Skip to content
Ohalo is now DataXray.What changed
Modules / AI Platform

Put AI to work on the files you govern

The AI Platform module lets your teams build AI agents that search and read the files DataXray has already classified. Every request is checked against the user's permissions and your AI-use policy, and every decision is recorded.

What it makes possible

AI use with guardrails in place

AI projects on sensitive files usually stall in security review or go ahead without the controls they need. The AI Platform module gives security teams the controls, and gives everyone else a way to use AI.

  • Security signs off on one policy, and every team builds within it. Projects stop waiting in review.

  • Every answer comes with a record of the files it read, the policy applied, and who asked.

  • Personal data, health records, and classified material are held back by category, before a model sees them. Self-hosted models keep requests inside your environment.

How it works

Policy checks each request before it reaches your files

Configured to how you work. Your security team sets the categories, models, tools, and approval steps. We configure the module around your policies and the applications your teams already use, and we can extend it when a new use case needs something it doesn't do yet.

  1. A user asks.
  2. Policy decides.
  3. The answer comes with a record.
Capabilities

Agents use only the files and models you allow

Every AI application your teams build can run through the AI Platform module. Model credentials are managed in one place, every agent follows the same policy, and no team has to build its own agent runtime or audit trail.

  • Governed document accessAgents search and read the files DataXray has classified, using built-in tools. Access never goes beyond the datasources the connection can reach, and it can be narrowed to each user's own DataXray permissions.
  • Content policy on every readPolicies match DataXray labels, datasources, users, and agents, then allow, redact, or block content. When several rules match, the strictest one applies, and a document no rule allows stays blocked.
  • Versioned agentsAn agent combines instructions, a registered model, approved tools, limits, and an output schema. A version cannot be changed once it is saved, and every run records the version it used.
  • API and MCPCall agents from your own applications through the API, or connect external AI clients over MCP. Those clients get the same tools and the same policy as agents built in the module.
  • Your choice of modelConnect Anthropic, AWS Bedrock, OpenAI, or Azure OpenAI, or run your own models through vLLM or Ollama. Policy can send a run to a model you host, so the request never leaves your environment.
  • Evidence for every runPolicy decisions, tool calls, document reads, usage, cost, and latency are stored as a replayable timeline, with redaction-safe audit records for reviewers.
Why it matters

DataXray classifications decide what AI can read

With the AI Platform module, the classification DataXray already applies decides what agents may read. The module runs in your environment next to DataXray, installed from signed container images with Ansible.

Frequently asked questions

What is the DataXray AI Platform?

The AI Platform is a DataXray module for building and running governed AI agents on the files DataXray has discovered and classified. Your applications reach those agents through an API or MCP, and every run gets a policy check and an evidence record.

Do I need DataXray to use the AI Platform?

Yes. The AI Platform is a module, and it runs on the files DataXray has already read and classified, so no file is read twice.

Which models can it use?

It works with models from Anthropic, AWS Bedrock, OpenAI, and Azure OpenAI, and with self-hosted models through vLLM or Ollama. An administrator registers each model, and policy decides which model a run may use.

Can an agent read documents a user cannot?

Not when entitlement filtering is on, because each user is then held to their own DataXray permissions. Without it, an agent can reach only the datasources its connection covers, under your content policy, and a document no rule allows stays blocked.

How does it work with MCP clients?

External AI clients connect to the module's MCP endpoint with their own access token. They get the same search and read tools as native agents under the same policy, and every request is authenticated again.

Where does it run?

It runs inside your environment, alongside DataXray, and your data never moves. It ships as signed container images installed with Ansible.

Can it be configured to our needs?

Yes. Your team sets the policy, models, tools, and approval steps, and we configure the module around the applications you already use. If you need something it doesn't do yet, talk to us.

Does it run in air-gapped or classified environments?

It runs wherever DataXray runs, including air-gapped networks.

In 30 minutes, see how DataXray reads what other tools only label