People cannot find it
Years of reports, contracts and manuals sit buried in folders no one remembers, in formats no one can search well. Staff spend hours locating information the organisation already owns.
The Zero Egress AI Platform
K-Lake by Zegress.Ai connects the file shares and storage you already own to the AI assistants your people already use. The documents, the index and your permissions all stay inside your perimeter. Every answer cites the source it came from.
No data leaves · No migration · No vendor lock-in
Only the specific retrieved, permission-checked snippet ever crosses, under your own vendor agreement. Choose a local model instead and nothing crosses at all.
The problem
Three barriers stop enterprise AI reaching the knowledge you already own — and in regulated sectors the third one ends the conversation.
Years of reports, contracts and manuals sit buried in folders no one remembers, in formats no one can search well. Staff spend hours locating information the organisation already owns.
Today's assistants only know what you paste in. Your private documents stay invisible, so the model either guesses or cannot help with the work that actually matters.
Getting AI to read your documents normally means copying them somewhere else first — chunked, embedded and re-indexed in a store you don’t hold, with the original permissions re-implemented rather than enforced. In regulated sectors that ends the conversation.
What we believe
Every other answer starts by moving your documents. Ours starts by leaving them exactly where they are, under the permissions they already carry, and bringing the intelligence to them.
How it works
From your existing storage to cited answers, without a migration project in between.
Point K-Lake at where your knowledge already lives — network shares, object storage, document stores. It reads in place across SMB, NFS, S3, Azure Blob, OneDrive and SharePoint, on Dell, HPE, NetApp, Pure and others. Nothing is migrated, copied or modified.
Every document is read, including scanned PDFs, tables and complex layouts, and each page becomes searchable by meaning and by keyword. Audio and video are indexed alongside, with timestamps you can click straight through to.
Your assistants answer from your documents with a citation back to the source, trimmed to what each person is already permitted to see — all inside your own walls.
What you get
Not a wrapper on someone else's cloud. A retrieval layer you run, with the controls your security and compliance teams need to sign off.
Connects your document estate in place. No migration, no re-platforming, no second copy of sensitive data to govern.
Existing file permissions honoured and trimmed at query time via Entra ID, Google, Keycloak, Okta or OAuth. Enforced by row-level security in the database, not application code, so access is denied by default and fails closed.
Every answer links back to the exact source document. No guessing, and a full audit trail for anyone who has to defend the answer.
Meaning and keyword together, so you find the document that answers the question rather than the one that repeats the words.
Demonstrated answering questions with the internet physically disconnected. Licensing is enforced offline with no licence-server call-home, and no telemetry ever leaves your environment.
The core services and every connector are written in Rust, eliminating buffer overflows, use-after-free and data races at compile time — the vulnerability classes behind a large share of CVEs in systems software.
Works with Copilot, Claude, ChatGPT, Gemini or a private local model over the open MCP standard. Change your mind later without changing your data.
Search what was said and shown inside recordings, indexed alongside documents, with clickable timestamps back to the moment.
See what changed in a document and when, line by line. Extract the people, organisations and topics across the estate, permission-trimmed and cited.
Who it is for
K-Lake is built for the enterprise that already owns its storage, is under pressure to show AI productivity, and cannot accept a cloud service holding a copy of its documents.
Assemble a review pack from siloed shares in minutes, with every fact traceable to source for the audit trail. Surface related accounts, narratives and connected parties per alert.
Ask what your policy says and where you are exposed across thousands of documents, and get a cited answer your compliance team can defend to a regulator.
Staff ask in plain language, in multiple languages, and get cited answers from internal policies, manuals and past projects — only from what they are already allowed to open.
The difference
| Typical cloud AI | K-Lake | |
|---|---|---|
| Your data | Sent to an external service | Stays on your infrastructure, even air-gapped |
| Accuracy | Can guess or hallucinate | Grounded in your documents, with citations |
| Finding answers | Keyword search alone misses | Keyword and meaning: 62% more right answers |
| Permissions | Re-permissioning and remapping projects | Your existing access model, trimmed at query time |
| Vendor lock-in | Tied to one provider | Open MCP standard, any model you approve |
| Deployment | A big, slow project | Single command, or one click on Azure Marketplace |
Retrieval figures reflect internal benchmarking and are indicative of the architecture, not a warranty of performance on any given document set. The 92% accuracy figure is an independent evaluation on public SEC filings. Any accuracy claim for your organisation should come from a proof-of-concept on your own documents.
Pricing
Roll it out to everyone without a per-user tax. Bought through the Azure Marketplace on one Azure bill, and it counts toward your Microsoft commitment.
Public plans are self-service on the Azure Marketplace; capacity is metered per cluster. Microsoft-billed on one Azure bill, not bring-your-own-licence, co-sell eligible, and eligible against your Azure Consumption Commitment. Enterprise is a private, negotiated offer where the rate steps down as committed capacity grows — talk to us for the volume schedule.
Transact through the Microsoft Azure Marketplace: one Azure bill, no new vendor onboarding, and the spend draws down against your existing Azure commitment.
Questions we get asked first
No. The document estate, the search index and permission enforcement all stay inside your perimeter. If you choose to point K-Lake at a cloud model such as Copilot or Claude, only the specific retrieved, permission-checked snippet is sent, under your own agreement with that vendor. If you require full isolation, K-Lake runs against a local model with no external egress at all.
Location isn’t custody. An in-tenant AI service still has to chunk, embed and store your document estate in a new index, and the original file permissions are re-implemented in that index rather than enforced. The questions to ask are how many copies of the corpus now exist, who holds them, and whether the copy still knows who is allowed to read each file. K-Lake reads the files in place and trims at query time against the permissions already on them.
No. K-Lake connects in place to SMB, NFS, S3, Azure Blob, OneDrive and SharePoint across Dell, HPE, NetApp, Pure Storage and others. Nothing is migrated, copied or modified.
Yes. K-Lake has been demonstrated answering questions with the internet physically disconnected. Licensing is enforced offline, with no licence-server call-home. You still get full observability — every service exposes Prometheus-format metrics and structured logs to your own monitoring and SIEM — but none of it is sent to us. Nothing leaves, and nothing needs to, so it works behind the strictest firewalls.
Access is trimmed at query time against your existing identity provider, including Microsoft Entra ID, Google, Keycloak, Okta and OAuth. If someone cannot open a document today, they will not see it or its content in an AI answer. There is no re-permissioning and no account remapping.
Because fuzzy matches never grant. Correlating file-side identities — Active Directory SIDs, POSIX groups — to caller-side ones from Entra ID or Okta produces edges rated high or medium confidence, and only exact identity keys expand access. A name-based near-match is recorded and visible, but authorises nobody until an operator verifies it. Enforcement itself sits in the database as row-level security rather than in application code, so access is denied by default and every surface inherits it.
Through the Microsoft Azure Marketplace on a single Azure bill. It is not bring-your-own-licence, it counts toward your Microsoft Azure Consumption Commitment, and it is co-sell eligible. Enterprise deployments above 50 TB are handled as a private, negotiated offer.
A working proof-of-concept stands up with a single command, or one click on the Azure Marketplace, on your infrastructure using your documents. Most proofs-of-concept are answering real questions within the first week.
About Zegress
Zegress.Ai is a specialist house, not a generalist reseller. We work on one problem: making enterprise AI usable on the data that cannot leave the building. That focus shapes everything — the architecture, the deployment model, and the fact that every answer carries a citation.
Custody, policy authority and deployment choice stay with you. The boundary is yours, not ours.
We ask why not before accepting how it has always been done, then solve the real adoption barrier.
Confident in the architecture, not the ego. We would rather prove it on your data than argue about it.
We win alongside your infrastructure partners and your existing AI vendors, not instead of them.
Start here
We will stand up a working proof-of-concept on your infrastructure, using your documents, behind your firewall. A single command, or one click on the Azure Marketplace.
Try it on your data Or email [email protected]
Prefer to talk first? Email [email protected].