Star us on GitHub Open source Self-hosted Runs inside your perimeter

Agents get the data.
You keep control.

Datris is the open-source data control plane for AI agents. Your teams describe the data they need; Datris acquires it, validates it, and lands it in the stores you already run. Credentials never leave your vault, every action is policy-checked, and every landed row carries a receipt back to its source. It runs inside your perimeter. Nothing leaves.

Evaluating for a regulated team? How it stays under control.


Watch the Assistant build a data feed and pipeline
Datris Assistant online
I'm looking for corporate earnings data.
Happy to set that up. Before I build anything, two quick questions so I don't guess:
— Source: SEC EDGAR (free, official), Polygon.io, or Alpha Vantage?
— Scope: which tickers, and how far back?
SEC EDGAR, Mag 7, last 2 years.
▸🔑Inspecting secret sec-edgar✓
▸✨Creating pipeline corporate-earnings → mongodb✓
▸✨Creating tap corporate-earnings✓
Test run looks good — flat fact records flowing across all 7 tickers. Running the real load now.
▸▶Running tap corporate-earnings✓
Done. 24,217 fact records for the Mag 7 loaded into datris.corporate-earnings in ~4 seconds.
Provenance
Pipeline corporate-earnings · Run f3a91e2c
Script commit a3f19c2 · As-of 2026-08-25 14:32 UTC
24,217 rows written · 0 quarantined · 0 duplicates
One thing to flag for the recurring runs: each weekly run currently appends all matching facts. If you'd rather upsert, I can set keyFields on the pipeline.
→ Open tap corporate-earnings
Describe the data you want to ingest… Send

The request, the schedule, and the receipt. The chat is never the system of record.


01

Requests stop queueing behind engineering

Describe the dataset. Datris scopes the source, builds the pipeline, validates the rows, lands them, and puts it on a schedule. A research lead gets EDGAR filings for a watchlist the same afternoon, not in next quarter's sprint.

02

No credential ever sits in an agent's hands

Vendor keys and database logins stay in your vault. Datris hands the pipeline what it needs at run time and takes it back. Agent-written code runs in isolation with no platform credentials inside.

03

Every row can be defended

Each landed row is traceable to the pipeline, the run, the exact script version, and the source it came from. When compliance, a regulator, or a client asks where a number came from, the answer is a receipt, not a chat log.


Your agents already do this work. Without a control plane, they do it badly.

The question is not Datris versus an ETL tool. It is whether your agents work through a governed surface or improvise against your infrastructure.

Without Datris
Every agent, wired by hand
  • Every agent wired to every source by hand, maintained by whoever built it
  • Vendor keys copied into agent configs, prompts, and laptops
  • The chat transcript is the only record of what was pulled and why
  • Nothing persists; each session re-derives the same data
  • One-off questions leave orphan tables behind
  • Failures surface as stack traces someone pastes into another chat
  • No one can say which script version produced last month's numbers
With Datris
One control plane, every agent
  • One governed door for every agent and every source
  • Credentials stay in your vault; the agent never sees a key
  • Every run recorded, every generated script versioned
  • Durable pipelines with platform-held state
  • Live Read answers the one-off without landing anything
  • Failures explained in plain English with a recommended fix
  • Any number traced to the run and source that produced it

Agents don't need a new data platform. They need a way into yours.

Datris sits beside the warehouse and the lake, never in front of them. It is the intake valve: the agent asks, Datris acquires and validates, and the rows land in the stores your teams already query. Nothing moves out of your stack and nothing new becomes the system of record.

The write path
  • SnowflakeAnalytics warehouse
  • DatabricksLakehouse
  • PostgreSQLOperational store
  • MongoDBDocuments
  • S3 / MinIOObject storage, Parquet
  • pgvector · Qdrant · Weaviate · Milvus · ChromaVector search

One pipeline lands the same validated records in several of these in parallel, idempotent by key. Keep the intake layer neutral and every future architecture decision stays yours.




Run a pilot in a week. License it when it matters.

Every feature ships in the open-source build. A commercial license adds the contract, the named engineer, and the security advisories.


Send us a message

Questions, feedback, or just want to chat — we'd love to hear from you.