Control comes before intelligence.

CogLake treats search, preview, download, graph traversal, REST, and MCP as one authorization boundary. A useful answer is returned only after identity and access are resolved.

Permissions do not stop at the search box.

The same decision model protects direct document IDs, chunks, citations, original links, downloads, related graph nodes, API calls, and agent tools.

01

Identity and SSO

Local accounts and enterprise OIDC establish stable user identities before any knowledge request is evaluated.

02

Scoped agent access

API keys and OAuth clients receive explicit scopes, expiry, rotation evidence, and revocation controls.

03

Layered authorization

Platform roles, workspace rights, connector grants, source ACLs, and public-link policy resolve centrally.

04

Verified retrieval

Fast candidate filtering is followed by authoritative API checks before content, originals, or graph paths leave the system.

05

Audit evidence

Administrative changes, searches, downloads, connector jobs, repairs, and agent activity remain attributable.

06

Repair and recovery

Permission drift repair, idempotent jobs, failed-document repair, encrypted backups, and restore probes support day-two operations.

Technical controls for governed deployments.

CogLake supports EU-hosted managed environments, dedicated deployments, and on-premises operation. Deployment-specific legal assessment, policies, and formal certifications remain the responsibility of the operating organization.

Data residency
EU managed, dedicated, or customer-controlled on-premises boundaries.
Model boundary
Hosted, OpenAI-compatible, or local inference selected per deployment.
Secrets
Encrypted connector credentials with versioned key handling and rotation workflows.
Recovery
Encrypted exports, local snapshots, restore choices, and index rebuild controls.

No certification theatre. CogLake provides technical controls and deploys on ISO 27001-controlled infrastructure where contracted. We distinguish those controls from a product certification and document the selected boundary during evaluation.

Deployment options

Govern the work, not only the lookup.

AI Workspace extends central administration to models, provider keys, MCP connections, skills and action approvals. Source access and tool execution remain separate permission decisions.

Explore AI Workspace

Evaluate security against your real boundary.

Bring your identity provider, source permissions, deployment constraints, and audit requirements to a focused technical review.

Book a walkthrough