A subset of Enclave — the knowledge-graph layer of Enclave's sovereign AI company brain.
Ontos is an in-VPC knowledge-graph runtime. It:
- Extracts typed entities and typed relationships from an enterprise's data (documents, communications, systems of record).
- Persists them as immutable, bitemporally-valid, provenance-tagged facts.
- Serves them to LLM agents through a Model Context Protocol (MCP) interface, with permission-aware graph traversal.
- Emits a compliance-grade audit record for every query.
Ontos is the "relationships" half of Enclave's company brain. Where the retrieval substrate answers what a document says, Ontos answers how things connect — who owns what, what depends on what, what changed when, and what the source-of-truth was on a given date.
Every fact carries provenance. Every query is audit-ready. Every deployment runs inside the customer's VPC.
| Component | Role |
|---|---|
| enclave-runtime | Retrieval substrate — document/passage retrieval inside the customer's VPC. |
| ontos (this repo) | Knowledge-graph layer — typed entities and relationships with provenance, bitemporal validity, and permission-aware traversal. |
| enclave-scribe | Sovereign extraction model (in development). Replaces the current LlamaIndex/LangChain extractors in ontos/extraction/ once it passes benchmarks against current frontier models. |
| enclave-ocr | Document and image OCR for the ingestion path. |
| enclave-gtm, enclave-home, enclave-business, … | Product surfaces that consume Ontos through MCP. |
0.1.0 (first public release) — the runtime works end-to-end: ingest a directory of text files via ontos ingest, query it via ontos query "..." or the ask MCP tool, verify the audit chain via ontos audit verify. See CHANGELOG.md for what shipped in this release and docs/design/ for the per-milestone architecture notes.
# From PyPI
pip install enclave-ontos
# Or via uv
uv add enclave-ontosThe PyPI distribution name is enclave-ontos; the import name stays ontos (same shape as pip install PyYAML → import yaml).
Container image on GHCR (multi-platform amd64):
docker pull ghcr.io/enclave-labs-inc/ontos:0.1.0
# or the moving tag
docker pull ghcr.io/enclave-labs-inc/ontos:latest# From an installed release
ontos serve
# From a clone (dev)
uv sync --extra dev
uv run ontos serveThen point any MCP-speaking client (Claude Code, Cursor, Codex, Gemini CLI) at the streamable-HTTP endpoint printed on start.
The CLI also ships ontos ingest <dir>, ontos query "<question>", and ontos audit verify — see CHANGELOG.md for what's in each release and RELEASING.md for the release process.
ontos ingest reads .txt, .md, and .pdf files from a directory. PDFs route through LlamaCloud's hosted vision API via the [llama] extra:
pip install 'enclave-ontos[llama]'
export LLAMA_CLOUD_API_KEY=llx-...
ontos ingest \
--source-dir ./corpus \
--ontology ./starter.yaml \
--pdf-backend llamaparse--pdf-backend llamaparse is a BRIDGE connector — document bytes leave the customer VPC on their way to api.cloud.llamaindex.ai. For in-VPC compliance, #39 tracks a sovereign pypdf backend (text-only PDFs; local parsing). Pure .txt/.md ingest requires no flag and no extra.
First-time model loads can take 30–60s. If ontos ingest or ontos query times out, warm the model via ollama run <model> first, or raise the per-request timeout with --ollama-timeout 180 (or higher for long documents).
By default the CLI persists dev-store facts to ~/.ontos/dev-store.pkl, so ontos ingest ... followed by ontos query ... works out of the box without an external database. Override the location with --storage-path PATH or ONTOS_STORAGE_PATH; pass --storage-path "" for ephemeral in-memory (what pre-0.3.0 did silently — operators who opt out see a loud warning). Regulated deploys continue to use ONTOS_STORAGE_BACKEND=neo4j; the dev-store pickle is Python-version-specific, single-process, and not a wire format.
- Every fact carries provenance —
(source_id, extractor_version, confidence, t_valid, t_invalid)on every triple. - Every query carries an audit record — EU AI Act Article 12: ≥12 fields per AI-influenced decision, ≥6 mo retention, per-user attribution.
- Permission-aware traversal at the executor — paths crossing forbidden nodes pruned during traversal, not after. Zero node-existence leakage.
- Bitemporal correctness —
as_ofon every read; contradictions close old validity windows. - Planner/executor split — LLM writes typed plans over the ontology; deterministic executor runs multi-hop retrieval.
- Sovereign by architecture — nothing leaves the customer VPC. Deployable air-gapped.
search(query, as_of?, k?, agent_identity)— semantic + graph retrievaltraverse(start, relation, depth, as_of?, agent_identity)— permission-aware multi-hopexplain(entity_id, as_of?, agent_identity)— entity dossier with sourcesprovenance(fact_id)— full provenance chain for one factaudit(query_id)— Article-12 audit record for a prior queryas_of(query, timestamp, agent_identity)— historical query for regulatory review
ontos/
├── runtime/ # FastMCP server + tool surface
├── planner/ # NL → typed plan over ontology
├── executor/ # multi-hop + PPR + pruning + authz-aware traversal
├── extraction/ # LlamaIndex/LangChain wrappers today; migrates to enclave-scribe once Scribe passes benchmarks
├── ontology/ # LinkML / YAML schemas
├── storage/ # backend-agnostic (Neo4j / NetworkX / Neptune)
├── authz/ # OpenFGA / SpiceDB
├── audit/ # Article-12 audit emitter
└── ingest/ # source connectors
Ontos is open-source and we actively want outside contributors. Start with:
- CONTRIBUTING.md — dev setup, coding standards, the non-negotiable invariants, and the PR process.
- CODE_OF_CONDUCT.md — Contributor Covenant v2.1.
- SECURITY.md — how to report a vulnerability (do not open a public issue for security bugs).
- GitHub Issues for bugs and feature proposals; GitHub Discussions for questions and design conversations.
Apache-2.0.