Data Governance

Policy enforced in the query path, at the point of compute. Talk to us about scoping your own data governance programme.

Starts with Classification

Every table and column enters a versioned catalogue. Each field is classified and bound to policy at the schema, and reclassified as the estate changes.

Enforcement

Every request is evaluated against the classification before it executes, and resolves to allow, mask, hash, tokenise, redact or deny. An explicit deny beats any grant inherited above it.

Inheritance

What a model may receive is a separate decision from what a person may read. Only schema and aggregates cross to a frontier model. Model placement is policy: local, in-region, or vendor-hosted.

Audit

Append-only and hash-chained, held in the customer's own database and exportable to their SIEM. Every denial is written, with no sampling.