).

| Feature | Developer | Hobbyist | Start-Up | Enterprise |
| --- | --- | --- | --- | --- |
| Concurrent browsers | 5 | 10 | 150 | Custom |
| App invocations | 5 | 10 | 50 | Custom |
| App invocations (per-app) | 5 | 10 | 20 | Custom |
| Managed auth health check interval | 6 hours minimum | 1 hour minimum | 20 minutes minimum | Custom |

#### Notes
- Reserved capacity in a [browser pool](/browsers/pools/overview) counts toward your concurrency limit whether or not the browsers are currently acquired—a pool sized to 40 browsers uses 40 of your limit.
- Browsers in [Standby Mode](/browsers/standby) count against your concurrency limit.
- Limits are org-wide by default unless stated otherwise.


## Rate limiting

Kernel enforces per-organization rate limits on API requests. When you exceed the rate limit, the API returns a `429 Too Many Requests` response with a `Retry-After` header indicating how many seconds to wait before retrying.

Rate-limited endpoints include these headers on every response:

| Header | Description |
| --- | --- |
| `X-RateLimit-Limit` | Maximum requests allowed per minute |
| `X-RateLimit-Remaining` | Requests remaining in the current window |
| `Retry-After` | Seconds to wait before retrying (only on `429` responses) |

All Kernel SDKs automatically retry `429` responses up to 2 times, respecting the `Retry-After` header for delay timing. If retries are exhausted, the SDK throws a typed `RateLimitError` with the response headers accessible for custom backoff logic.
## Other ways to pay

If you need higher rate limits, [contact us](https://calendly.com/d/d3tn-5kp-5yt).
Agents can buy a single browser without a KERNEL account or API key through the [machine payments protocol (MPP)](/info/mpp). One stealth, headful browser for 30 minutes costs \$0.50, paid with a Link payment. See [buy a browser with MPP](/info/mpp) for the payment flow.

## FAQ

<Accordion title="How are app invocations charged?">
App invocations are billed for active compute time, not per API call. The invocation rate in [Usage Rates](#usage-rates) is based on the current 4 GB memory allocation at $0.0000166667 per GB-second.

Billing starts when your code begins executing and stops when it finishes. You aren't charged for queued time, deploying an app, or leaving a deployed app idle. Failed and canceled invocations still accrue charges for the time they ran.

Browsers created by an invocation are billed separately for their active runtime at the browser rates above. Services your code calls, such as an LLM API, also bill you independently.

The [app invocation limits](#concurrency-limits) are concurrency limits, not a number of invocations included with your plan.
</Accordion>
<Accordion title="how can i control my team's usage spending?">
see this guide on [spending controls](/info/spending-caps).
</Accordion>
<Accordion title="How does billing work across a browser's lifecycle? Am I charged for the full timeout_seconds, or only while it's actively in use?">
Only for active runtime. `timeout_seconds` sets an idle auto-delete ceiling, not a billing window. Once a browser goes idle — 5 seconds after the last CDP or Live View activity — it enters Standby Mode and stops accruing usage cost, even if it stays alive until the timeout is reached. Deleting a browser early doesn't lower cost any further (idle time is already free), but it does free up your concurrency slot sooner.
</Accordion>
<Accordion title="How can I control my team's usage spending?">
Set an organization or project [spending cap](/info/spending-caps).
</Accordion>
<Accordion title="How are browser pools charged?">
you pay the standard usage-based price per GB-second while browsers are running. Idle browsers in a pool incur no disk charges—you only pay when a browser is actively in use.

Note: A browser pool counts toward your concurrency limit whether or not its browsers are currently acquired — a browser pool sized to 40 browsers uses 40 of your limit. Browser pools are available on Start-Up and Enterprise plans.
Note: A browser pool counts toward your concurrency limit whether or not its browsers are currently acquired — a browser pool sized to 40 browsers uses 40 of your limit.
</Accordion>
<Accordion title="How is Managed Auth charged?">
Managed Auth is included on all plans with no per-connection fees. It uses browser sessions for login, health checks, and eligible automatic reauthentication. These count toward your browser usage and concurrency like any other browser session.

Auth sessions are fast, typically 5-30 seconds each, and most website sessions remain valid for days. For example, monitoring 100 auth connections typically costs less than $5/month in browser usage.
</Accordion>
<Accordion title="Does it cost money to use Vaults and Agentic Payments?">
Free users can create up to three vaults. Unlimited vaults are included in paid plans. There are no surcharges to use Kernel's agentic payments products.
</Accordion>
<Accordion title="What do regional browsers cost?">
Regional browsers are charged at the same usage rates as our default, US-based browsers.
</Accordion>
<Accordion title="Does it cost money to use Vaults and Agentic Payments?">
Free users can create up to three vaults. Unlimited vaults are included in paid plans. There are no surcharges to use Kernel's agentic payments products.
<Accordion title="How are app invocations charged?">
App invocations are billed for active compute time, not per API call. The invocation rate in [Usage Rates](#usage-rates) is based on the current 4 GB memory allocation at $0.0000166667 per GB-second.

Billing starts when your code begins executing and stops when it finishes. You aren't charged for queued time, deploying an app, or leaving a deployed app idle. Failed and canceled invocations still accrue charges for the time they ran.

Browsers created by an invocation are billed separately for their active runtime at the browser rates above. Services your code calls, such as an LLM API, also bill you independently.

The [app invocation limits](/browsers/concurrency-and-limits#concurrency) are concurrency limits, not a number of invocations included with your plan.
</Accordion>
2 changes: 1 addition & 1 deletion info/spending-caps.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -168,5 +168,5 @@ If a project cap is higher than the organization cap plus monthly credits, the o
</Accordion>

<Accordion title="How are spending caps different from concurrency limits?">
Spending caps bound monthly usage cost. [Concurrency limits](/info/pricing#concurrency-limits) bound simultaneous browser capacity. A spending cap doesn't reserve throughput, and a concurrency limit doesn't bound monthly spend.
Spending caps bound monthly usage cost. [Concurrency limits](/browsers/concurrency-and-limits#concurrency) bound simultaneous browser capacity. A spending cap doesn't reserve throughput, and a concurrency limit doesn't bound monthly spend.
</Accordion>
17 changes: 17 additions & 0 deletions info/trust-center.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
title: "Trust Center"
description: "Where to get Kernel's compliance reports and security artifacts"
---

Kernel's compliance artifacts live in the trust center: **[trust.kernel.sh](https://trust.kernel.sh)**.

What you'll find there:

- The **SOC 2 Type II** report, available on request.
- Current compliance status.
- The [authorized subprocessor list](https://trust.kernel.sh/subprocessors), referenced by the [DPA](/dpa).
- Security artifacts and questionnaire responses for vendor review.

For how the program works rather than the paperwork, see [security practices](/security) and the [shared responsibility model](/shared-responsibility-model). For what changes on an Enterprise plan — BAA and zero data retention — see [Enterprise](/info/enterprise).

Security questions go to [security@kernel.sh](mailto:security@kernel.sh). Reporting a vulnerability? See [vulnerability reporting](/security-vulnerability-reporting).
1 change: 1 addition & 0 deletions security-vulnerability-reporting.mdx
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
---
title: "Bug Bounty Program: Scope and Policy"
sidebarTitle: "Vulnerability Reporting"
description: "Kernel's bug bounty scope, rewards, severity assessment, safe harbor, and rules of engagement"
---

Expand Down
Loading
Loading