Private preview.

Govern every answer your data gives.
Human or AI.

The governed gateway between your organisation's data and everything that reads it. One definition of what the data means, one set of rules about who may see it - applied before a value is returned.

1
Governed gateway
14
Connectors wired
0
Cloud required
See how it works
Governed request PDPL
Asked byn.alotaibi@bank.sa · Analyst, Retailvia Agent (MCP)

“Average balance of retail customers in Riyadh this quarter?”

  1. Identity resolved
    Entra ID · group: retail-analytics
  2. Row security applied
    region = RIYADH · segment = RETAIL
  3. Masking applied
    national_id → •••• ••• 4821 · iban → SA•• •••• 7730
  4. Query served
    1 measure · 3,412 rows · 212 ms
Answer
SAR 48,210
Audit record #a3f9c2 written

Works with the engines you already run

PostgreSQL
Oracle
Snowflake
SQLSQL Server
Google BigQuery
MongoDB
Databricks
MySQL
Amazon Redshift
Elasticsearch
ClickHouse
SAP
DuckDB
QdQdrant
Why Vektor

Every AI system wants your data.
Not all of them should see it.

Agents, copilots, dashboards and notebooks each open their own door into production. Vektor closes them and leaves one - governed, identity-aware and audited.

Direct access

Every tool its own door

Each system connects to production with its own credentials. Masking depends on whoever wrote the query, nobody can say who read what, and an agent inherits everything its service account can reach.

Through Vektor

One governed path

Every request passes one layer. Row-level security, masking and residency apply before a value is returned, the caller's own identity decides what they see, and all of it lands in an audit log.

Identity travels with the query

An agent acting for a user sees exactly what that user may see - never what its service account could reach.

Controls live in the path

Masking, row-level security and residency are enforced on the way out, not documented in a catalogue nobody consults.

Evidence, not assurances

Every question, the SQL it became, who asked and what came back - kept, searchable and exportable.

How it works

Four layers. One path.

Connect a source, agree on what it means, attach the rules, and serve it to every consumer under the same contract.

Connect any source in minutes

Point Vektor at a database or vector store. It reads the schema, keys, constraints and column comments, then profiles the data to see what is actually in it - national IDs and IBANs among them, found by checksum rather than guessed at.

  • 14 engines, relational to vector
  • Read-only, credential-scoped connection
  • Deterministic PII discovery
Sources

Connect every database
and every vector store.

Fourteen engines wired today - relational, warehouse, document and search. The same governance applies to every one, and adding the next is configuration rather than a rebuild.

PostgreSQL
Relational
MySQL
Relational
Oracle
Relational
SQL
SQL Server
Relational
Snowflake
Warehouse
Google BigQuery
Warehouse
Amazon Redshift
Warehouse
Databricks
Warehouse
ClickHouse
Warehouse
DuckDB
Warehouse
SAP
Relational
MongoDB
Document
Elasticsearch
Search & vector
Qd
Qdrant
Search & vector

What teams use it for

One gateway, six jobs. Each one is a project on its own without it.

Governed AI access

Let agents and assistants query real business data without handing them a service account. An agent cannot read a row its caller cannot read.

Ask in plain language

Your team asks in Arabic or English and gets an answer traced back to the exact query that produced it, with the constraints stated in words.

Sensitive data, controlled

National IDs, IBANs and phone numbers found deterministically, classified, and masked at the gateway before a value reaches anyone.

One semantic model

Define a measure once. Chat, a dashboard, a scheduled document and an external agent all compute it the same way.

Answers you can audit

Every question, the query it resolved to, who asked and what came back - written down, searchable, exportable as evidence.

Runs on your soil

Your data centre, your cloud account, or fully air-gapped with no route off the network. Your LLM key, or a local model.

Sovereignty

Built for the frameworks
your regulator actually names.

Vektor deploys where the data already is - your data centre, your cloud account, or with no route off the network at all. Arabic is a language the product thinks in, not one it was translated into.

Your data centre

Containers on your own hardware. Nothing leaves the building.

Your cloud account

Deployed into your tenancy on any local region. You hold the keys.

Air-gapped

No route off the network. Bring a local model and it still works.

Framework coverage

  • PDPLSaudi Personal Data Protection Law · SDAIADesigned against
  • NDMONational data management standardsDesigned against
  • SAMA CSFCyber security framework for bankingOn the roadmap
  • NCA ECCEssential cybersecurity controlsOn the roadmap
  • GDPRFor the export caseOn the roadmap

We report evidence and coverage, never a verdict. Vektor shows what was checked, what it found, and what it could not see. The certificate is the regulator's to give.

FAQ

Questions teams ask before a pilot

Does Vektor store a copy of our data?

No. Vektor sits in the query path and returns results from your own systems. It stores metadata - the semantic model, policies and the audit log - and nothing else unless you turn on result caching, which is off by default and lives inside your deployment.

Which LLM does it use, and where does it run?

Yours. Bring a key for a hosted model in a local region, or point Vektor at a model running on your own hardware. Prompts never include raw rows unless the policy for that caller allows it, and the model is never the thing enforcing a rule - the gateway is.

How does it know who is asking when an agent makes the request?

Agents connect through the MCP server or the API with a token that carries the end user's identity from your IdP. Row-level security and masking are evaluated against that identity, so an agent can never read a row its caller could not read directly.

What does 'designed against PDPL' mean in practice?

The controls PDPL expects - purpose limitation, minimisation, residency, subject-access evidence - map to concrete Vektor features, and the audit log is built to answer the questions an assessor asks. It is not a certificate; that remains the regulator's to give.

How long does a pilot take?

A copy of one real source, the model built with your team, and your own questions asked against it - typically two to four weeks. You keep the semantic model whatever you decide afterwards.

Does it work in Arabic?

Natively. Business terms, questions and answers work in Arabic and English, and the interface is fully right-to-left. It was built for Arabic first, not translated into it.

Bring a schema. We will show you it working on that.

Not a sandbox and not a slide. We connect a copy of a real source, build the model with you, and you ask it what your team actually asks.

See how it works