Ontos

mcp
Security Audit
Warn
Health Warn
  • No license — Repository has no license file
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Low visibility — Only 7 GitHub stars
Code Pass
  • Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Pass
  • Permissions — No dangerous permissions requested

No AI report is available for this listing yet.

SUMMARY

Audit-first, in-VPC knowledge-graph runtime with permission-aware traversal and per-fact provenance. Agent-native (MCP). Subset of Enclave.

README.md

ontos

CI
PyPI
Python
Downloads
Container
License

A subset of Enclave — the knowledge-graph layer of Enclave's sovereign AI company brain.

What Ontos is

Ontos is an in-VPC knowledge-graph runtime. It:

  1. Extracts typed entities and typed relationships from an enterprise's data (documents, communications, systems of record).
  2. Persists them as immutable, bitemporally-valid, provenance-tagged facts.
  3. Serves them to LLM agents through a Model Context Protocol (MCP) interface, with permission-aware graph traversal.
  4. Emits a compliance-grade audit record for every query.

Ontos is the "relationships" half of Enclave's company brain. Where the retrieval substrate answers what a document says, Ontos answers how things connect — who owns what, what depends on what, what changed when, and what the source-of-truth was on a given date.

Every fact carries provenance. Every query is audit-ready. Every deployment runs inside the customer's VPC.

Where Ontos sits in the Enclave family

Component Role
enclave-runtime Retrieval substrate — document/passage retrieval inside the customer's VPC.
ontos (this repo) Knowledge-graph layer — typed entities and relationships with provenance, bitemporal validity, and permission-aware traversal.
enclave-scribe Sovereign extraction model (in development). Replaces the current LlamaIndex/LangChain extractors in ontos/extraction/ once it passes benchmarks against current frontier models.
enclave-ocr Document and image OCR for the ingestion path.
enclave-gtm, enclave-home, enclave-business, … Product surfaces that consume Ontos through MCP.

Status

0.1.0 (first public release) — the runtime works end-to-end: ingest a directory of text files via ontos ingest, query it via ontos query "..." or the ask MCP tool, verify the audit chain via ontos audit verify. See CHANGELOG.md for what shipped in this release and docs/design/ for the per-milestone architecture notes.

Install

# From PyPI
pip install enclave-ontos

# Or via uv
uv add enclave-ontos

The PyPI distribution name is enclave-ontos; the import name stays ontos (same shape as pip install PyYAML → import yaml).

Container image on GHCR (multi-platform amd64):

docker pull ghcr.io/enclave-labs-inc/ontos:0.1.0
# or the moving tag
docker pull ghcr.io/enclave-labs-inc/ontos:latest

Quickstart

# From an installed release
ontos serve

# From a clone (dev)
uv sync --extra dev
uv run ontos serve

Then point any MCP-speaking client (Claude Code, Cursor, Codex, Gemini CLI) at the streamable-HTTP endpoint printed on start.

The CLI also ships ontos ingest <dir>, ontos query "<question>", and ontos audit verify — see CHANGELOG.md for what's in each release and RELEASING.md for the release process.

Design pillars

  1. Every fact carries provenance — (source_id, extractor_version, confidence, t_valid, t_invalid) on every triple.
  2. Every query carries an audit record — EU AI Act Article 12: ≥12 fields per AI-influenced decision, ≥6 mo retention, per-user attribution.
  3. Permission-aware traversal at the executor — paths crossing forbidden nodes pruned during traversal, not after. Zero node-existence leakage.
  4. Bitemporal correctness — as_of on every read; contradictions close old validity windows.
  5. Planner/executor split — LLM writes typed plans over the ontology; deterministic executor runs multi-hop retrieval.
  6. Sovereign by architecture — nothing leaves the customer VPC. Deployable air-gapped.

MCP tools (v0)

  • search(query, as_of?, k?, agent_identity) — semantic + graph retrieval
  • traverse(start, relation, depth, as_of?, agent_identity) — permission-aware multi-hop
  • explain(entity_id, as_of?, agent_identity) — entity dossier with sources
  • provenance(fact_id) — full provenance chain for one fact
  • audit(query_id) — Article-12 audit record for a prior query
  • as_of(query, timestamp, agent_identity) — historical query for regulatory review

Layout

ontos/
├── runtime/     # FastMCP server + tool surface
├── planner/     # NL → typed plan over ontology
├── executor/    # multi-hop + PPR + pruning + authz-aware traversal
├── extraction/  # LlamaIndex/LangChain wrappers today; migrates to enclave-scribe once Scribe passes benchmarks
├── ontology/    # LinkML / YAML schemas
├── storage/     # backend-agnostic (Neo4j / NetworkX / Neptune)
├── authz/       # OpenFGA / SpiceDB
├── audit/       # Article-12 audit emitter
└── ingest/      # source connectors

Contributing

Ontos is open-source and we actively want outside contributors. Start with:

  • CONTRIBUTING.md — dev setup, coding standards, the non-negotiable invariants, and the PR process.
  • CODE_OF_CONDUCT.md — Contributor Covenant v2.1.
  • SECURITY.md — how to report a vulnerability (do not open a public issue for security bugs).
  • GitHub Issues for bugs and feature proposals; GitHub Discussions for questions and design conversations.

License

Apache-2.0.

Reviews (0)

No results found