Request a demo
Security

Your data stays inside your boundary.

Pometry processes data in place. Nothing is copied, replicated or transmitted to an external system.

Assurance

Built to the standards our customers are held to.

Pometry runs in tier one global banks, G7 government agencies and defence organisations.

ISO 27001

Certified

Information security management is certified to ISO 27001, covering risk treatment, access control and incident handling.

GDPR

Deployed inside your controllership

Pometry runs as software in your environment and meets all GDPR requirements.

Air-gapped

Runs with no external network access

Deployed offline with government and defence customers, including agencies in the US, UK and Europe.

Controls

Control down to a single edge, and a record of who saw what.

Permissions apply to the model itself rather than to a copy of it, so the same controls hold whether a person or an agent is asking.

Fine-grained access control

Role-based control down to individual nodes, edges and time windows, applied without changing the underlying data model.

Full audit logging

Queries, answers and agent actions are logged, so what was asked and what was returned can be reconstructed after the fact.

Data lineage built in

Every answer traces to the records and timestamps behind it, which is the same mechanism that makes regulatory evidence possible.

Common questions

Frequently asked by security teams.

For the architecture behind these answers, see System Specifications.

Where can it run?

On-premise bare metal, private cloud (AWS, Azure, GCP), hybrid, Kubernetes, or embedded inside an existing application so it inherits that system's security boundary. It also runs fully offline with no external network access, which is how it is deployed with government and defence customers. A single 10MB binary that you run yourself, with no call out to a vendor cloud.

Where does our data end up?

Where it already is. Pometry reads your systems in place and writes the graph to disk inside your own infrastructure, under your existing storage, backup and encryption controls. Residency and sovereignty follow from where you chose to deploy, not from a decision of ours.

Do you train models on our data?

No. Pometry is infrastructure, not a model provider, and we have no mechanism to train on your data because it never reaches us. One thing to be clear about: if you connect a hosted model, the query results Pometry returns are sent to that provider under your contract with them. Where that is unacceptable, Pometry works with open-weight models running inside your own boundary.

How is access controlled for AI agents?

The caller's identity is carried into the query and permissions are evaluated at traversal time, down to individual nodes, edges and time windows, so an agent resolves only what its caller could resolve. Every traversal is logged against that identity. Controls on what an agent then does with an answer it was entitled to sit with your AI platform.

What happens to our data if we stop using Pometry?

The data stays on your disk, in Arrow-backed columnar files inside your own infrastructure. Column-level data is readable with standard Arrow tooling and exports to Parquet or CSV without involving us. Only reading it as a temporal graph requires the Pometry licence and binary.

Experience Pometry in action
with a live demo.

Find out how you can close your visibility gap with unique, institutional intelligence.