Your data stays inside your boundary.
Pometry processes data in place. Nothing is copied, replicated or transmitted to an external system.
Built to the standards our customers are held to.
Pometry runs in tier one global banks, G7 government agencies and defence organisations.
Certified
Information security management is certified to ISO 27001, covering risk treatment, access control and incident handling.
Deployed inside your controllership
Pometry runs as software in your environment and meets all GDPR requirements.
Runs with no external network access
Deployed offline with government and defence customers, including agencies in the US, UK and Europe.
Control down to a single edge, and a record of who saw what.
Permissions apply to the model itself rather than to a copy of it, so the same controls hold whether a person or an agent is asking.
Fine-grained access control
Role-based control down to individual nodes, edges and time windows, applied without changing the underlying data model.
Full audit logging
Queries, answers and agent actions are logged, so what was asked and what was returned can be reconstructed after the fact.
Data lineage built in
Every answer traces to the records and timestamps behind it, which is the same mechanism that makes regulatory evidence possible.
Frequently asked by security teams.
For the architecture behind these answers, see System Specifications.
Where can it run?
On-premise bare metal, private cloud (AWS, Azure, GCP), hybrid, Kubernetes, or embedded inside an existing application so it inherits that system's security boundary. It also runs fully offline with no external network access, which is how it is deployed with government and defence customers. A single 10MB binary that you run yourself, with no call out to a vendor cloud.
Where does our data end up?
Where it already is. Pometry reads your systems in place and writes the graph to disk inside your own infrastructure, under your existing storage, backup and encryption controls. Residency and sovereignty follow from where you chose to deploy, not from a decision of ours.
Do you train models on our data?
No. Pometry is infrastructure, not a model provider, and we have no mechanism to train on your data because it never reaches us. One thing to be clear about: if you connect a hosted model, the query results Pometry returns are sent to that provider under your contract with them. Where that is unacceptable, Pometry works with open-weight models running inside your own boundary.
How is access controlled for AI agents?
The caller's identity is carried into the query and permissions are evaluated at traversal time, down to individual nodes, edges and time windows, so an agent resolves only what its caller could resolve. Every traversal is logged against that identity. Controls on what an agent then does with an answer it was entitled to sit with your AI platform.
What happens to our data if we stop using Pometry?
The data stays on your disk, in Arrow-backed columnar files inside your own infrastructure. Column-level data is readable with standard Arrow tooling and exports to Parquet or CSV without involving us. Only reading it as a temporal graph requires the Pometry licence and binary.
Experience Pometry in action
with a live demo.
Find out how you can close your visibility gap with unique, institutional intelligence.