Platform
A platform built as a system — not a stack of services.
Four layers, one mental model. Your people, your data and your rules come together in one coherent platform — every decision traceable to its source, every language model replaceable.
Spring 2026 release
Further reach. More evidence. More control.
Three directions our customers asked for most. The platform now reaches deeper into the field, proves more about every answer it produces, and puts more controls in the hands of your own administrators.
NATS event mesh
End-to-end messaging from edge agent to platform. Per-device credentials, JetStream durability, and a NATS-to-Pulsar bridge for systems already on Pulsar.
Fleet & edge devices
Manage hundreds of edge agents from one console. Device groups, signed self-updates, live event streams and remote browse — without opening inbound ports.
IndentiaLocal
Desktop and NAS agent that indexes local files with on-device embeddings, an encrypted credential vault and a signed update channel.
Visual ontology editor
Shape your company ontology by drawing it. Drag to connect, right-click to edit, embedded directly in the back office.
Audit time-machine
Replay the platform's audit stream to any moment in time. For incident reviews, regulator questions and "who knew what, when".
Data Hub & lineage
Structured, unstructured and IoT data combined in one entity-keyed hub — with OpenLineage on every record, queryable in the same knowledge graph as the data itself.
Structured-data stack
Federated SQL over warehouses, databases, lakehouses and streams — Trino under a sovereign query gateway, Superset for BI, DataHub for catalogue and lineage.
Unified User Experience
One shared shell across Search, AI Chat, Translator, AI Agents, BackOffice and more. Integrated look and feel. With browser and Microsoft Office extensions.
Row-level ACL on the graph
Permissions enforced inside IndentiaDB itself, with live change subscriptions over WebSocket.
Document Intelligence
Smart parser routing that races multiple extraction engines in parallel and picks the best result automatically — verified by an LLM judge. Supports PDF, Office, images and more.
Lexicon
Enterprise terminology lifecycle management — propose, review, approve, deprecate and SHACL-validate terms against your business ontology, with DataHub sync and gap detection.
That's eleven of them. Browse the full Indentia product stack → — twenty-seven apps and extensions, grouped by purpose.
Reference architecture · 2026
The Indentia stack at a glance.
Ingestion, semantic curation, governance, storage, orchestration, delivery, experience and intelligence — one coherent vertical slice with zero-trust on the left and observability on the right. Print it, hand it to your architect, walk through it together.
Layer 1 · Knowledge graph
IndentiaDB
A multi-tenant knowledge database that connects every entity from every source. Documents, emails, customers, contracts, projects and risks — under one company ontology, with stable IRIs under id.indentia.ai.
- ✓ Per-tenant isolation in the IRI itself — no cross-realm leakage
- ✓ Property-graph and RDF in the same store
- ✓ Row-level ACL enforced inside the graph, with live change subscriptions
- ✓ Disk-backed HNSW vectors for hybrid retrieval
- ✓ Time-machine replay — query the graph at any point in its history
- ✓ SPARQL 1.2 federated queries — combine multiple graphs in a single statement using the W3C SERVICE directive
- ✓ Production-grade durability — every committed write is fsynced, checksummed and automatically recovered after a crash or power loss; no data is ever partially written
Layer 2 · Search
Enterprise Search & RAG
Search SharePoint, Salesforce, Confluence, network drives and email from one interface. Hybrid retrieval (BM25 + dense + graph context), with security trimming at the ACL level and citations on every claim.
- ✓ Hybrid Search — BM25 + vector + RRF re-ranking
- ✓ Deep understanding of long documents
- ✓ Security trimming — users only see what they're entitled to
- ✓ Citation-backed — every answer with a direct link to the source
- ✓ Federated facets to easily filter your search results
- ✓ Native Dutch — RobBERT-2022 embedding model understands Dutch the way Dutch speakers actually write it
- ✓ Government Q&A — parliamentary questions and official decisions rendered inline, linked to persons, dossiers and source documents
Layer 3 · Agents
Autonomous Agent Runtime
Versioned agents in a registry, evaluated in their own harness, deployed in a sandboxed runtime with five security layers. Every tool call audited, every model swappable.
- ✓ MicroVM sandbox — five security layers per agent
- ✓ Multi-step reasoning, self-correction, proactive insights
- ✓ Workspace memory (SOUL.md, MEMORY.md) — persistent context per agent
- ✓ Bring your own model — connect the AI Gateway to your own local LLMs or frontier AI models (incl. OpenAI, Anthropic, Gemini, Ollama, Azure)
The true power of agents
This is where agents stop being assistants and start being colleagues. A copilot makes a human 20–40% faster on a task they were already going to do. An agent runs the task end-to-end — intake, triage, drafting, reconciliation, resolution — while a human supervises at checkpoints. That isn't a percentage uplift; it's a 10× to 40× shift in throughput. Klarna replaced the workload of 600 customer-service agents with autonomous AI. Palantir compressed underwriting and intake projects that used to take a year into a week. The Autonomous Agent Runtime is how you get that leverage on your data, behind your policies, with every step provable in the audit trail.
Layer 4 · Governance
AI Governance & Compliance
Policies, risks, controls and assessments — modelled as data, not as PDFs. Aligned out of the box with the EU AI Act, NIS2, ISO 27001 and ISO 42001.
- ✓ Policy-as-data with versioned change management
- ✓ Full audit trail — every retrieval, every output traceable
- ✓ Pre-built assessments for AI Act, NIS2, ISO 27001/42001
- ✓ Continuous evidence collection from the runtime
- ✓ OpenLineage data lineage landing directly in the knowledge graph
Open by construction
No magic. Standards, used well.
RDF + IRI
Every entity has a stable, tenant-scoped IRI under id.indentia.ai.
Per-tenant IdP
Each tenant runs its own Identity Provider — Keycloak, Authentik, Azure AD, ADFS. Identity flows through OIDC, SAML and ABAC into every query.
OpenTelemetry
Traces, metrics and logs in the format your SOC already speaks.
S3 + Postgres
Storage primitives you can audit, back up and migrate — even without us.
Replayable events
Every change is an event. New consumers replay from offset zero.
Bring your own model
Connect the AI Gateway to your own local LLMs or frontier AI models — incl. OpenAI, Anthropic, Gemini, Ollama, Azure.
NATS & Pulsar
An event mesh that reaches from edge devices to the central platform — both protocols, with a bridge between them.
OpenLineage
Cross-system data lineage in a format your data team already knows — stored as RDF in the same graph.
W3C trace-context
End-to-end traces from edge agent to LLM call, propagated across NATS, HTTP and WebSocket.
SPARQL 1.2
W3C SPARQL 1.2 federated queries with the SERVICE directive, RDF 1.2 triple terms, and native streaming in CSV, TSV, XML and JSON.
Capability deep dives
The pillars under the platform.
Five capabilities that distinguish a sovereign cognitive platform from a generic AI stack.
Security & trust
Zero-trust runtime, semantic ABAC, STANAG 4774/4778 labels, PKI + mTLS, HSM-backed keys at EAL4+ / FIPS 140-3 L3.
Edge & autonomy
Disconnected operation, on-device ONNX inference, firmware attestation, NATS leaf-sync, signed agent updates.
Data mesh & governance
Per-domain ownership, ontology-driven contracts, federated SPARQL, label propagation, OPA + ODRL policy-as-code.
Human oversight & HITL
Four explicit gates, AbstentionGate, releasability, STANAG 4559 metadata, NATO CoT output, signed decision log.
Strategic autonomy
Your keys, your code, your hardware, your jurisdiction. Built to outlive any single vendor — including us.
Connectors
Indentia unlocks knowledge where it actually lives.
600+ connectors out of the box — SaaS and on-premises, cloud drives and NAS, structured databases and streaming endpoints. The platform preserves metadata, permission structures and context — so even awkward sources become as usable as structured data in dashboards.
On-premises data integration is genuinely hard — legacy ACL models, brittle connectors, throughput limits, undocumented schemas, half-broken fileshares. We know, because we've done it. Indentia has a track record of ingesting 50 million+ documents for production deployments, with provenance and permissions intact end-to-end. The connector grid below is what the platform ships with; the experience behind it is what makes the rollout finish.
Microsoft 365
SharePoint, OneDrive, Outlook, Teams
Google Workspace
Drive, Gmail, Docs
CRM & Support
Salesforce, HubSpot, Zendesk, ServiceNow
Wiki & Docs
Confluence, Notion, Coda
Chat
Slack, Microsoft Teams, Mattermost
Cloud storage
AWS S3, Azure Blob, Google Cloud
On-premises
Fileshares, NAS, SMB, NFS
Edge & IoT
IndentiaLocal agent, NATS-connected devices, OT sensors
Email & SMTP
Inbound capture mailboxes, base32-routed workflows
Lineage & events
OpenLineage, NATS JetStream, Apache Pulsar
Government & OSINT
Rijksoverheid.nl, Tweede Kamer documents, open OSINT endpoints
Custom
REST, GraphQL, JDBC via Connector Studio
Deployment
Lands on your cluster. Stays on your cluster.
Indentia ships as a GitOps-managed bundle. ArgoCD applications, Helm charts and Kustomize overlays — auditable, diffable, yours. Air-gapped installs include a mirrored registry and an offline evaluation harness. Hybrid deployment is possible: sensitive data local, non-sensitive workloads in an EU cloud if you prefer.