Skip to main content

ontos

CI License Python

A subset of Enclave — the knowledge-graph layer of Enclave's sovereign AI company brain.

What Ontos is

Ontos is an in-VPC knowledge-graph runtime. It:

  1. Extracts typed entities and typed relationships from an enterprise's data (documents, communications, systems of record).
  2. Persists them as immutable, bitemporally-valid, provenance-tagged facts.
  3. Serves them to LLM agents through a Model Context Protocol (MCP) interface, with permission-aware graph traversal.
  4. Emits a compliance-grade audit record for every query.

Ontos is the "relationships" half of Enclave's company brain. Where the retrieval substrate answers what a document says, Ontos answers how things connect — who owns what, what depends on what, what changed when, and what the source-of-truth was on a given date.

Every fact carries provenance. Every query is audit-ready. Every deployment runs inside the customer's VPC.

Where Ontos sits in the Enclave family

Component Role
enclave-runtime Retrieval substrate — document/passage retrieval inside the customer's VPC.
ontos (this repo) Knowledge-graph layer — typed entities and relationships with provenance, bitemporal validity, and permission-aware traversal.
enclave-scribe Sovereign extraction model (in development). Replaces the current LlamaIndex/LangChain extractors in ontos/extraction/ once it passes benchmarks against current frontier models.
enclave-ocr Document and image OCR for the ingestion path.
enclave-gtm, enclave-home, enclave-business, … Product surfaces that consume Ontos through MCP.

Status

0.1.0 (first public release) — the runtime works end-to-end: ingest a directory of text files via ontos ingest, query it via ontos query "..." or the ask MCP tool, verify the audit chain via ontos audit verify. See CHANGELOG.md for what shipped in this release and docs/design/ for the per-milestone architecture notes.

Quickstart (dev)

uv sync --extra dev
uv run ontos

Then point any MCP-speaking client (Claude Code, Cursor, Codex, Gemini CLI) at the streamable-HTTP endpoint printed on start.

Design pillars

  1. Every fact carries provenance — (source_id, extractor_version, confidence, t_valid, t_invalid) on every triple.
  2. Every query carries an audit record — EU AI Act Article 12: ≥12 fields per AI-influenced decision, ≥6 mo retention, per-user attribution.
  3. Permission-aware traversal at the executor — paths crossing forbidden nodes pruned during traversal, not after. Zero node-existence leakage.
  4. Bitemporal correctness — as_of on every read; contradictions close old validity windows.
  5. Planner/executor split — LLM writes typed plans over the ontology; deterministic executor runs multi-hop retrieval.
  6. Sovereign by architecture — nothing leaves the customer VPC. Deployable air-gapped.

MCP tools (v0)

  • search(query, as_of?, k?, agent_identity) — semantic + graph retrieval
  • traverse(start, relation, depth, as_of?, agent_identity) — permission-aware multi-hop
  • explain(entity_id, as_of?, agent_identity) — entity dossier with sources
  • provenance(fact_id) — full provenance chain for one fact
  • audit(query_id) — Article-12 audit record for a prior query
  • as_of(query, timestamp, agent_identity) — historical query for regulatory review

Layout

ontos/
├── runtime/     # FastMCP server + tool surface
├── planner/     # NL → typed plan over ontology
├── executor/    # multi-hop + PPR + pruning + authz-aware traversal
├── extraction/  # LlamaIndex/LangChain wrappers today; migrates to enclave-scribe once Scribe passes benchmarks
├── ontology/    # LinkML / YAML schemas
├── storage/     # backend-agnostic (Neo4j / NetworkX / Neptune)
├── authz/       # OpenFGA / SpiceDB
├── audit/       # Article-12 audit emitter
└── ingest/      # source connectors

Contributing

Ontos is open-source and we actively want outside contributors. Start with:

  • CONTRIBUTING.md — dev setup, coding standards, the non-negotiable invariants, and the PR process.
  • CODE_OF_CONDUCT.md — Contributor Covenant v2.1.
  • SECURITY.md — how to report a vulnerability (do not open a public issue for security bugs).
  • GitHub Issues for bugs and feature proposals; GitHub Discussions for questions and design conversations.

License

Apache-2.0.

Release files for enclave-ontos 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for enclave-ontos 0.1.0
File Size Uploaded
enclave_ontos-0.1.0.tar.gz 386.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for enclave-ontos 0.1.0
File Interpreter ABI Platform
enclave_ontos-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 449.9 kB

Release files / enclave_ontos-0.1.0.tar.gz

Download URL enclave_ontos-0.1.0.tar.gz
Size 386.6 kB
Tags Source
SHA-256 checksum
How to use checksums
49ab214ee443093e83513c7cb43f5bb6a3530c2c528b24a909affc900a8e72cd
BLAKE2b-256 checksum
How to use checksums
ec27c2885bbe86e2279f61d6679f9dd1284a6c58d60fe3953cbe4275062260d6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / enclave_ontos-0.1.0-py3-none-any.whl

Download URL enclave_ontos-0.1.0-py3-none-any.whl
Size 63.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
407db31e959c56a8a26cd941b30115cf37a057a82771c31cf184c2d5134a469e
BLAKE2b-256 checksum
How to use checksums
13e39e6868527b558e99caaa42efedd5f75ee0b4d9e55f3ecae636caf168cbd7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page