The Zero Egress AI Platform

Your AI can finally read your files.Nothing leaves.

K-Lake by Zegress.Ai connects the file shares and storage you already own to the AI assistants your people already use. The documents, the index and your permissions all stay inside your perimeter. Every answer cites the source it came from.

No data leaves  ·  No migration  ·  No vendor lock-in

Live viewWhat crosses the line
Your infrastructure
K-Lake index · permissions · citations
inside
outside
Your AI assistant receives one checked snippet

Only the specific retrieved, permission-checked snippet ever crosses, under your own vendor agreement. Choose a local model instead and nothing crosses at all.

+62%
more of the right answers than keyword search alone
92%
answer accuracy on an independent financial-document benchmark
100%
retrieval and index inside your perimeter, even air-gapped
1
command to stand up a proof-of-concept on your own data

The problem

Your company knows a lot.
Your AI knows none of it.

Three barriers stop enterprise AI reaching the knowledge you already own — and in regulated sectors the third one ends the conversation.

People cannot find it

Years of reports, contracts and manuals sit buried in folders no one remembers, in formats no one can search well. Staff spend hours locating information the organisation already owns.

AI cannot reach it

Today's assistants only know what you paste in. Your private documents stay invisible, so the model either guesses or cannot help with the work that actually matters.

Every tool wants a copy

Getting AI to read your documents normally means copying them somewhere else first — chunked, embedded and re-indexed in a store you don’t hold, with the original permissions re-implemented rather than enforced. In regulated sectors that ends the conversation.

What we believe

AI should move to the data — not the data to the AI.

Every other answer starts by moving your documents. Ours starts by leaving them exactly where they are, under the permissions they already carry, and bringing the intelligence to them.

How it works

Three steps. Nothing copied, nothing moved.

From your existing storage to cited answers, without a migration project in between.

STEP 01

Connect

Point K-Lake at where your knowledge already lives — network shares, object storage, document stores. It reads in place across SMB, NFS, S3, Azure Blob, OneDrive and SharePoint, on Dell, HPE, NetApp, Pure and others. Nothing is migrated, copied or modified.

STEP 02

Understand

Every document is read, including scanned PDFs, tables and complex layouts, and each page becomes searchable by meaning and by keyword. Audio and video are indexed alongside, with timestamps you can click straight through to.

STEP 03

Serve securely

Your assistants answer from your documents with a citation back to the source, trimmed to what each person is already permitted to see — all inside your own walls.

What you get

Built for the questions a CISO actually asks

Not a wrapper on someone else's cloud. A retrieval layer you run, with the controls your security and compliance teams need to sign off.

Zero-copy connectivity

Connects your document estate in place. No migration, no re-platforming, no second copy of sensitive data to govern.

Permission-aware retrieval

Existing file permissions honoured and trimmed at query time via Entra ID, Google, Keycloak, Okta or OAuth. Enforced by row-level security in the database, not application code, so access is denied by default and fails closed.

Grounded citations

Every answer links back to the exact source document. No guessing, and a full audit trail for anyone who has to defend the answer.

Hybrid retrieval

Meaning and keyword together, so you find the document that answers the question rather than the one that repeats the words.

Air-gapped operation

Demonstrated answering questions with the internet physically disconnected. Licensing is enforced offline with no licence-server call-home, and no telemetry ever leaves your environment.

Memory-safe by construction

The core services and every connector are written in Rust, eliminating buffer overflows, use-after-free and data races at compile time — the vulnerability classes behind a large share of CVEs in systems software.

Model-agnostic by design

Works with Copilot, Claude, ChatGPT, Gemini or a private local model over the open MCP standard. Change your mind later without changing your data.

Audio and video search

Search what was said and shown inside recordings, indexed alongside documents, with clickable timestamps back to the moment.

Version history and entities

See what changed in a document and when, line by line. Extract the people, organisations and topics across the estate, permission-trimmed and cited.

Who it is for

Organisations that were told no

K-Lake is built for the enterprise that already owns its storage, is under pressure to show AI productivity, and cannot accept a cloud service holding a copy of its documents.

Financial services · DORA, MiFID II, FCA Legal · privilege and matter data Healthcare and life sciences · PHI, NHS governance Government and public sector · sovereign data Defence and aerospace · air-gapped estates

KYC, AML and investigations

Assemble a review pack from siloed shares in minutes, with every fact traceable to source for the audit trail. Surface related accounts, narratives and connected parties per alert.

Compliance and regulatory answers

Ask what your policy says and where you are exposed across thousands of documents, and get a cited answer your compliance team can defend to a regulator.

The private company brain

Staff ask in plain language, in multiple languages, and get cited answers from internal policies, manuals and past projects — only from what they are already allowed to open.

The difference

Why this is not another cloud AI tool

 Typical cloud AIK-Lake
Your dataSent to an external serviceStays on your infrastructure, even air-gapped
AccuracyCan guess or hallucinateGrounded in your documents, with citations
Finding answersKeyword search alone missesKeyword and meaning: 62% more right answers
PermissionsRe-permissioning and remapping projectsYour existing access model, trimmed at query time
Vendor lock-inTied to one providerOpen MCP standard, any model you approve
DeploymentA big, slow projectSingle command, or one click on Azure Marketplace

Retrieval figures reflect internal benchmarking and are indicative of the architecture, not a warranty of performance on any given document set. The 92% accuracy figure is an independent evaluation on public SEC filings. Any accuracy claim for your organisation should come from a proof-of-concept on your own documents.

Pricing

Priced on capacity, not on seats

Roll it out to everyone without a per-user tax. Bought through the Azure Marketplace on one Azure bill, and it counts toward your Microsoft commitment.

Small

1 TB capacity
$150
per month
≈ $1,800 / year
Public Buy on Azure Marketplace

Medium

10 TB capacity
$1,500
per month
≈ $18,000 / year
Public Buy on Azure Marketplace

Large

50 TB capacity
$7,500
per month
≈ $90,000 / year
Public Buy on Azure Marketplace

Enterprise

50 TB and above
Custom
negotiated
private offer
Private Request a private offer

Public plans are self-service on the Azure Marketplace; capacity is metered per cluster. Microsoft-billed on one Azure bill, not bring-your-own-licence, co-sell eligible, and eligible against your Azure Consumption Commitment. Enterprise is a private, negotiated offer where the rate steps down as committed capacity grows — talk to us for the volume schedule.

Buy it the way procurement already approved

Transact through the Microsoft Azure Marketplace: one Azure bill, no new vendor onboarding, and the spend draws down against your existing Azure commitment.

One Azure billNot BYOLMACC-eligible Co-sell eligible3% marketplace fee

Questions we get asked first

The security review, answered up front

Does any of our data leave our infrastructure?

No. The document estate, the search index and permission enforcement all stay inside your perimeter. If you choose to point K-Lake at a cloud model such as Copilot or Claude, only the specific retrieved, permission-checked snippet is sent, under your own agreement with that vendor. If you require full isolation, K-Lake runs against a local model with no external egress at all.

We already run AI inside our own tenant — isn’t that already zero egress?

Location isn’t custody. An in-tenant AI service still has to chunk, embed and store your document estate in a new index, and the original file permissions are re-implemented in that index rather than enforced. The questions to ask are how many copies of the corpus now exist, who holds them, and whether the copy still knows who is allowed to read each file. K-Lake reads the files in place and trims at query time against the permissions already on them.

Do we have to migrate or copy our documents?

No. K-Lake connects in place to SMB, NFS, S3, Azure Blob, OneDrive and SharePoint across Dell, HPE, NetApp, Pure Storage and others. Nothing is migrated, copied or modified.

Can it run air-gapped?

Yes. K-Lake has been demonstrated answering questions with the internet physically disconnected. Licensing is enforced offline, with no licence-server call-home. You still get full observability — every service exposes Prometheus-format metrics and structured logs to your own monitoring and SIEM — but none of it is sent to us. Nothing leaves, and nothing needs to, so it works behind the strictest firewalls.

How are existing file permissions handled?

Access is trimmed at query time against your existing identity provider, including Microsoft Entra ID, Google, Keycloak, Okta and OAuth. If someone cannot open a document today, they will not see it or its content in an AI answer. There is no re-permissioning and no account remapping.

How do you know your permission model hasn’t granted someone access by mistake?

Because fuzzy matches never grant. Correlating file-side identities — Active Directory SIDs, POSIX groups — to caller-side ones from Entra ID or Okta produces edges rated high or medium confidence, and only exact identity keys expand access. A name-based near-match is recorded and visible, but authorises nobody until an operator verifies it. Enforcement itself sits in the database as row-level security rather than in application code, so access is denied by default and every surface inherits it.

How is it bought and billed?

Through the Microsoft Azure Marketplace on a single Azure bill. It is not bring-your-own-licence, it counts toward your Microsoft Azure Consumption Commitment, and it is co-sell eligible. Enterprise deployments above 50 TB are handled as a private, negotiated offer.

How quickly can we see it working on our own data?

A working proof-of-concept stands up with a single command, or one click on the Azure Marketplace, on your infrastructure using your documents. Most proofs-of-concept are answering real questions within the first week.

About Zegress

We build for the answer that has to hold up

Zegress.Ai is a specialist house, not a generalist reseller. We work on one problem: making enterprise AI usable on the data that cannot leave the building. That focus shapes everything — the architecture, the deployment model, and the fact that every answer carries a citation.

Read the Zegress story

Your rules

Custody, policy authority and deployment choice stay with you. The boundary is yours, not ours.

Usefully curious

We ask why not before accepting how it has always been done, then solve the real adoption barrier.

Confident, not loud

Confident in the architecture, not the ego. We would rather prove it on your data than argue about it.

Collaborative

We win alongside your infrastructure partners and your existing AI vendors, not instead of them.

Start here

See it on your own data.

We will stand up a working proof-of-concept on your infrastructure, using your documents, behind your firewall. A single command, or one click on the Azure Marketplace.

No data leaves No migration No vendor lock-in

Try it on your data Or email [email protected]

Prefer to talk first? Email [email protected].