CLIENT KALEM CONTROL PLANE DHCP LEASE IPAM CIDR ALLOC DNS DNSSEC · DDNS LEASE ✓ DDNS ✓ DISCOVER
Sovereign Native-Code Air-Gap Capable

Kalem DDI

Unified DDI Platform — DNS · DHCP · IPAM

Kalem DDI unifies authoritative DNS, DHCP and IP address management into a single, sovereign control plane. Built from the ground up for a small, auditable attack surface, it delivers gap-finding CIDR allocation, DHCPv4 leasing, DNSSEC-signed authoritative DNS and automatic lease-to-DDNS-to-IPAM synchronisation — with single sign-on, hash-chained audit and post-quantum readiness throughout.

Sovereign REST API DNSSEC Post-Quantum DNSSEC

DNS, DHCP and IPAM — finally in one control plane

Most networks run these as three disconnected tools that drift apart. Kalem operates them as one consistent system.

DNS

Authoritative DNS + DNSSEC

Signed zones and fast authoritative answers, with dynamic updates driven straight from live DHCP leases.

DHCP

DHCPv4 Engine

Lease management with reservations, option sets and high-availability operation across your network.

IPAM

IP Address Management

One source of truth for subnets and addresses — gap-finding CIDR allocation and network discovery.

Everything the network plan needs

A complete DDI feature set, engineered as one codebase and exposed through typed REST services.

Authoritative DNS + DNSSEC

Signed, authoritative zones with DDNS updates — no split between DNS and the address plan.

DHCPv4 Engine

Reservations, option policies and lease lifecycle managed from the same control plane.

IPAM & CIDR Allocation

Gap-finding allocation across subnets, attribute validation and a clean allocation history.

Lease → DDNS → IPAM Sync

Every lease automatically flows into DNS and the address inventory — always consistent.

Network Discovery

Reconcile the live network against the inventory to find drift and unmanaged addresses.

SSO & RBAC

Standards-based single sign-on, roles and per-service API keys for fine-grained access.

Hash-Chained Audit

A SHA-256 hash-chained audit log makes every change tamper-evident and reviewable.

Post-Quantum Ready

Cryptography designed for the quantum era via our Nizam work — future-proof by default.

Engineered for control, not lock-in

Kalem is a from-scratch, native codebase — the modern, sovereign successor to legacy DDI appliances.

One Control Plane

DNS, DHCP and IPAM operated together as one system — not three disconnected, drifting tools.

Single Codebase

One audited, compiled codebase; no interpreted languages in production, a minimal attack surface.

API-First

Every service exposes a typed REST API for automation, IaC and third-party integration.

Native Identity

Identity, roles and service-to-service authentication are built in from the first commit.

Tamper-Evident Audit

Hash-chained change history across the whole platform — court-defensible and easy to review.

Sovereign & Air-Gap

Runs fully on-prem and in closed networks, with no external cloud dependency.

Have a project in mind?

We're happy to talk — whether you need a product, consulting, or just want to bounce ideas.