System & data integrations

Connect kiLM to the Data Your Teams Already Use

kiLM ingests the file formats, applications, protocols, and cloud services your organization already runs on — and every connector is module-gated, so the air-gap and intake-only profiles stay safe. The lists below are honest about what ships today versus what is opt-in, and what is still on the roadmap.

Connector Ingestion & Provenance

The file and data formats kiLM ingests into governed records — office, CAD/BIM, engineering, simulation, quality and Japanese-industry formats (illustrative).
Illustrative representation.
Connector ingestion & provenance — governed, provenance-complete ingestion of enterprise files and records (illustrative).
Illustrative representation.

File Extension Types

Every uploaded or pulled file is routed to a purpose-built worker that knows how to Extract text, structure, geometry, or signal from that format. Code, executables, and untrusted archives are quarantined by default — opt in deliberately.

Office & documents Shipped

Everyday documents and the structural information inside them — paragraphs, headings, tables, embedded images, captions.

  • PDF
  • DOC
  • DOCX
  • PPT
  • PPTX
  • ODT
  • ODP
  • RTF
  • TXT
  • MD
  • HTML
  • EML
  • MBOX
  • MSG
  • IPYNB
  • ICS
  • VCard
  • SRT
  • VTT
  • INI
  • TOML
  • conf
  • ReqIF

Structured data Shipped

Tabular and semi-structured data with column-aware extraction — supports schema inference and per-cell sensitivity classification. Big-data columnar formats land natively; database dumps and SQLite files are parsed by the same path.

  • CSV
  • TSV
  • JSON
  • JSONL
  • XML
  • Parquet
  • Avro
  • ORC
  • SQL
  • SQLite

Spreadsheets Shipped

Multi-sheet workbooks with formula preservation, merged-cell handling, and per-sheet schema inference. Macros are sandboxed (XLSM gets the same treatment as XLSX — never executed).

  • XLS
  • XLSX
  • XLSM
  • ODS

CAD & engineering Shipped

Native B-Rep, mesh, BIM, USD, and FEM formats with geometry-aware extraction. Tier 1 formats use built-in kernels; Tier 2 formats route to an OpenCascade companion worker.

  • STEP
  • STP
  • IGES
  • IGS
  • BREP
  • STL
  • OBJ
  • PLY
  • GLB
  • GLTF
  • 3MF
  • IFC
  • DXF
  • DWG
  • USD
  • USDA
  • USDC
  • USDZ
  • JT
  • BDF
  • NAS
  • OP2

Simulation Models Shipped

Functional Mock-up Units (FMI standard) — Model metadata, parameter ranges, and variable definitions extracted into searchable records so engineers can find the Model they need without running it.

  • FMU
  • FMI 2.0 / 3.0

Engineering & manufacturing Systems Shipped

Neutral interchange exports from PLM, ALM, QMS/LIMS, CAE, MES, and the core engineering tools (MATLAB, Modelica/Dymola, Revit) — imported air-gapped with no vendor SDK and no live credentials. PLMXML/STEP-AP242 BOMs, ReqIF requirement-to-test traceability, AnIML lab results, VTK/HDF5 simulation results, B2MML/ISA-95 as-built genealogy, MATLAB .mat datasets, and Modelica .mo system Models become governed, queryable records plus graph relationships. Every import is bound to a versioned Extraction Contract. Default off; operator opt-in per source. Native vendor formats (Abaqus .odb, MATLAB .m/.slx, Revit .rvt) are bring-your-own-license.

  • PLMXML
  • STEP-AP242
  • ReqIF
  • ReqIFZ
  • AnIML
  • VTK
  • HDF5
  • MED
  • CGNS
  • ODB (BYOL)
  • B2MML
  • ISA-95
  • MAT
  • Modelica .mo
  • IFC
  • FMU
  • .m/.slx (BYOL)
  • .rvt (BYOL)
  • Simscape .ssc
  • Amesim (BYOL)
  • SAP IDoc
  • Ariba cXML
  • EDI X12/EDIFACT
  • EDI logistics (WMS/TMS)
  • OAGIS BOD (Infor)
  • IBM Maximo MIF
  • PLCopen XML
  • AutomationML
  • ServiceNow
  • Workday
  • AAS (.aasx)
  • OPC-UA NodeSet2
  • Gerber (RS-274X)
  • ODB++

Quality, test & process Shipped

Free, air-gapped readers for quality, test-management, and business-process interchange: dimensional-inspection results (QIF / ISO 23952, Q-DAS / AQDEF — Hexagon, Zeiss), test cases with requirement coverage (TestRail XML, Xray Cucumber / Test JSON), and process / decision Models (BPMN 2.0, DMN, Visio). Each becomes governed, queryable records plus graph relationships — which tests cover a requirement, which characteristics failed inspection, and the next step in a process. No vendor API and no live credentials; default off, operator opt-in per source.

  • QIF (ISO 23952)
  • Q-DAS / AQDEF
  • STDF
  • TestRail
  • Xray (Cucumber)
  • Xray (JSON)
  • BPMN 2.0
  • DMN
  • Visio .vsdx

Geospatial Shipped

Vector geospatial with attribute extraction; coordinate reference Systems preserved through the pipeline.

  • SHP
  • GPKG
  • GML
  • GeoJSON
  • GeoJSONL
  • KML
  • KMZ
  • GPX

Automotive Shipped

CAN bus databases, calibration files, AUTOSAR descriptions, and ODX diagnostics — extracted into searchable structured records.

  • DBC
  • A2L
  • ARXML
  • ODX
  • FIBEX
  • LDF
  • HEX
  • S19
  • BIN
  • ASAM MDF4

Scientific & life sciences Shipped

Bioinformatics, chemistry, structural biology, and high-throughput experimental data.

  • FASTA
  • FASTQ
  • VCF
  • SDF
  • MOL
  • PDB
  • CIF
  • mmCIF
  • mzML
  • mzXML
  • NetCDF
  • CDF
  • HDF5

Healthcare & clinical records Shipped

Standards-based clinical Ingestion for the healthcare domain — HL7 FHIR R4/R5 resources and Bundles (Patient, Encounter, Observation, Condition, Procedure, MedicationRequest, DiagnosticReport) and DICOM imaging header metadata (Patient → Study → Series → Instance). PHI is Presidio-scrubbed at parse time and DICOM PatientID is hashed; the DICOM reader reads header metadata only and never the pixel data. No vendor SDK, no live credentials, fully air-gappable; default off, operator opt-in per source.

  • HL7 FHIR (R4/R5)
  • FHIR Bundle
  • DICOM (.dcm)

Finance, compliance & security Shipped

Financial reporting and software-supply-chain / security compliance as a governed graph: XBRL / iXBRL financial reports (context / unit / fact), NIST OSCAL control catalogs, SSPs and assessment results, CycloneDX and SPDX software bills-of-materials (component dependency graph), and OASIS CSAF security advisories (advisory → vulnerability → affected product). The SBOM dependency graph pairs with CSAF advisories. No vendor SDK, no live credentials, fully air-gappable; default off, operator opt-in per source.

  • XBRL / iXBRL
  • OSCAL
  • CycloneDX
  • SPDX
  • CSAF

Technical documentation Shipped

Aerospace / defense / MRO service manuals as a navigable structure: S1000D data and publication modules and DITA topics and maps become Module / Topic records with the cross-references between them (a publication module references a data module, a map references a topic). The structure and identifiers are graphed; the prose body still flows through normal text Ingestion and Retrieval. No vendor SDK, no live credentials, fully air-gappable; default off, operator opt-in per source.

  • S1000D
  • DITA
  • DITA map

Images & multimodal Shipped

Images become first-class search citizens — OCR text, vision captions, and visual embeddings for cross-modal Retrieval.

  • PNG
  • JPG
  • JPEG
  • TIFF
  • BMP
  • WebP
  • PDF

Audio & video Limited

Audio and video formats are routed to a speech worker for transcription. The speech worker is shipped at a placeholder level today — formats are recognized and queued, but production-grade transcription quality should be validated against your specific use case. Native transcription engine selection is on the roadmap.

  • WAV
  • MP3
  • M4A
  • AAC
  • FLAC
  • OGG
  • OPUS
  • WMA
  • MP4
  • MOV
  • MKV
  • AVI
  • WebM
  • MPEG

Archives Gated OFF

Multi-file archives are extracted into staging, scanned for nested code or executables, then re-routed to the appropriate worker per child file. The archive gate ships OFF because expansion costs are unbounded without explicit opt-in.

  • ZIP
  • TAR
  • TAR.GZ
  • TAR.BZ2
  • TAR.XZ
  • GZ
  • BZ2
  • XZ
  • 7Z
  • LZ4
  • ZST

Quarantined by default Shipped

Source code, installers, executables, and DLLs land in quarantine instead of the Knowledge corpus. Time-series / sensor-telemetry tables in CSV or Excel are also quarantined — kiLM does not handle time-series data today; only the non-time-series content of a mixed file is ingested. An admin can review or reroute; nothing is silently extracted.

  • ~150 source extensions
  • EXE / MSI / DMG / PKG / DEB / RPM / APK
  • DLL / SO / DYLIB
  • RAR (always refused)
  • Time-series tables (CSV / Excel)

Software Applications

kiLM is self-hosted, but it pulls governed data from the applications your teams already use. Each connector is module-gated, so adopting one is an explicit admin decision rather than a default-on egress.

SharePoint Online Shipped

Per-folder pull via Microsoft Graph. Delta sync, attachment expansion, and lake-watcher hand-off into the standard Ingestion pipeline.

Microsoft 365 Email Shipped

Inbound via Microsoft Graph or Exchange Web Services. Outbound via SMTP. Quote-strip and PII-aware sanitization on the way in.

Google Drive Gated OFF

Folder-scoped pull, delta sync, per-file sensitivity classification on ingest.

Microsoft OneDrive Gated OFF

Personal and business OneDrive via the cloud-storage puller shared with the other providers below.

Box Gated OFF

Folder pull with Box Enterprise features (legal hold, retention policy) preserved as ingest metadata.

Dropbox Gated OFF

Team folder pull with delta sync; same per-connector air-gap toggle as the other cloud-storage providers.

Web URL connector Gated OFF

Controlled webpage reader — an admin-curated allowlist of URLs or domains, pulled on demand into the standard Ingestion pipeline. Defense-in-depth egress: allowlist, connect-time SSRF guard, and per-URL intranet/internet classification, so air-gap installs fetch intranet pages only.

Zoom live transcripts (REST v2) Gated OFF

Read-only internet pull of Zoom cloud-recording transcripts via Server-to-Server OAuth + REST v2, mapped to Meeting / Participant / Utterance records with provenance and incremental sync. BYOL — bring your own paid Zoom plan (cloud_recording:read); kiLM bundles no paid dependency. High-PII, training-excluded by default. This path is internet-required (Zoom cloud), so it is excluded on air-gapped installs — the offline WebVTT card covers transcripts you export yourself.

Meeting transcripts — WebVTT (.vtt) Gated OFF

Offline meeting-transcript ingestion for any tool that exports WebVTT (.vtt) — Microsoft Teams, Zoom, and other sources — mapped to the same Meeting / Participant / Utterance records with provenance. Pure file parsing: no vendor SDK, no live credentials, no internet, air-gap safe. A gated, default-off connector; high-PII, training-excluded by default. Any WebVTT source works; Google Meet, whose native transcript is a Google Doc rather than a .vtt file, must be exported or converted to WebVTT first.

  • WebVTT (.vtt)
  • Microsoft Teams
  • Zoom

Cloud data warehouses Gated OFF

Federated query across Snowflake, BigQuery, and Databricks via declarative connections. Per-table annotation, fan-out into search + graph stores.

  • Snowflake
  • BigQuery
  • Databricks

SQL databases Gated OFF

Read-only connections to the enterprise systems your operations already run. RDBMS and Data Warehouses connect natively or via the generic JDBC / ODBC path. Per-table annotation, per-column sensitivity classification, change-data-capture optional via the slice-0139d REST contract.

  • PostgreSQL
  • MySQL
  • Microsoft SQL Server
  • Oracle
  • Redshift
  • CockroachDB

Data-lake federation Gated OFF

Register an external data lake and index it in place — objects are catalogued and made searchable without copying them into kiLM. Intranet and internet egress are separately gated; operators re-index on demand from the admin surface.

MCP — Model Context Protocol Shipped

kiLM acts as both an MCP server (Claude Desktop, Cursor, Cline, n8n, any MCP-compliant client) and a sanitizing MCP client (pulls from upstream MCP servers with control-token stripping + PII scan).

Microsoft 365 Copilot Shipped

Manifest emission for Microsoft 365 Copilot: declarative agents, API plugins, trimmed OpenAPI specs, source-attribution metadata. Customers download the bundle and register it with their tenant.

Label Studio Shipped

HMAC-signed webhook receiver for human-in-the-loop label review (VLM captions, OCR corrections). Applied labels write back into per-domain chunks.

Identity providers Gated OFF

OIDC federation into the bundled Keycloak realm: Azure AD, Okta, Google Identity, plus any generic OIDC issuer. Keycloak itself ships always-on.

  • Azure AD
  • Okta
  • Google Identity
  • Generic OIDC

Stripe Gated OFF

Per-customer MCP usage rollups exported as CSV by default; Stripe push is an opt-in second gate.

Enterprise Engineering & Operations Systems

kiLM ingests the standard interchange formats that PLM, ERP, ALM, MBSE, and CAE Systems already export. That covers a meaningful share of day-to-day "what changed in the BOM / Requirements / Model" questions without needing a vendor-specific connector. Where a native REST connector to the system of record makes more sense than file exports, it's on the roadmap below — we list every vendor by name so a procurement evaluator can confirm fit without a sales call.

Shipped today: file-format Ingestion

PLM exchange formats Shipped

Geometry interchange (STEP / IGES / BREP / IFC / glTF / STL / OBJ / 3MF / USD) ingests via the cad-worker. PLMXML and 3DXML are routed and metadata-extracted. Vendor-native NX (.prt / .asm), CATIA (.catpart / .catproduct), Creo (.prt), SOLIDWORKS (.sldprt / .sldasm), and AutoCAD (.dwg) files Extract natively when the customer brings their own License — see the "BYOL CAD sidecar" card below. Solid Edge (.par / .psm) is routed today and gains the same native-extraction BYOL adapter per-customer-demand.

  • STEP
  • IGES
  • BREP
  • IFC
  • PLMXML
  • 3DXML
  • glTF
  • STL
  • OBJ
  • USD

ALM Requirements (ReqIF) Shipped

OMG Requirements Interchange Format (.reqif / .reqifz) ingests via the office-document-worker's ReqIF branch and lands as structured Requirement records. That covers DOORS Next, Polarion, codebeamer, Jama Connect, and any other ALM tool that publishes its Requirements set as ReqIF — which is most of them.

  • IBM DOORS Next
  • Siemens Polarion
  • PTC Codebeamer
  • Jama Connect

CAE simulation Models & results Shipped

Functional Mock-up Units (.fmu, FMI 2.0 / 3.0) ingest via the FMPy-based fmu-worker. Nastran bulk-data decks (.bdf / .dat) and meshes ingest via the scientific-worker (pyNastran + meshio). Vendor-native binary solver outputs (Abaqus .odb, Ansys result files, Simulink .slx) are routed and quarantined for vendor-side conversion before downstream extraction.

  • FMU (FMI 2.0/3.0)
  • Nastran BDF
  • Meshes (UNV, VTK, MED)
  • Abaqus .inp
  • Ansys .cdb
  • OpenFOAM .foam
  • Fluent .cas
  • Abaqus ODB*
  • Simulink SLX*

ERP / MES exports Shipped

Bill-of-material drops (CSV / XLSX / TSV / JSON), routing sheets, work-order manifests, and vendor master extracts ingest via the structured-worker and land into the operational_data domain with per-column sensitivity classification. SAP, Oracle EBS / Fusion, Microsoft Dynamics, Infor, and IFS all publish in these formats by default for downstream BI — so the export path covers the common case without a vendor connector.

  • CSV / TSV
  • XLSX
  • JSON / JSONL
  • Parquet
  • IDoc XML

MBSE / SysML Models Gated OFF

OMG XMI (.xmi / .xml) exports from MBSE tools ingest as structured-XML; SysML v2 KerML text format is parsed by the same pipeline. Diagrams embedded as images are routed through the VLM worker for caption extraction. Tested with Cameo Systems Modeler and No Magic / 3DS CATIA Magic — your model-library round-trip should be validated against your specific profile.

  • Cameo / 3DS CATIA Magic
  • Capella XMI
  • SysML v2 KerML

Process, Traceability & Co-Simulation Standards Gated OFF

Native parsing of open engineering and operations standards, so process, traceability and system-structure data ingest without a vendor SDK: OCEL 2.0 object-centric event logs (process conformance), GS1 EPCIS 2.0 traceability events (lot / serial / shipment genealogy), and SSP 2.0.1 System Structure & Parameterization for co-simulation architectures. Each is a gated, default-off, air-gap-clean connector — enable it per source.

  • OCEL 2.0
  • GS1 EPCIS 2.0
  • SSP 2.0.1

Structural steel, plant piping & PCB Gated OFF

Native parsing of open structural-steel, plant-piping and PCB interchange — no CAD tool, no dependency, air-gap safe. Steel detailing lands from SDNF (.sdnf) and CIS/2 (.cis2) into one shared steel graph. Plant piping ingests ISOGEN Piping Component Files (.pcf) and CAESAR II pipe-stress neutral files (.cii). PCB board layout ingests IDF (.idf). Navisworks file sets (.nwf) map their appended member models, and AVEVA PDMS / E3D review models (.rvm) reconstruct the SITE / ZONE / equipment hierarchy. Each is a gated, default-off connector.

  • SDNF
  • CIS/2
  • ISOGEN PCF
  • CAESAR II
  • PCB IDF
  • Navisworks NWF
  • AVEVA RVM

Japanese OEM & industry data Gated OFF

Japanese-OEM data readiness across engineering and business systems — every reader is in-house, air-gap safe, and gated default-off. A Shift-JIS / CP932 / EUC-JP / ISO-2022-JP decode layer means legacy Japanese exports land as clean text, not 文字化け (mojibake). chemSHERPA-AI / -CI (.shai / .shci) substance-in-product declarations become a governed article → material → substance graph with CAS number and mass-ppm concentration for RoHS / REACH / ELV / SCIP evidence (extracted as declared data, not a compliance certification). Construction CAD lands from SXF (.sfc / .sxf — JACIC/OCF, the MLIT public-works & i-Construction exchange) and JWW (.jww — Jw_cad, the dominant free JP 2D CAD). Business data reads Zengin (全銀) fixed-width transfer / payment batches and 流通BMS retail EDI (XML) into transaction, line and trading-party records. Each is a gated, default-off connector — enable it per source.

  • Shift-JIS / CP932
  • chemSHERPA
  • SXF
  • JWW
  • Zengin (全銀)
  • 流通BMS

Generic SQL / warehouse pull Shipped

For enterprise Systems that publish a read-only SQL view of their tables — Teamcenter on top of Oracle, ARAS Innovator on top of Microsoft SQL Server, Windchill on top of Oracle, SAP S/4HANA via the embedded Postgres / HANA bridge, IFS on top of Oracle — kiLM connects through the warehouse-puller (Snowflake / BigQuery / Databricks native, Postgres / MSSQL / Oracle via JDBC) and federates the queries into the search + graph stores. Per-table annotation locks the sensitivity tier per column.

Native vendor connectors

Native PLM (Aras, Teamcenter, 3DEXPERIENCE, Windchill), live ALM (Codebeamer REST v3), OpenBOM, Sparx EA OSLC, Cadence BYOL, and the AVEVA family (PI Web API, Historian REST, CONNECT Data Services, AIM, MES REST) now ship — each is marked Shipped below. The remaining connectors (SAP, Oracle, Polarion, DOORS Next, Jama, Cameo, Ansys Minerva) stay on the public roadmap so a procurement evaluator can confirm fit before signing, and so customers know which pulls today rely on the file-export path above versus a future REST / OData / SOAP connector against the system of record. Sequencing is demand-driven: tell us which three matter for your stack and we'll prioritise.

Siemens Teamcenter Shipped

Native pull via Teamcenter Active Workspace JSON-REST (TC Server API): parts, items, BOMs, and change notices — polled on a configurable tick and staged into the manufacturing domain with canonical BOM extraction. BYOL — Teamcenter is customer-owned and customer-licensed; kiLM bundles no Siemens SDK (HTTP/JSON only). Covers both on-prem / self-hosted Active Workspace (cookie session, intranet, air-gap OK) and Teamcenter X (Xcelerator SaaS) via OAuth2 — cloud calls pass the egress policy + SSRF guard and are vetoed in air-gapped installs. Default off; enable the gate after configuring the gateway URL + service account.

Dassault 3DEXPERIENCE Shipped

Native pull via the 3DSpace REST web services: EngItems, documents, and BOM structure — staged into the manufacturing domain with canonical BOM extraction. BYOL — 3DEXPERIENCE is customer-owned and customer-licensed; kiLM bundles no Dassault SDK (HTTP/JSON only). Covers on-prem / private-cloud 3DSpace behind 3DPassport (cookie login, intranet, air-gap OK) and 3DEXPERIENCE-on-Cloud (SaaS) via 3DPassport OAuth2 — cloud calls are egress-policy gated and air-gap-vetoed. Default off; enable the gate after configuring the 3DSpace URL + service account.

Aras Innovator Shipped

Native pull via the Aras IOM OData REST API with OAuth2 password-grant auth: Items, ItemTypes, Part BOMs, ECNs, Document records — polled on a configurable tick (default every 6 hours) and staged into the manufacturing domain. Aras Community Edition is free, so no per-seat License token is consumed for read-only Ingestion; the unnamed service-account pattern also keeps Enterprise Edition deployments off the named-user count. Configure auth URL + service account + tick interval from the customer-side Admin UI — no file editing required. Polled changes only (no event hooks yet). Native Teamcenter, Windchill, and 3DEXPERIENCE PLM connectors now ship on the same pattern (see below).

PTC Windchill Shipped

Native pull via Windchill REST Services (OData domain APIs): parts, documents, and BOM structure — staged into the manufacturing domain with canonical BOM extraction. BYOL — Windchill is customer-owned and customer-licensed; kiLM bundles no PTC SDK or Info*Engine task (HTTP/JSON, GET-based reads). Covers on-prem / private-cloud Windchill (HTTP Basic, intranet, air-gap OK) and Windchill+ / PTC Atlas (SaaS) via OAuth2 — cloud calls are egress-policy gated and air-gap-vetoed. Default off; enable the gate after configuring the Windchill REST URL + service account.

SAP S/4HANA & ECC Planned

Native pull via SAP OData services (S/4HANA Cloud + Business Suite gateways) for material masters, BOMs, purchase orders, and work orders. Today the export-driven CSV / XLSX / IDoc-XML path covers most BI use cases; the native connector adds live document-flow walks and event-driven CDC.

Oracle E-Business Suite & Fusion Planned

Native pull via Oracle Fusion REST / BICC extracts + EBS Integrated SOA Gateway. Today the warehouse-puller (Oracle via JDBC) handles read-only inventory; the native connector adds event subscriptions for procure-to-pay and order-to-cash.

Siemens Polarion (ALM) Planned

Native pull via the Polarion REST API: work items, document trees, traceability links, baselines. Today the ReqIF export path (Shipped above) handles the Requirements set; the native connector adds traceability graph walks and baseline snapshots.

IBM DOORS / DOORS Next Planned

Native pull via OSLC-RM (DOORS Next) and DXL bridge (classic DOORS). Today the ReqIF export path handles Requirements content; the native connector adds OSLC link traversal across DOORS Next configurations.

Cameo / 3DS CATIA Magic (MBSE) Planned

Native pull via the Cameo Collaborator REST API + Teamwork Cloud OSLC. Today the XMI export path covers static Model snapshots; the native connector adds project-on-server diffs and reviewer-comment threads.

Ansys Minerva & Granta Planned

Native pull from Ansys Minerva simulation-process-and-data management and Granta materials Intelligence. Today FMU / Nastran exports cover specific deliverables; the native connector adds simulation lineage + materials selection records.

PTC Codebeamer live REST v3 Shipped

Read-only intranet pull of tracker items and relations via Codebeamer REST API v3 (not OSLC). Scheduled asyncio worker, not Temporal. ReqIF remains the air-gap fallback. Default off; not license-locked. Training data is stamped excluded by default. Source-ACL capture at ingest is available. Polarion and DOORS Next live OSLC pullers remain on the roadmap.

OpenBOM live REST Shipped

Read-only internet pull of OpenBOM SaaS BOM documents via REST. License-locked; not air-gap. Distinct from the PLMXML / STEP-AP242 file path. No OpenBOM SDK and no write-back. Default off. Enable after configuring the OpenBOM app key and secret or access token.

Sparx Enterprise Architect OSLC Shipped

Read-only intranet pull of packages, elements, and connectors via Pro Cloud Server OSLC Architecture Management 2.0. XMI remains the air-gap fallback. Not Codebeamer REST v3. Default off; not license-locked.

AVEVA PI Web API Shipped

Read-only intranet catalogue of Asset Framework elements, templates, PI points, and Event Frames. Does not ingest tag values, streams, or historian samples. PI Server stays the system of record for timeseries. HTTP Basic, Bearer, or Kerberos / Negotiate. No AF SDK; no write-back. Default off; not license-locked.

AVEVA Historian REST Shipped

Read-only intranet OData catalogue of tags, IOServers, and alarm/event metadata. Does not ingest process values or snapshots. Not PI Web API and not CONNECT. HTTP Basic, Bearer, or Kerberos / Negotiate. Default off; not license-locked.

AVEVA CONNECT Data Services Shipped

Read-only internet catalogue of namespaces, assets, asset types, and SDS stream metadata. Does not ingest stream samples. License-locked; not air-gap. Bearer or OAuth2 client credentials. No CONNECT SDK; no write-back. Default off.

AVEVA AIM live Shipped

Read-only internet AIM OData 2.0 catalogue of assets, documents, tagged entities, and 3D model metadata. Does not download files or geometry. License-locked; not air-gap. Default off.

AVEVA MES REST Shipped

Read-only intranet pull of work orders, equipment, and material lots. Discrete genealogy only — no timeseries or OEE samples. Distinct from B2MML file import. HTTP Basic, Bearer, or Kerberos / Negotiate. Default off; not license-locked.

BYOL CAD sidecar — NX, CATIA, Creo, SOLIDWORKS, AutoCAD & Cadence shipped Shipped

The customer brings their own CAD vendor License + install; the platform mounts the install as a sidecar and invokes each vendor's official headless/batch mode (for NX, CATIA, Creo, SOLIDWORKS, AutoCAD and Cadence) to Extract the Model natively — not converted to STEP. Each part emits a JSON sidecar with the feature tree (bounded), parameters, materials with density & mechanical properties, PMI / annotations, assembly & BOM structure, custom attributes, and geometric summary. The platform never ships a CAD kernel, vendor SDK, or License. Single-tenant by design. Per-vendor license-token concurrency cap (default 1, configurable). Customer-side admin configures everything from a central "BYOL Tool Configuration" interface — install dir, License server, tier — no manual config-file editing needed. STEP / Parasolid / 3DXML / IGES export remain available as opt-in workflows when downstream geometry rendering is genuinely needed. Shipped today: NX (Siemens), CATIA V5/V6 (Dassault), Creo (PTC), SOLIDWORKS (Dassault), AutoCAD (Autodesk), and Cadence Allegro / OrCAD / Virtuoso. SOLIDWORKS and AutoCAD run on a Windows host. Cadence uses the same sidecar image with a native SKILL journal. Solid Edge ships on the same rich-extraction pattern per-customer-demand.

Cloud translation & BIM (BYOL) — Autodesk APS, Bentley iTwin, Tekla Gated OFF

Bring-your-own-license paths for formats only the vendor's own engine reads faithfully. Autodesk APS (Forge) Model Derivative translates native part formats (.ipt / .sldprt / .x_t / .x_b / .sat and more) to neutral geometry using the customer's own Autodesk subscription — cloud-based and requires internet egress to Autodesk, so it is excluded on air-gapped installs. Tekla (.db1) reads locally through the Tekla Open API (the customer's own Tekla install) — no internet, air-gap OK, license-locked — and reuses the SDNF / CIS-2 steel graph. Bentley iTwin iModel (.imodel) is wired as a BYOL seam, with the live reader on the roadmap. kiLM bundles no vendor SDK or license; each is default-off until configured.

Licensed Tools (BYOL) & Per-Customer Extensibility

Many of the tools engineering, quality, and operations teams depend on — CAD kernels, solver runtimes, simulation engines — are commercially licensed. kiLM never bundles, embeds, or resells a vendor's licensed software. Where faithful native extraction needs the vendor's own engine, kiLM uses a bring-your-own-license (BYOL) Model: you supply the License and install you already own, and kiLM drives it in place. Open, standards-based interchange formats stay free and fully air-gapped. And because every connector follows the same module-gated pattern, new integrations can be added to fit your specific system landscape and needs.

Bring-your-own-license (BYOL) policy Shipped

For vendor-native formats that only the vendor's own tool can read faithfully — NX, CATIA, Abaqus .odb, MATLAB / Simulink, Revit, Amesim, Dymola — the customer brings their own License and install. kiLM mounts that install as an isolated sidecar and invokes the vendor's official headless tool to Extract natively, rather than guessing at a proprietary binary. We always ask before introducing any paid dependency; nothing licensed is switched on without your explicit decision.

Free & air-gapped by default Shipped

Open, standards-based interchange — STEP, IGES, PLMXML, STEP-AP242, ReqIF, QIF, Q-DAS, STDF, B2MML / ISA-95, VTK, HDF5, FMU, AnIML and the rest — is read by kiLM's own parsers with no vendor SDK, no License token, and no internet. These ship with by-design air-gap support and are off until an operator opts in. Only the vendor-native binary path needs BYOL, and it is always the customer's existing License.

License compliance & isolation Shipped

kiLM never ships a CAD kernel or solver and never holds a vendor License. BYOL adapters are single-tenant by design, run behind a license-locked gate that stays OFF until configured, and honor a per-vendor concurrency cap so your seat count is respected. The customer-side admin sets install path, License server, and tier from a central "BYOL Tool Configuration" screen — no config-file editing, and the License never leaves your environment.

Selectable packages in your quote Shipped

When you request a quote you can opt into named packages. Seven neutral-interchange packs are included at no extra license fee and stay fully air-gapped: Engineering & manufacturing interchange (PLM / ALM / QMS / CAE / MES / metrology / STDF / PLCopen / AutomationML / MBSE, plus free MATLAB / Modelica / Simscape readers), Enterprise & business interchange (SAP IDoc & Ariba cXML, EDI X12/EDIFACT + logistics, OAGIS BOD, IBM Maximo MIF, ServiceNow, Workday), Process & decision modeling (BPMN, DMN, Visio), Healthcare & clinical records (HL7 FHIR, DICOM), Finance, compliance & security (XBRL, OSCAL, CycloneDX / SPDX SBOM, CSAF), Industry 4.0 & digital twin (AAS, OPC-UA NodeSet2, ASAM MDF4), and Technical documentation & PCB fab (S1000D / DITA, Gerber / ODB++). Each turns on only the connector modules you select. Engineering-tool BYOL adapters are available as separate line items — MATLAB Engine, Autodesk Revit / APS, Dymola, Simcenter Amesim, and Abaqus .odb — where you bring your own vendor license and kiLM drives it in place.

  • Engineering & manufacturing interchange (included)
  • Enterprise & business interchange (included)
  • Process & decision modeling (included)
  • Healthcare & clinical records (included)
  • Finance, compliance & security (included)
  • Industry 4.0 & digital twin (included)
  • Technical documentation & PCB fab (included)
  • MATLAB Engine (BYOL)
  • Revit / APS (BYOL)
  • Dymola (BYOL)
  • Amesim (BYOL)
  • Abaqus .odb (BYOL)

Choose Packages in a Quote

Integration Protocols

kiLM speaks the standard protocols your enterprise stack already uses, so the integration surface is auditable rather than bespoke. Every protocol below is covered by the same air-gap and intake-only egress gates.

MCP Shipped

Model Context Protocol over HTTP+SSE and stdio. Both server and sanitizing client modes. Per-client bearer-token + ACL + Audit on every invocation.

REST + Server-Sent Events Shipped

A published REST API with an OpenAPI specification. Chat and long-running jobs stream over Server-Sent Events (SSE), under a versioned namespace.

Webhooks Shipped

Outbound webhooks via an at-least-once outbox pattern with HMAC-SHA256 signing, exponential backoff, and a dead-letter queue. Subscribers configure event filters per endpoint.

OAuth 2.0 + OpenID Connect Shipped

All authentication routes through Keycloak. Token exchange, refresh, PKCE, service-account credentials, and per-tenant realms supported out of the box.

SMTP & Microsoft Graph Shipped

SMTP for outbound delivery; inbound mail comes via Microsoft Graph or Exchange Web Services. IMAP and POP3 Ingestion are intentionally not supported.

S3-compatible storage Shipped

SeaweedFS is bundled as the default object lake. Any S3-compatible backend works — AWS S3, Backblaze B2, Wasabi, or your own MinIO cluster.

PostgreSQL Shipped

Primary warehouse + per-domain partitions. Postgres-compatible warehouses (Redshift, CockroachDB) federate via the generic JDBC path.

Kafka Shipped

Event-bus subscription via aiokafka. Topic-scoped subscriptions, consumer-group offsets, and replay markers — Kafka is the first adapter; others are planned.

CDC delete events Gated OFF

REST endpoint that accepts change-data-capture delete events for governed erasure — deterministic idempotency by event signature, still routed through dual approval. Full CDC source connectors (Debezium and friends) are planned.

Temporal Shipped

All long-running work is a Temporal workflow with deterministic replay, explicit retry policies, and per-activity Audit. Self-hosted, no external Temporal Cloud dependency.

Local LLMs (Bundled Runtime)

kiLM ships with a fully local LLM runtime and a curated registry of open-weight community models, each verified by the kiLM team on the matching hardware. You are never locked in: any open-weight LLM you choose can be run, and a hardware-aware router automatically picks the most-capable model that fits your GPU envelope — so no model is ever hard-coded.

Verified Community Models Shipped

Examples we validate out of the box — CPU-only: Phi-3 mini, Llama 3.1 8B. Workstation GPU: Mixtral 8x7B (q4). Datacenter GPU: Qwen 2.5 72B, DeepSeek-Coder 67B, Llama 4 Scout (q4, ~109B total / 17B active). Vision: LLaVA. All released under permissive open licenses and validated by kiLM on the corresponding hardware tier. Prefer a different or newer model? Bring it — the registry is open.

  • phi3:mini
  • llama3.1
  • mixtral:8x7b
  • qwen2.5:72b
  • deepseek-coder:67b
  • llama-4-scout
  • llava

Newer Frontier Models (Operator-verify-required) Preview

The registry also seeds newer community frontier models, each carrying the verify_by_operator flag. Their sizing figures — VRAM, context, runtime class — are placeholders kiLM has not measured, so the hardware-aware router skips these rows entirely rather than routing a turn onto numbers it cannot stand behind. Your admin reviews and clears the values in the model registry (Admin → Model Registry), and only then does the router consider the model. This keeps the registry forward-looking without kiLM promising anything it has not independently validated.

  • glm-5.1
  • kimi-k2.6
  • gemma-4-31b
  • qwen-3.6
  • deepseek-v4

Hardware-aware router Shipped

The runtime router classifies your install into one of five hardware tiers — CPU-only, consumer GPU, workstation GPU, datacenter GPU, and multi-GPU — and picks the most-capable model that fits. It re-checks the available GPUs automatically, and your admin can override the tier from the admin console. Every fallback is recorded with a reason, so you can audit why a particular turn used a smaller model.

QLoRA Fine-Tuning (Unsloth) Shipped

Fine-tune any registry model that supports it, using the bundled Unsloth QLoRA worker. A hardware-aware pre-flight refuses jobs that would exceed the available GPU memory, so you never start a training run that can't finish. Results become first-class registry entries the router can pick from immediately.

Cloud Services

When your Governance posture allows cloud egress, kiLM connects to the hyperscaler and SaaS services your data already lives in. When it doesn't, every cloud connector here can be disabled by flipping a single gate — the air-gap install profile turns them all off at runtime.

AWS S3 & S3-compatible Shipped

First-class data lake target. Bring your own S3 endpoint, or use the bundled SeaweedFS for fully-isolated deployments. Backblaze B2 and Wasabi tested.

Google Workspace Gated OFF

Google Drive for content pull; Google Identity for federated authentication. Both independently gated.

Microsoft 365 Gated OFF

SharePoint Online, OneDrive, Exchange (Graph + EWS), and Azure AD federation. Manifest export for Microsoft 365 Copilot.

Box Gated OFF

Box Business / Enterprise pull with metadata templates preserved through ingest.

Dropbox Gated OFF

Team folder pull. Same cloud-storage egress gate as Drive, OneDrive, Box.

Cloud data warehouses Gated OFF

Snowflake, BigQuery, Databricks. Each warehouse is a separately-gated federation; no single switch unlocks the lot.

Identity federation Gated OFF

Azure AD, Okta, Google Identity — kiLM uses the standard OIDC discovery flow through Keycloak.

Stripe Gated OFF

Usage-based billing export for MCP-consumer accounts. CSV by default; Stripe push is opt-in.

Inbound APIs & Upload Mechanics

Beyond the file formats and the SaaS connectors, several low-level surfaces let your platform call kiLM, push files in, or auto-ingest from buckets — without writing a custom HTTP client.

Python SDK Shipped

A Python SDK ships with every release, with typed wrappers for the admin, search, chat, ingest, inference, and webhook APIs — including ingest helpers. Bring-your-own bearer token; everything routes through the same OpenAPI spec.

Admin ingest endpoints Shipped

A POST API kicks ingestion for a single object already staged in the object lake, and a batch POST API accepts up to a thousand object references and queues each one through the standard routing path. Useful for pipelines that hand off batches at the end of an upstream run.

Signed S3 PUT URLs Shipped

The Upload page mints a short-lived signed PUT URL so the browser uploads directly to the object lake, then POSTs an ingest trigger. Scripts can request the same URL via the admin API. Size limits and magic-byte sniff enforced server-side.

Multipart upload Shipped

Standard multipart for airgap release-bundle upload, support-request and enhancement attachments, and admin import flows. Streaming size cap + content-type allowlist on every endpoint.

Object-store notifications → auto-ingest Shipped

External pipelines can drop objects straight into a watched object-store bucket; the lake-watcher worker receives the bucket-notification webhook and kicks the standard Ingestion workflow. Per-bucket auto-ingest toggle.

Chat SSE streaming Shipped

Server-Sent Events stream chat responses — tokens, citations, tool decisions, conflict signals, task-dispatcher events. The MCP server uses the same transport.

Local MCP stdio bridge Shipped

A local MCP bridge exposes kiLM's MCP tools to local clients like Claude Desktop and Cursor over standard input/output, without opening an HTTP port on the workstation.

Archive explode & re-route Gated OFF

When the archive gate is ON, uploaded ZIP / TAR / 7Z / etc. are unpacked into a staging area, scanned for nested code or executables, then each member is re-injected into the standard Ingestion router as if it had been uploaded directly. Expansion limits and per-member quotas keep runaway archives bounded.

Failure-recovery reroute Shipped

If a worker's extractor fails — wrong extension, mistyped MIME, vendor PDF that's really an image — kiLM sniffs the file's magic bytes and reroutes it to the worker that should have handled it in the first place. The reroute is audited; reconciliation flags persistent misrouting patterns so admins can fix the upstream source.

Chat-attachment Ingestion Gated OFF

Files dropped into the chat composer become session-scoped Knowledge — visible to that conversation only, with their own retention policy. Not the same as permanent corpus Ingestion; use the save-to-corpus task verb to promote a useful attachment.

Structured record Ingestion Shipped

The structured-worker path normalizes records, tables, and spreadsheets into searchable row-level entries with schema-aware extraction. Persistent upsert into per-domain tables is still evolving — current Ingestion is read-then-index; mutation semantics follow on a future slice.

Outbound Traffic & Exports

When kiLM emits — events, reports, telemetry, evidence bundles — every channel is observable and most are gated. The intake-only profile blocks all outbound paths; the air-gap profile additionally blocks the vendor heartbeat.

Outbound HTTP webhooks Shipped

Event notifications for findings, proposals, Model promotions, config changes, ingest completions, and more. At-least-once outbox + HMAC-SHA256 signing + per-endpoint event filters + dead-letter queue.

SMTP (STARTTLS / TLS) Shipped

Outbound email for emailed reports, ask-by-email replies, system notifications. Honors your SMTP provider's STARTTLS upgrade and pinned TLS modes; auth via username/password or service-account credentials.

Vendor heartbeat Gated OFF

Counts-only HTTPS POST to the vendor portal for License + capacity telemetry. No business data, no chat content, no document metadata. Records-then-skips under air-gap; queueable for later import.

Alertmanager-compatible webhook Shipped

The bundled Prometheus + Alertmanager stack routes operational alerts to any HTTP receiver — Slack, PagerDuty, Opsgenie, Microsoft Teams, or your own incident webhook. SLO breaches, capacity thresholds, reconciliation findings all surface here.

Signed download URLs Shipped

Short-lived, signed download links for generated reports, request attachments, support bundles, and release artifacts. URLs include per-resource access checks; downloads are audit-logged.

Report & data exports Shipped

Native renderers for the formats finance, ops, and ML teams actually consume. Reports, billing rollups, feedback exports, Training datasets — all formats below.

  • DOCX
  • PDF
  • XLSX
  • CSV
  • JSONL
  • Parquet

Support bundle (tar.gz + GPG) Shipped

Deterministic diagnostic snapshot — config, logs, schema, gate state, recent findings — packaged as a GPG-signed tar.gz. Designed for offline transfer to vendor support; never auto-uploaded.

Airgap release bundle Shipped

Versioned, signature-verified release artifact for offline update of airgap installs. Each bundle includes images, migrations, schema, OpenAPI, SBOMs, and the operator documentation that goes into the system-manuals corpus.

Identity & Access Integration

Authentication flows through the bundled Keycloak realm. Federation, machine-to-machine, user-delegated, and signed-payload integrations are all first-class.

OIDC federation Gated OFF

Pre-built presets for Microsoft Entra (Azure AD), Okta, Google Workspace, and any generic OIDC issuer with discovery. Each provider is independently gated.

SAML 2.0 Gated OFF

Generic SAML 2.0 federation via the bundled Keycloak — metadata URL + signing keys, ADFS / OneLogin / Auth0 / Ping / Shibboleth all federate via this path.

LDAP / Active Directory Gated OFF

User federation against Active Directory, OpenLDAP, FreeIPA, or any LDAPv3 server. Read-only or read-write attribute mapping. Optional Kerberos pass-through.

OAuth 2.0 client credentials Shipped

Machine-to-machine auth for the Python SDK, MCP clients, the Copilot connector, and backend service principals. Per-client scopes, per-realm credential rotation.

OAuth 2.0 authorization code + PKCE Shipped

User-delegated grants for the webapp, the MCP browser flow, and selected cloud-storage and email integrations that need consented per-user access (Microsoft Graph, Google Drive).

Bearer tokens Shipped

JWT bearer tokens issued by Keycloak authenticate every REST, MCP, SDK, and Copilot call. Standard expiry + refresh; service-account tokens optional for long-running integrations.

HMAC-SHA256 signatures Shipped

Used wherever a bearer token isn't appropriate: object-store bucket events, outbound webhooks, Label Studio review callbacks, vendor heartbeat. Subscribers verify with the published signing key.

If you don't see your stack on this page, ask. Most enterprise Systems plug into the same puller pattern, and we keep this page honest about what's shipped versus on the way.

Preferences saved on this device.