Nothing reads your data until Lakekeeper says yes.
The governance layer between every engine, every agent and your data.
Define policy once. Enforce it everywhere.
Open source (Apache 2.0)500k+ monthly downloadsAir-gapped deploymentCommercial support by Vakamo
Your data used to be read by people. Now AI reads it too.
A few known people used to touch your data, at human pace, mostly across governed tables. Now AI agents read across all of it — documents, emails, files — thousands of times a day, on their own.
- A few known people
- Slow, human pace
- Mostly the governed tables
- Thousands of automated reads
- Across documents, emails, files
- Data no one ever governed
- 84%
doubt they could pass a compliance audit on AI agent behaviour or access controls
Cloud Security Alliance / Strata Identity, February 2026 - 18%
are highly confident their IAM can manage agent identities
Cloud Security Alliance / Strata Identity, February 2026 - 63%
of breached organisations had no AI governance in place
IBM, Cost of a Data Breach 2025
Your AI does 99% of the work. Your signature carries 100% of the liability.
Under DORA and NIS2, the management body is accountable for ICT risk — not the vendor, and not the platform team.
- Can you name every identity — human or agent — that read this table last quarter?
- Which policy allowed it, and who approved that policy?
- Can you reproduce the exact data an agent saw on a given date?
- All of that, across every engine, in one place?
Only one of them holds up.
- The policy lives in a document nobody queries.
- The agent asks for data. Nothing checks.
- You reconstruct what happened from logs, if there are any.
- You find out after the fact. Too late to act.
- A copy of the policy per engine, drifting apart.
- Each one checks a little differently.
- Five partial answers to reconcile by hand.
- No single source of truth.
- One policy, reviewed like code.
- Every request checked before any data is read.
- One record: who, what, under which policy.
- One answer, whatever engine asks.
Less risk. Faster teams. Provable compliance.
Every request is evaluated before data is accessed. Unauthorized reads never happen, reducing exposure before incidents begin.
Hand auditors a complete, durably recorded, append-only record — proof, not promises. One append-only history of who accessed what, under which policy.
Put AI to work on governed data from day one — no weeks of access reviews.
Access is granted per task and expires on its own — fast, with no doors left open.
See it enforce your policies
A 30-minute walkthrough against your data and your rules.
Running in banks, retailers and regulated enterprises

Built on — the open-source Apache Iceberg REST Catalog. Apache 2.0, 500,000+ downloads a month.