-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathplatform-map.html
More file actions
301 lines (277 loc) · 26.2 KB
/
Copy pathplatform-map.html
File metadata and controls
301 lines (277 loc) · 26.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
<title>Off Grid AI — the platform</title>
<style>
:root{
--bg:#0a0a0a;--panel:#111312;--panel2:#161917;--line:#242826;
--ink:#e7ece9;--dim:#8a938d;--em:#34D399;--em-dim:#1c5c46;--amber:#f0b24a;--amber-dim:#5c4a1c;
--mono:'Menlo','SFMono-Regular',ui-monospace,monospace;
}
*{box-sizing:border-box}
body{margin:0;background:var(--bg);color:var(--ink);font-family:var(--mono);font-size:13px;line-height:1.5;padding:26px}
.wrap{max-width:1220px;margin:0 auto}
h1{font-size:20px;letter-spacing:.02em;margin:0 0 2px}
.sub{color:var(--dim);font-size:12px;margin:0 0 6px}
.thesis{border-left:2px solid var(--em);padding:6px 0 6px 12px;margin:14px 0 22px;color:var(--ink);font-size:13.5px}
.em{color:var(--em)}.amber{color:var(--amber)}.dim{color:var(--dim)}
h2.sec{font-size:11px;text-transform:uppercase;letter-spacing:.16em;color:var(--em);margin:26px 0 10px;border-bottom:1px solid var(--line);padding-bottom:6px}
.band{border:1px solid var(--line);border-radius:10px;background:var(--panel);padding:14px 16px;margin:0 0 12px}
.band h3{font-size:11px;text-transform:uppercase;letter-spacing:.14em;color:var(--dim);margin:0 0 12px;font-weight:500}
.row{display:grid;gap:10px}
.c2{grid-template-columns:1fr 1fr}.c3{grid-template-columns:repeat(3,1fr)}.c4{grid-template-columns:repeat(4,1fr)}.c5{grid-template-columns:repeat(5,1fr)}
.node{border:1px solid var(--line);border-radius:8px;background:var(--panel2);padding:10px 12px}
.node .t{font-weight:600;color:var(--ink);font-size:12.5px}
.node .d{color:var(--dim);font-size:11px;margin-top:3px}
.node.em{border-color:var(--em-dim);box-shadow:inset 0 0 0 1px rgba(52,211,153,.08)}.node.em .t{color:var(--em)}
.node.amber{border-color:var(--amber-dim)}.node.amber .t{color:var(--amber)}
.arrow{text-align:center;color:var(--em);font-size:14px;margin:2px 0;letter-spacing:.3em}
.pill{display:inline-block;border:1px solid var(--line);border-radius:999px;padding:1px 8px;font-size:10.5px;color:var(--dim);margin:2px 4px 2px 0}
.pill.on{border-color:var(--em-dim);color:var(--em)}.pill.new{border-color:var(--amber-dim);color:var(--amber)}
.spine{border:1px dashed var(--em-dim);border-radius:10px;background:linear-gradient(180deg,rgba(52,211,153,.05),transparent);padding:14px 16px;margin:0 0 12px}
.org{border:1px solid var(--em-dim);border-radius:10px;background:rgba(52,211,153,.04);padding:12px 16px;margin:0 0 12px;text-align:center}
.k{display:inline-block;width:10px;height:10px;border-radius:2px;vertical-align:middle;margin:0 4px 0 12px}
.k.on{background:var(--em)}.k.new{background:var(--amber)}
table{width:100%;border-collapse:collapse;font-size:11.5px;margin-top:4px}
th,td{text-align:left;padding:6px 8px;border-bottom:1px solid var(--line);vertical-align:top}
th{color:var(--dim);font-weight:500;text-transform:uppercase;font-size:10px;letter-spacing:.1em}
td .s{color:var(--em)}td .n{color:var(--amber)}
.foot{color:var(--dim);font-size:11px;margin-top:8px}
@media(max-width:860px){.c2,.c3,.c4,.c5{grid-template-columns:1fr}}
</style>
<div class="wrap">
<h1>Off Grid AI — <span class="em">the platform</span></h1>
<p class="sub">Become an intelligent enterprise, without compromising. On-prem · local-first · source-available · data never leaves the box.</p>
<div class="thesis">
One <span class="em">governed pipeline</span> is the unit of everything — it governs <b>model access AND data movement</b> under one policy/guardrail/redaction/eval contract. It runs on a <span class="em">smart gateway</span> (routing + edge + its own telemetry). Every run and every sync emits into <b>one shared spine</b> (observability · audit · lineage · provenance · cost · compliance) — <span class="amber">replayable end-to-end</span> — and an <span class="em">org view</span> rolls the whole estate up. That's the platform.
</div>
<!-- ============ THE DIAGRAM ============ -->
<h2 class="sec">The architecture — one governed flow</h2>
<div class="band" style="padding:18px">
<svg viewBox="0 0 1160 640" style="width:100%;height:auto;font-family:var(--mono)" role="img" aria-label="Off Grid AI architecture">
<defs>
<marker id="ar" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse">
<path d="M0 0 L10 5 L0 10 z" fill="#34D399"/>
</marker>
<marker id="arA" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse">
<path d="M0 0 L10 5 L0 10 z" fill="#f0b24a"/>
</marker>
</defs>
<style>
.bx{fill:#161917;stroke:#242826;stroke-width:1;rx:8}
.bxE{fill:#12211b;stroke:#1c5c46;stroke-width:1.2}
.bxA{fill:#211d12;stroke:#5c4a1c;stroke-width:1.2}
.lbl{fill:#e7ece9;font-size:13px;font-weight:600}
.sub2{fill:#8a938d;font-size:10.5px}
.em2{fill:#34D399;font-size:11px;font-weight:600}
.am2{fill:#f0b24a;font-size:11px;font-weight:600}
.cap{fill:#8a938d;font-size:10px;text-transform:uppercase;letter-spacing:.14em}
.flow{stroke:#34D399;stroke-width:1.5;fill:none}
.flowA{stroke:#f0b24a;stroke-width:1.5;fill:none;stroke-dasharray:4 3}
</style>
<!-- ORG VIEW banner -->
<rect x="20" y="14" width="1120" height="40" rx="8" fill="#0f1c17" stroke="#1c5c46"/>
<text x="580" y="33" text-anchor="middle" class="em2">ORG VIEW — roll-up across every pipeline · gateway · consumer</text>
<text x="580" y="47" text-anchor="middle" class="sub2">spend · traces · audit · lineage graph · drift & quality · compliance · fleet</text>
<!-- CONSUMERS row -->
<text x="20" y="82" class="cap">Consumers</text>
<g>
<rect class="bxE" x="20" y="90" width="205" height="52" rx="8"/><text x="34" y="112" class="lbl">App</text><text x="34" y="130" class="sub2">UI · HITL · review · reports</text>
<rect class="bxE" x="242" y="90" width="205" height="52" rx="8"/><text x="256" y="112" class="lbl">Agent</text><text x="256" y="130" class="sub2">autonomous · headless · report</text>
<rect class="bxE" x="464" y="90" width="205" height="52" rx="8"/><text x="478" y="112" class="lbl">Chat / Projects</text><text x="478" y="130" class="sub2">governed conversation</text>
<rect class="bxA" x="686" y="90" width="205" height="52" rx="8"/><text x="700" y="112" class="am2">BI · PowerBI / Superset</text><text x="700" y="130" class="sub2">reads the warehouse</text>
<rect class="bxE" x="908" y="90" width="232" height="52" rx="8"/><text x="922" y="112" class="lbl">External 3rd-party</text><text x="922" y="130" class="sub2">provisioned pipeline key</text>
</g>
<!-- arrows consumers -> pipeline -->
<path class="flow" d="M580 142 L580 172" marker-end="url(#ar)"/>
<text x="592" y="162" class="sub2">bind</text>
<!-- PIPELINE (the big box) -->
<text x="20" y="192" class="cap">Pipeline — the one governed unit (owns everything)</text>
<rect x="20" y="200" width="1120" height="150" rx="10" fill="#0e1a15" stroke="#1c5c46" stroke-width="1.4"/>
<!-- does -->
<rect class="bx" x="36" y="214" width="250" height="50" rx="8"/><text x="48" y="234" class="lbl">Model access</text><text x="48" y="251" class="sub2">grounded answers + citations</text>
<rect class="bxA" x="298" y="214" width="300" height="50" rx="8"/><text x="310" y="234" class="am2">Data movement (ETL + ELT / CDC)</text><text x="310" y="251" class="sub2">connector → warehouse · redact pre-load</text>
<text x="620" y="234" class="sub2">+ compose</text><text x="620" y="249" class="sub2">pipelines-as-tools</text>
<!-- peripheries -->
<text x="36" y="286" class="cap">governed by the same peripheries</text>
<g class="sub2" font-size="10.5">
<rect x="36" y="294" width="150" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="46" y="308" class="em2" font-size="10">data-allowlist ⛔ceiling</text>
<rect x="196" y="294" width="95" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="206" y="308" class="em2" font-size="10">policy ABAC</text>
<rect x="301" y="294" width="90" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="311" y="308" class="em2" font-size="10">guardrails</text>
<rect x="401" y="294" width="105" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="411" y="308" class="em2" font-size="10">PII redaction</text>
<rect x="516" y="294" width="120" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="526" y="308" class="em2" font-size="10">evals + golden</text>
<rect x="646" y="294" width="70" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="656" y="308" class="em2" font-size="10">drift</text>
<rect x="726" y="294" width="150" height="20" rx="10" fill="#211d12" stroke="#5c4a1c"/><text x="736" y="308" class="am2" font-size="10">data-quality (GE)</text>
<rect x="886" y="294" width="90" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="896" y="308" class="em2" font-size="10">routing</text>
<rect x="986" y="294" width="138" height="20" rx="10" fill="#12211b" stroke="#1c5c46"/><text x="996" y="308" class="em2" font-size="10">API key · versioning</text>
</g>
<text x="36" y="336" class="cap">lifecycle</text>
<text x="120" y="337" class="em2" font-size="11">draft → in-review → published (approver + release-gate) → deprecated · auto-rollback on breach</text>
<!-- arrow pipeline -> gateway -->
<path class="flow" d="M300 350 L300 384" marker-end="url(#ar)"/><text x="312" y="373" class="sub2">runs on</text>
<!-- arrow pipeline -> data engine -->
<path class="flowA" d="M448 350 L448 384" marker-end="url(#arA)"/><text x="460" y="373" class="sub2">syncs via</text>
<!-- SUBSTRATE: gateway + data engine -->
<text x="20" y="404" class="cap">Substrate — two engines</text>
<rect x="20" y="412" width="558" height="96" rx="10" class="bxE"/>
<text x="34" y="432" class="em2" font-size="12">GATEWAY — smart model + network edge</text>
<text x="34" y="452" class="sub2">smart routing · fallback · egress leash (local/cloud/block)</text>
<text x="34" y="468" class="sub2">edge: WAF · rate-limit · cache · TLS · per-tenant URL</text>
<text x="34" y="484" class="sub2">its own logs + observability · llama.cpp fleet + cloud</text>
<text x="34" y="500" class="em2" font-size="10">on-prem · OpenAI · Anthropic · OpenRouter · STT/TTS · image</text>
<rect x="590" y="412" width="550" height="96" rx="10" class="bxA"/>
<text x="604" y="432" class="am2" font-size="12">DATA ENGINE — ETL/CDC + warehouse (on S2)</text>
<text x="604" y="452" class="sub2">Airbyte (connectors + CDC) · Redpanda (Kafka/MQ)</text>
<text x="604" y="468" class="sub2">ClickHouse (warehouse) · dbt (transform) · Great Expectations</text>
<text x="604" y="484" class="sub2">data lake (S3 / SeaweedFS) landing zone</text>
<text x="604" y="500" class="am2" font-size="10">staged in compose · provisions on S2</text>
<!-- arrow substrate -> spine -->
<path class="flow" d="M300 508 L300 540" marker-end="url(#ar)"/>
<path class="flowA" d="M865 508 L865 540" marker-end="url(#arA)"/>
<text x="470" y="530" text-anchor="middle" class="em2" font-size="11">every RUN or SYNC = the join key ↓</text>
<!-- SPINE -->
<rect x="20" y="548" width="1120" height="76" rx="10" fill="#0f1c17" stroke="#1c5c46" stroke-width="1.4"/>
<text x="34" y="568" class="em2">THE SPINE — what every run & sync emits into</text>
<g class="sub2" font-size="11">
<text x="34" y="592" class="em2">Observability</text><text x="34" y="607" class="sub2">traces·latency</text>
<text x="200" y="592" class="em2">Audit / SIEM</text><text x="200" y="607" class="sub2">every decision</text>
<text x="365" y="592" class="em2">Lineage</text><text x="365" y="607" class="sub2">src→answer / →BI</text>
<text x="540" y="592" class="em2">Provenance</text><text x="540" y="607" class="sub2">signed · citations</text>
<text x="710" y="592" class="em2">FinOps</text><text x="710" y="607" class="sub2">cost · chargeback</text>
<text x="850" y="592" class="em2">Regulatory</text><text x="850" y="607" class="sub2">ISO·NIST·EU-AI</text>
<text x="1010" y="592" class="am2">→ export</text><text x="1010" y="607" class="sub2">Splunk·Purview·Grafana</text>
</g>
</svg>
<p class="foot"><span style="color:var(--em)">green</span> = model plane (live) · <span style="color:var(--amber)">amber</span> = data plane (staged, provisions on S2). The pipeline owns both; the spine captures both; the org view rolls both up.</p>
</div>
<!-- ORG -->
<h2 class="sec">Org view — the whole estate</h2>
<div class="org">
<div class="em" style="font-weight:600">▲ roll-up across every pipeline, gateway & consumer</div>
<div class="dim" style="font-size:11px;margin-top:3px">total spend & chargeback · all traces/audit · every data flow + lineage graph · drift & data-quality · compliance coverage · fleet health · tenants — the estate at a glance, drill into any pipeline's slice</div>
</div>
<!-- CONSUMERS -->
<h2 class="sec">Consumers — who uses a pipeline (Apps vs Agents is the key distinction)</h2>
<div class="band">
<div class="row c2" style="margin-bottom:10px">
<div class="node em"><div class="t">APP — has a UI</div><div class="d"><b>Human-facing.</b> A UI + input forms · <b>HITL</b> (human-in-the-loop approve/reject/edit) · a <b>Review</b> queue · <b>Reports</b>. A person drives it. e.g. reimbursement approval, KYC review.</div></div>
<div class="node em"><div class="t">AGENT — no UI</div><div class="d"><b>Autonomous.</b> No UI, runs on a trigger/schedule, does its work headless, and <b>emits a report</b>. No human in the loop. e.g. overnight fraud sweep, scheduled data sync, monitoring.</div></div>
</div>
<div class="row c3">
<div class="node em"><div class="t">Chat / Projects</div><div class="d">governed conversation · @knowledge · citations</div></div>
<div class="node amber"><div class="t">BI — Superset / PowerBI <span class="pill new">new</span></div><div class="d">reads the warehouse a pipeline fills</div></div>
<div class="node em"><div class="t">External 3rd-party</div><div class="d">provisioned per-pipeline key + endpoint</div></div>
</div>
<div class="dim" style="margin-top:8px"><span class="em">App = UI + HITL + review + reports.</span> <span class="em">Agent = autonomous, headless, report-only.</span> Both bind a governed pipeline; both built by non-technical dept staff in plain language.</div>
</div>
<!-- LIBRARY -->
<h2 class="sec">The prebuilt library — the on-ramp & the showcase</h2>
<div class="band" style="border-color:var(--em-dim)">
<div class="dim" style="margin-bottom:10px"><span class="em">A LOT of small, composable pipelines shipped as fully-governed examples.</span> Each is ONE thing done well, wired end-to-end (evals · golden set · drift · observability · policy · guardrails · lineage — everything), and composes into bigger ones (pipeline-as-tool). People <b>clone → tweak in plain language → deploy</b>. This is the fastest path to value and the proof the platform works.</div>
<div class="row c4">
<div class="node"><div class="t">Each example ships WITH</div><div class="d">evals + golden set · drift setup · observability · policy · guardrails · routing — governed from day one, not a bare skeleton</div></div>
<div class="node"><div class="t">Small + composable</div><div class="d">one job each; compose as tools into apps & agents</div></div>
<div class="node"><div class="t">BFSI examples</div><div class="d">KYC · loan underwriting · fraud · FNOL · reimbursement · cross-sell</div></div>
<div class="node amber"><div class="t">Data examples <span class="pill new">new</span></div><div class="d">connector→warehouse syncs · CDC feeds · quality-gated ELT</div></div>
</div>
</div>
<div class="arrow">▲ bind ▲</div>
<!-- PIPELINE -->
<h2 class="sec">Pipeline — the one governed unit (owns everything)</h2>
<div class="band" style="border-color:var(--em-dim)">
<div class="row c2" style="margin-bottom:12px">
<div class="node"><div class="t">What it can DO</div><div class="d"><b>Model access</b> → grounded answers + citations. <b class="amber">Data movement</b> → connector→warehouse sync (batch · incremental · CDC). Compose pipelines-as-tools.</div></div>
<div class="node"><div class="t">How it's consumed</div><div class="d">provisioned API key + endpoint · versioned + <span class="amber">replayable</span> (every run/sync is a recorded, re-runnable event) · templated (sample BFSI pipelines)</div></div>
</div>
<div class="dim">Governed by the SAME peripheries whether it's moving tokens or rows:</div>
<div style="margin-top:6px">
<span class="pill on">data-allowlist — hard ceiling</span>
<span class="pill on">policy (ABAC / OPA)</span>
<span class="pill on">guardrails (injection · grounding · toxicity)</span>
<span class="pill on">PII redaction / masking (Presidio) — on the sync path too</span>
<span class="pill on">model evals + golden set</span>
<span class="pill on">drift detection</span>
<span class="pill new">data-quality evals (Great Expectations)</span>
<span class="pill on">routing + egress leash</span>
<span class="pill new">schedule / CDC trigger</span>
<span class="pill on">RBAC (who may run) → ABAC (what this request may touch)</span>
</div>
<div class="dim" style="margin-top:10px">Per-pipeline lenses = its slice of the spine: observability · audit · lineage · provenance · cost · quality.</div>
</div>
<div class="arrow">▲ runs on ▲</div>
<!-- GATEWAY -->
<h2 class="sec">Gateway — the smart network + model edge</h2>
<div class="band"><div class="row c3">
<div class="node em"><div class="t">Smart routing</div><div class="d">model pick · fallback chain · load-balance across fleet nodes · egress leash (data-class → local / cloud / block) · cost-aware</div></div>
<div class="node em"><div class="t">Edge functions (Caddy)</div><div class="d">WAF · rate-limit · caching (Redis) · TLS · per-tenant provisioned URL — the real internet-gateway layer</div></div>
<div class="node em"><div class="t">Gateway's OWN telemetry</div><div class="d">access logs · which node served · latency / throughput / errors — distinct from the pipeline's lenses</div></div>
</div>
<div style="margin-top:8px">
<span class="pill on">on-prem cluster (fleet)</span><span class="pill on">OpenAI</span><span class="pill on">Anthropic</span><span class="pill on">OpenRouter</span>
<span class="pill on">STT/TTS (speech)</span><span class="pill on">image (sd)</span><span class="pill on">embeddings</span>
</div></div>
<!-- ENGINES / SUBSTRATE -->
<h2 class="sec">Substrate — the two engines a pipeline runs on</h2>
<div class="band"><div class="row c2">
<div class="node em"><div class="t">Model engine — the AI gateway</div><div class="d">llama.cpp fleet + cloud providers, OpenAI-compatible. LIVE.</div></div>
<div class="node amber"><div class="t">Data engine — ETL + ELT / CDC stack <span class="pill new">new · on S2</span></div><div class="d">Airbyte (extract+load + CDC) · Redpanda (Kafka/MQ) · ClickHouse (warehouse) · dbt (in-warehouse transform) · Great Expectations (quality). <b>Both patterns:</b> PII redaction runs ETL-style <b>in-flight before load</b> (raw PII never lands) → then ELT-model in-warehouse. Drag-drop / "write english → sync".</div></div>
</div></div>
<!-- SPINE -->
<h2 class="sec">The spine — run OR sync is the join key</h2>
<div class="spine"><div class="row c3">
<div class="node em"><div class="t">Observability</div><div class="d">traces · latency · tokens (Langfuse)</div></div>
<div class="node em"><div class="t">Audit / SIEM</div><div class="d">every call/sync + policy/guardrail decision + egress + invoker (OpenSearch)</div></div>
<div class="node em"><div class="t">Lineage</div><div class="d">source→chunk→answer AND <span class="amber">source→sync→warehouse→BI</span> (Marquez)</div></div>
<div class="node em"><div class="t">Provenance + Citations</div><div class="d">signed run manifests · grounded citations · verify + rotate · replayable</div></div>
<div class="node em"><div class="t">FinOps / Cost</div><div class="d">model spend + sync/warehouse cost per pipeline · virtual keys · budgets · chargeback</div></div>
<div class="node em"><div class="t">Regulatory</div><div class="d">ISO 42001 · NIST AI RMF · EU AI Act coverage over the same runs + syncs</div></div>
</div></div>
<!-- CROSS-CUTTING -->
<h2 class="sec">Platform services (cross-cutting)</h2>
<div class="band"><div class="row c4">
<div class="node em"><div class="t">Identity / SSO</div><div class="d">Keycloak — realms, service accounts, federation</div></div>
<div class="node em"><div class="t">Secrets</div><div class="d">OpenBao — keys, credentials, rotation</div></div>
<div class="node em"><div class="t">Multi-tenancy</div><div class="d">org-scoped everything · per-tenant subdomain + gateway URL · membership-checked</div></div>
<div class="node em"><div class="t">Feature flags</div><div class="d">Unleash — capability/module licensing per org</div></div>
<div class="node em"><div class="t">Fleet / MDM</div><div class="d">FleetDM — device mgmt · the on-prem compute fleet (10 nodes)</div></div>
<div class="node em"><div class="t">Storage</div><div class="d">SeaweedFS (S3) · buckets · artifacts</div></div>
<div class="node em"><div class="t">Knowledge / Brain</div><div class="d">RAG — Qdrant / LanceDB vector stores</div></div>
<div class="node em"><div class="t">Backups / DR</div><div class="d">scheduled · restore · prune</div></div>
</div></div>
<!-- OSS STACK -->
<h2 class="sec">The open-source stack (permissive licences — the moat is ownership, not secrecy)</h2>
<div class="band">
<table>
<tr><th>Capability</th><th>Engine (OSS)</th><th>Status</th></tr>
<tr><td>Model gateway</td><td>llama.cpp fleet + OpenAI-compat</td><td class="s">■ live</td></tr>
<tr><td>Warehouse (Snowflake/Databricks-equiv)</td><td>ClickHouse</td><td class="n">■ new</td></tr>
<tr><td>Connectors + ELT (Glue-equiv)</td><td>Airbyte — 300+ sources</td><td class="n">■ new</td></tr>
<tr><td>CDC (log-based change capture)</td><td>Debezium (via Airbyte)</td><td class="n">■ new</td></tr>
<tr><td>Streaming / MQ</td><td>Redpanda (Kafka API)</td><td class="n">■ new</td></tr>
<tr><td>Transforms</td><td>dbt</td><td class="n">■ new</td></tr>
<tr><td>Data-quality evals</td><td>Great Expectations</td><td class="n">■ new</td></tr>
<tr><td>PII redaction</td><td>Presidio</td><td class="s">■ live</td></tr>
<tr><td>Model evals / drift</td><td>ragas · deepeval · Evidently</td><td class="s">■ live</td></tr>
<tr><td>Observability / traces</td><td>Langfuse</td><td class="s">■ live</td></tr>
<tr><td>Audit / SIEM</td><td>OpenSearch</td><td class="s">■ live</td></tr>
<tr><td>Lineage</td><td>Marquez (OpenLineage)</td><td class="s">■ live</td></tr>
<tr><td>Policy</td><td>OPA (ABAC)</td><td class="s">■ live</td></tr>
<tr><td>Secrets</td><td>OpenBao</td><td class="s">■ live</td></tr>
<tr><td>Identity</td><td>Keycloak</td><td class="s">■ live</td></tr>
<tr><td>Durable runs</td><td>Temporal</td><td class="s">■ live</td></tr>
<tr><td>Flags · MDM · BI · store</td><td>Unleash · FleetDM · Superset · SeaweedFS</td><td class="s">■ live (BI+MDM: register)</td></tr>
</table>
<div class="foot"><span class="k on"></span>live & wired <span class="k new"></span>new data plane — Airbyte · Redpanda · ClickHouse · dbt · Great Expectations · BI, on the freed <b>S2</b> server node. Fleet: 10 machines (S1 control-plane · S2 data-plane · g1–g8 model nodes).</div>
</div>
<!-- MATURITY -->
<h2 class="sec">What's next — the maturity arc (governs → compounds)</h2>
<div class="band"><div class="row c5">
<div class="node em"><div class="t">M1 · Close the loop</div><div class="d">detect→ACT→learn: release gate + auto-rollback + HITL/thumbs → eval data. <span class="em">building</span></div></div>
<div class="node"><div class="t">M2 · Lifecycle & ownership</div><div class="d">teams · owners · promote/approve gate (draft→eval-gated→published)</div></div>
<div class="node amber"><div class="t">M4 · Deep data governance</div><div class="d">catalog · classification · retention/RTBF · freshness + broken-sync alerts</div></div>
<div class="node"><div class="t">M5 · Self-driving</div><div class="d">ops copilot · auto-suggest guardrails/evals · anomaly detection (the AI moat)</div></div>
<div class="node"><div class="t">M6 · Good citizen</div><div class="d">export audit/lineage/metrics → Splunk · Purview · Grafana</div></div>
</div>
<div class="dim" style="margin-top:8px"><span class="dim">M3 (capacity/GPU quota + control-plane HA) — <s>dropped</s>: temporary 10-machine artifact; rack/cloud coming.</span></div></div>
<!-- EXPERIENCE -->
<h2 class="sec">The experience bet — beautiful & effortless</h2>
<div class="band"><div class="dim">Creating and deploying a governed use-case is the core loop, and it must be a <span class="em">joy</span>, not a config chore. You start from a prebuilt pipeline (governance already wired), describe the change in plain <span class="em">English</span>, and deploy — as an <b>App</b> (UI + HITL + review + reports) or an <b>Agent</b> (autonomous, report-only). The library of small composable pipelines is the on-ramp; the plain-language authoring is the magic; the shared spine means every use-case is observable, auditable, and replayable the moment it ships.</div></div>
<p class="sub" style="margin-top:18px">Positioning: not "a private ChatGPT" — <span class="em">a private AI, everywhere</span>, and the governed data platform under it. Fair-code: free for up to 25 users; larger deployments require a commercial license. The bet: every enterprise capability (model access, ETL, BI, governance, compliance) as <span class="em">small, reusable, composable, replayable pipelines</span> — shipped as fully-governed examples — that never let data leave.</p>
</div>