One control plane. Run it your way.
Open source, self-hosted, or fully managed Private beta — start where it fits and grow into the rest. Vakamo sits on top of your existing stack and governs what’s already there, with no rip-and-replace.
Your whole data landscape — not just the easy part
A small slice of your data lives in governed tables. Most of it — the documents, files and context your AI reads — never has. Vakamo governs both.
Deterministic reads are reproducible; probabilistic AI reads are not. Lakekeeper governs and records both — every access tied to an identity and a policy.
Enforcement at the control plane — not observation after the fact
Every request — from a person or an AI agent — passes through Lakekeeper. Policy is evaluated at the moment of access, and the access is durably recorded.
- Who is asking — identity & role
- What they want — the resource
- What policy applies
Access is authorized at the control plane before any engine touches data — not reconstructed from logs afterwards.
Credentials are issued per request, scoped to the task, and expire on their own — no static keys, no standing access.
Access policies are declarative and version-controlled — reviewed, diffed, and rolled out like any other code, not clicked together in a console.
Built on the Apache Iceberg REST standard and works with your current identity provider — no rip-and-replace.
Lakekeeper administers and enforces access without reading your data contents — control without custody.
Governance enforced at one point — the catalog, not per engine
Every engine reaches your data through one Iceberg REST catalog — Lakekeeper — so policy, credentials and audit are enforced at a single point, not per engine.
- Access control & policy
- Short-lived credential vending
- Audit & lineage
Structured data and files — governed today
Databases, reports and files (as generic datasets over object storage, v0.13), AI context and versioned objects — all under Lakekeeper’s control.
Core
Open Source Foundation
The open-source foundation: catalog your data and control who can access it — on open standards, running anywhere.
Enterprise Self-Hosted
Real enforcement, a full audit trail and policy as code — self-hosted, with enterprise support.
Structured data
- Fine-grained access control
- Short-lived credentials
- Complete audit trail
- Automatic upkeep
Documents & AI
- Govern documents & files
- AI context & embeddings
- Versioned objects
- Generic tables & datasets over object storage
Fully Managed SaaS
We run it, you govern. Fully managed by Vakamo — availability and scaling handled for you.
Request a quote or more info
Tell us about your environment and we'll come back with pricing and next steps.