ontos
A subset of Enclave — the knowledge-graph layer of Enclave's sovereign AI company brain.
What Ontos is
Ontos is an in-VPC knowledge-graph runtime. It:
- Extracts typed entities and typed relationships from an enterprise's data (documents, communications, systems of record).
- Persists them as immutable, bitemporally-valid, provenance-tagged facts.
- Serves them to LLM agents through a Model Context Protocol (MCP) interface, with permission-aware graph traversal.
- Emits a compliance-grade audit record for every query.
Ontos is the "relationships" half of Enclave's company brain. Where the retrieval substrate answers what a document says, Ontos answers how things connect — who owns what, what depends on what, what changed when, and what the source-of-truth was on a given date.
Every fact carries provenance. Every query is audit-ready. Every deployment runs inside the customer's VPC.
Where Ontos sits in the Enclave family
| Component | Role |
|---|---|
| enclave-runtime | Retrieval substrate — document/passage retrieval inside the customer's VPC. |
| ontos (this repo) | Knowledge-graph layer — typed entities and relationships with provenance, bitemporal validity, and permission-aware traversal. |
| enclave-scribe | Sovereign extraction model (in development). Replaces the current LlamaIndex/LangChain extractors in ontos/extraction/ once it passes benchmarks against current frontier models. |
| enclave-ocr | Document and image OCR for the ingestion path. |
| enclave-gtm, enclave-home, enclave-business, … | Product surfaces that consume Ontos through MCP. |
Status
0.1.0 (first public release) — the runtime works end-to-end: ingest a directory of text files via ontos ingest, query it via ontos query "..." or the ask MCP tool, verify the audit chain via ontos audit verify. See CHANGELOG.md for what shipped in this release and docs/design/ for the per-milestone architecture notes.
Quickstart (dev)
uv sync --extra dev
uv run ontos
Then point any MCP-speaking client (Claude Code, Cursor, Codex, Gemini CLI) at the streamable-HTTP endpoint printed on start.
Design pillars
- Every fact carries provenance —
(source_id, extractor_version, confidence, t_valid, t_invalid)on every triple. - Every query carries an audit record — EU AI Act Article 12: ≥12 fields per AI-influenced decision, ≥6 mo retention, per-user attribution.
- Permission-aware traversal at the executor — paths crossing forbidden nodes pruned during traversal, not after. Zero node-existence leakage.
- Bitemporal correctness —
as_ofon every read; contradictions close old validity windows. - Planner/executor split — LLM writes typed plans over the ontology; deterministic executor runs multi-hop retrieval.
- Sovereign by architecture — nothing leaves the customer VPC. Deployable air-gapped.
MCP tools (v0)
search(query, as_of?, k?, agent_identity)— semantic + graph retrievaltraverse(start, relation, depth, as_of?, agent_identity)— permission-aware multi-hopexplain(entity_id, as_of?, agent_identity)— entity dossier with sourcesprovenance(fact_id)— full provenance chain for one factaudit(query_id)— Article-12 audit record for a prior queryas_of(query, timestamp, agent_identity)— historical query for regulatory review
Layout
ontos/
├── runtime/ # FastMCP server + tool surface
├── planner/ # NL → typed plan over ontology
├── executor/ # multi-hop + PPR + pruning + authz-aware traversal
├── extraction/ # LlamaIndex/LangChain wrappers today; migrates to enclave-scribe once Scribe passes benchmarks
├── ontology/ # LinkML / YAML schemas
├── storage/ # backend-agnostic (Neo4j / NetworkX / Neptune)
├── authz/ # OpenFGA / SpiceDB
├── audit/ # Article-12 audit emitter
└── ingest/ # source connectors
Contributing
Ontos is open-source and we actively want outside contributors. Start with:
- CONTRIBUTING.md — dev setup, coding standards, the non-negotiable invariants, and the PR process.
- CODE_OF_CONDUCT.md — Contributor Covenant v2.1.
- SECURITY.md — how to report a vulnerability (do not open a public issue for security bugs).
- GitHub Issues for bugs and feature proposals; GitHub Discussions for questions and design conversations.
License
Apache-2.0.
Release files for enclave-ontos 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| enclave_ontos-0.1.0.tar.gz | 386.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| enclave_ontos-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 449.9 kB
Release files / enclave_ontos-0.1.0.tar.gz
| Download URL | enclave_ontos-0.1.0.tar.gz |
|---|---|
| Size | 386.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
49ab214ee443093e83513c7cb43f5bb6a3530c2c528b24a909affc900a8e72cd
|
|
BLAKE2b-256 checksum How to use checksums |
ec27c2885bbe86e2279f61d6679f9dd1284a6c58d60fe3953cbe4275062260d6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / enclave_ontos-0.1.0-py3-none-any.whl
| Download URL | enclave_ontos-0.1.0-py3-none-any.whl |
|---|---|
| Size | 63.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
407db31e959c56a8a26cd941b30115cf37a057a82771c31cf184c2d5134a469e
|
|
BLAKE2b-256 checksum How to use checksums |
13e39e6868527b558e99caaa42efedd5f75ee0b4d9e55f3ecae636caf168cbd7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log