Home / Platform

A data and AI platform you host and govern yourself.

Data, processing, AI models and keys stay in your infrastructure. AKKO assembles some fifty open components into one platform, installed by one Helm chart on your Kubernetes, with one identity from the directory down to the query. Every layer can be replaced by what you already have.

The layers

Nine layers, one cockpit, one identity.

Click a layer to see what it holds and the cockpit screen that drives it.

Identity and access

One identity, from the directory to the engine. Row filters and column masks per group.

ComponentsKeycloak, LDAP or your Active Directory, OPA or Ranger

Cockpit AKKO, accès aux données : politiques par catalogue et par groupe

Layer by layer

Identity and access

ComponentsKeycloak · LDAP or Active Directory · OPA or Ranger · Kerberos

Your directory remains the source of accounts and groups. Keycloak federates identity (OIDC, SSO); data rights are expressed per group and applied by the engine: row filters and column masks, for a dashboard, a notebook, a model or an agent. OPA or Apache Ranger decide, whichever you already have.

Data access: policies per catalogue and per group

Federation and SQL engine

ComponentsTrino

One SQL over PostgreSQL, Hive, Iceberg and the other sources Trino connects, queried where they are. Only the requested rows travel; every query carries the identity of the person.

Federated sources in the cockpit

Lakehouse

ComponentsApache Iceberg · S3-compatible object storage · Polaris or Hive Metastore

Open-format tables on your storage, readable by any engine today and tomorrow. When a source deserves a copy, Iceberg and orchestration take over, on your team's decision.

Catalogue and quality

ComponentsOpenMetadata · NORA

Lineage, owners, classifications, profiling: the same truth for people and for models. NORA suggests descriptions and flags what is missing; a steward reviews and approves.

NORA: review of catalogue enrichments

Orchestration

ComponentsApache Airflow

Scheduled pipelines whose lineage is emitted to the catalogue. DAGs run in your cluster.

Compute

ComponentsApache Spark

Distributed processing on the lakehouse, from notebooks or pipelines.

Analytics and reporting

ComponentsApache Superset

Dashboards on the federated engine, with the rights of the signed-in person.

Lab

ComponentsJupyterHub · code-server · MLflow

Python, R, Julia or Scala notebooks, code environments and model tracking, with data access governed like everything else. Roles decide who reaches which tool.

Platform roles and tool access

Governed AI

ComponentsADEN · NORA · Ollama, vLLM · Mistral, Qwen, DeepSeek

ADEN turns a question into SQL and runs it under the identity of the person: same filters, same masks. Every answer shows its steps, its SQL, its confidence score and the model name. By default, models run on your side; the Mistral AI API is an explicit choice.

ADEN: an answer from mistral-small with chart and SQL

Federation

Start by federating, without moving your data.

Your data stays in PostgreSQL, Hive or Iceberg. AKKO exposes it through a single Trino engine: one SQL query, several sources, one result. Only the requested rows travel.

Every query runs under the identity of the signed-in person. Row and column rules apply at query time, across every source, and every execution is logged.

The catalogue fills up as you federate: NORA suggests descriptions and flags what is missing. When a source deserves a copy, Iceberg and Airflow take over, on your team's decision.

WITH COPYPostgreSQL · customersHive · salesIceberg · logsETLCopied warehouseyesterdayDashboardThree copies to maintain.Rights copied by hand.Yesterday's data.WITHOUT COPY, WITH AKKOIN PLACE, WITH YOUPostgreSQL · customersHive · salesIceberg · logsSELECTFROM pg.clients JOIN hive.ventesSQL engineTrino, under the identity of the personNotebook, BIor ADENNo copy.Rights applied by the engine, on every query.The data at the moment of the question.

Deployment

AKKO installs with you, wherever your Kubernetes is.

One Helm chart, one values file per environment, the same result everywhere. The targets below are the ones we have installed and tested; we do not list others.

helm install akkoDATA CENTREYour serversbare metal or virtualisedSOVEREIGN CLOUDThe host of your choicein your accountEXISTING KUBERNETESYour cluster, your operatorsk3s in demonstration; OpenShift under validationNO INTERNET ACCESSIsolated networkembedded images and chartsSAME CHART · SAME IMAGES · SAME IDENTITY

Where things run

Everything runs inside your perimeter.

YOUR INFRASTRUCTURE · KUBERNETES OR OPENSHIFT · INCLUDING WITHOUT INTERNET ACCESSEXISTING DIRECTORYActive Directory, LDAP, KeycloakEXISTING SOURCESPostgreSQL, Hive, Iceberg, Oracle…MODELSrunning on your side (Ollama, vLLM)Existing Ranger or OPAAKKO · NINE LAYERS · ONE COCKPITIdentity and accessSQL federationLakehouseCatalogueOrchestrationComputeBILabGoverned AIOne identity runs through the nine layers. No data leaves the perimeter.AKKO · THE VENDORSigned charts and imagesDocumentation, updatesSupportNever sees your data.
Where things run. The whole platform runs inside your perimeter, with your directory, your sources and your models; what comes from AKKO is signed charts and images, documentation and support.

The cockpit

One console for everything, with the same rights everywhere.

The cockpit brings tools, sources, roles, supervision and AI into one interface, in French and English. It opens every tool under the identity of the signed-in person.

Cockpit home
Cockpit home
Platform supervision
Platform supervision
Roles and tool access
Roles and tool access

Ecosystem

What the platform connects to.

Where it runs

  • Kubernetes
  • OpenShift
  • OVHcloud
  • Scaleway
  • Any managed Kubernetes

Existing Hadoop estates

  • Cloudera
  • Kerberos
  • Apache Ranger
  • Apache Knox
  • Hive Metastore
  • ODP (Clemlab)
  • OKDP (TOSIT)

Data sources

  • PostgreSQL
  • Apache Iceberg
  • Apache Hive
  • MinIO / S3
  • MySQL
  • Oracle
  • ClickHouse
  • MongoDB
  • Cassandra
  • Elasticsearch
  • Kafka
  • Delta Lake

Identity

  • Keycloak
  • LDAP
  • Active Directory
  • Kerberos
  • Open Policy Agent
  • Apache Ranger

Models

  • Mistral
  • Ollama
  • vLLM
  • Qwen
  • Any OpenAI-compatible endpoint

Catalogue and observability

  • OpenMetadata
  • OpenSearch
  • Prometheus

Frequently asked questions

Does AKKO work without Internet access?
Installation isolated from the Internet is planned and documented: embedded images and charts. By default no component calls an outside service; wiring a remote model, for example the Mistral AI API, is an explicit choice of your team.
What hardware is needed?
A conformant Kubernetes cluster, on premises or at the host of your choice. AI models work from CPU configurations; GPUs improve latency.
How long to deploy?
One Helm chart installs the platform. Connecting your directory and your sources is then done from the cockpit.
Can we take only a part?
Yes. The published bricks install on their own (akko-mcp-trino today, akko-lab soon); the whole platform and the control plane are delivered under an Enterprise licence.

Let us talk about your infrastructure.

A demonstration on your case, or a technical conversation about your Kubernetes, your directory and your sources.

Request a demonstration Read the documentation