Nothing reads your data until Lakekeeper says yes.

The governance layer between every engine, every agent and your data.

Define policy once. Enforce it everywhere.

SparkTrinoDatabricksSnowflakeAI agents
Lakekeeper
Policy · Vend credentials · Audit
S3ADLSGCS
Running in production at
Kantoxa leading German banking groupa global footwear retailerEnterpriseDB

Open source (Apache 2.0)500k+ monthly downloadsAir-gapped deploymentCommercial support by Vakamo

What changed

Your data used to be read by people. Now AI reads it too.

A few known people used to touch your data, at human pace, mostly across governed tables. Now AI agents read across all of it — documents, emails, files — thousands of times a day, on their own.

Before
People read your data
  • A few known people
  • Slow, human pace
  • Mostly the governed tables
Now
AI agents read it too
  • Thousands of automated reads
  • Across documents, emails, files
  • Data no one ever governed
  • 84%

    doubt they could pass a compliance audit on AI agent behaviour or access controls

    Cloud Security Alliance / Strata Identity, February 2026
  • 18%

    are highly confident their IAM can manage agent identities

    Cloud Security Alliance / Strata Identity, February 2026
  • 63%

    of breached organisations had no AI governance in place

    IBM, Cost of a Data Breach 2025
What you will be asked to evidence

Your AI does 99% of the work. Your signature carries 100% of the liability.

Under DORA and NIS2, the management body is accountable for ICT risk — not the vendor, and not the platform team.

  1. Can you name every identity — human or agent — that read this table last quarter?
  2. Which policy allowed it, and who approved that policy?
  3. Can you reproduce the exact data an agent saw on a given date?
  4. All of that, across every engine, in one place?
Lakekeeper answers all four. Every request — person or AI agent — is checked against your policy and recorded before any data is read. One record, across every engine.
Three ways to respond

Only one of them holds up.

Not enough
Document it
  • The policy lives in a document nobody queries.
  • The agent asks for data. Nothing checks.
  • You reconstruct what happened from logs, if there are any.
  • You find out after the fact. Too late to act.
Fragmented
Push it to each engine
  • A copy of the policy per engine, drifting apart.
  • Each one checks a little differently.
  • Five partial answers to reconcile by hand.
  • No single source of truth.
Controlled
Enforce it
  • One policy, reviewed like code.
  • Every request checked before any data is read.
  • One record: who, what, under which policy.
  • One answer, whatever engine asks.
What you get

Less risk. Faster teams. Provable compliance.

Risk reduction

Every request is evaluated before data is accessed. Unauthorized reads never happen, reducing exposure before incidents begin.

Audit evidence

Hand auditors a complete, durably recorded, append-only record — proof, not promises. One append-only history of who accessed what, under which policy.

Evidence for your obligations under:EU AI Act · GDPR · DORA
AI readiness

Put AI to work on governed data from day one — no weeks of access reviews.

Speed without standing risk

Access is granted per task and expires on its own — fast, with no doors left open.

See it enforce your policies

A 30-minute walkthrough against your data and your rules.

See it in action
Trusted in production

Running in banks, retailers and regulated enterprises

Leading German banking group
Global footwear retailer
Aerospace & defence
European insurance
A global content delivery network
European hyperscaler

Built on — the open-source Apache Iceberg REST Catalog. Apache 2.0, 500,000+ downloads a month.