Why the scope of review is smaller than you expect
K-Lake is deployed on your infrastructure. In normal operation we do not receive, store or
process your document data, which typically narrows a vendor assessment considerably compared
with a cloud service that holds a copy of your estate.
The document estate, the index and permission enforcement all remain inside your perimeter.
Where you choose to connect a cloud model, only the specific retrieved, permission-checked
snippet is sent, under your own agreement with that model vendor. Where you require full
isolation, K-Lake runs against a local model with no external egress at all.
Licensing is enforced offline. There is no licence-server call-home, and no telemetry leaves
your environment — metrics and logs are exposed for your own monitoring stack rather than
sent to us. That is what makes air-gapped deployment possible rather than theoretical.
Security
Controls you can inspect
Permission-aware retrieval enforced at query time against your existing identity provider,
and enforced in the database by row-level security rather than in application code — so
access is denied by default and new code paths inherit the control automatically. Strict
tenant isolation at the same layer. The core services and every connector are written in
Rust, which removes memory-corruption vulnerability classes by construction. Every answer
carries a citation, so any output can be checked against its source.
Privacy
Data residency by design
Your data does not leave your environment, so residency is a property of where you deploy
rather than a contractual promise about where we store things. Aligned to UK GDPR and GDPR.
Compliance
Built for regulated review
Designed for organisations subject to DORA, FCA rules, NHS data governance, HIPAA and
public-sector data policy. Our certification roadmap is published below rather than implied.