The problem is structural, not incidental. Every organization has to gather, use, and share sensitive data — personal records, health and financial data, behavioral analytics. Most struggle to do it safely: policies live in too many places, access is granted once and trusted forever, and "secure" data ends up copied into insecure corners just so people can get their work done.
The Challenge
Customer records link to transactions, which connect to products, employees, locations, and countless other entities — each with unique attributes and evolving relationships. Traditional relational databases struggle to keep up.
Data Risk
Heterogeneous, Interconnected Data
Rigid relational schemas struggle with the real-world nature of enterprise data, where every record can have a different shape and neighboring records need not share the same structure.
Data Risk
Access Granted Once, Trusted Forever
Policies live in too many places and access decisions are rarely re-evaluated. Once a user or system is granted access, that access tends to outlive the reason it was granted.
Data Risk
Insecure Copies for the Sake of Productivity
When secure systems are too rigid or too slow, sensitive data gets copied into spreadsheets, data lakes, and side channels just so people — and now AI agents — can get their work done.
Data Risk
Rising Regulatory Pressure
GDPR, CCPA, HIPAA, and SOX all demand that organizations protect data at rest and in transit, control and audit access, and demonstrate compliance with an ever-growing array of requirements.
The Manetu Answer
Security by Design
Every value — and every relationship between values — is individually encrypted and access-controlled by default. Data is protected at rest, in motion, and in use, with no back door, not even for the platform operator.
- Zero-knowledge enclaves protect keys and algorithms
- Zero-trust identity, mutual TLS, policy checks on every request
- Every decision logged, explainable, and auditable
AI-Ready Data
Purpose-built to govern data and resources for agentic AI, so organizations can put sensitive data to work without multiplying risk — and without the security and privacy reviews that typically stall AI projects.
- A contextualized, policy-enforced slice of one source of truth per request
- Operations run against encrypted data; decryption happens only when mandatory
- Tokenization and de-identification let references travel safely
- Powers Permissioned RAG and GraphRAG — retrieval governed by access control, not just prompt design
A Knowledge Graph
Data and its relationships are modeled as a graph on open standards — RDF and SPARQL — the foundation of modern analytics and explainable AI, revealing what rows and columns hide.
- High-performance relationship discovery across connected data
- Schema that flexes as data and business needs evolve
- Relationships span vaults with different sensitivities and jurisdictions
One secured source of truth + contextual, easy access = the elimination of insecure copies. Manetu sits at the intersection of data security, governance, control, and usability — so users get the data they need without ever feeling the need to work around security.
How It Works
RDF: A Standards-Based Data Model
The Resource Description Framework represents information as a graph of interconnected nodes, expressed as Subject–Predicate–Object triples. This simple, powerful model can represent arbitrarily complex relationships, supports optional ontologies for semantic reasoning, and is queried with SPARQL — the standard query language for RDF, offering flexible, recursive pattern matching across even complicated graphs.
Vaults: The Unit of Protection
Manetu organizes and protects data through Vaults — secure containers that store related data as Graphs, Objects, and Tokens. Each Vault maintains its own encryption key, and every data element within it is individually encrypted. Organizations are encouraged to create as many Vaults as needed — often thousands or millions, such as one per customer relationship — limiting the blast radius of any single compromised key to one relationship rather than the entire database.
A Query's Path Through the Graph
RDF Triplessubject · predicate · object
→
Encrypted Vaultsindividually keyed
→
SPARQL Query Enginecross-vault pattern matching
→
Policy Enforcementevaluated per request
→
Contextual Viewperson · app · AI agent
Virtual Nodes (VNodes)
The platform augments the RDF model with VNodes — triples queried using natural SPARQL semantics but not physically stored in the graph. VNodes let queries retrieve a result's vault, last-modified timestamp, permissions, and sensitivity classification, enabling sophisticated governance and auditing.
Tags & Metadata
Tags attach additional metadata to individual attributes as first-class, queryable members of the graph — enabling attribute-level sensitivity classification, data lineage tracking, and fine-grained access policy based on attribute metadata.
Grounding AI Safely
Retrieval Augmented Generation lets LLMs draw on private data without fine-tuning — but traditional RAG has no concept of who's asking. Permissioned RAG and GraphRAG close that gap.
Permissioned RAG
Attribute-Based Access Control (ABAC) is embedded directly into the retrieval process — evaluating role, data classification, device, and request context before any data is returned. An HR user might retrieve performance data while remaining restricted from executive financial records; the generated response reflects those boundaries automatically.
GraphRAG
A graph-based representation of private data — entities and relationships organized into interconnected communities — sits alongside standard vector similarity search. This surfaces not just relevant content, but the relationships and context around it, for more accurate, nuanced retrieval with permissioning applied throughout.
Built on the Knowledge Graph: Manetu's secure, permissioned graph technology powers ABAC within both Permissioned RAG and GraphRAG, combining graph-based representations with vector search for retrieval that's auditable, explainable, and less prone to hallucination — while staying aligned with your governance policies.
By the Numbers
Millions
of lightweight, individually-keyed vaults — scale to any organization
Every Request
evaluated in real time on identity, context & policy
~50%
of Gartner AI inquiries involve graph technology
Zero
platform-operator access to unencrypted data — no back door
Data Protection Features
Zero-Knowledge Encryption
Every attribute is individually encrypted and hashed. Even the platform itself cannot access unencrypted values without proper authorization — encryption is transparent to authorized users and impenetrable to everyone else.
De-Identification
Create pointers or references to sensitive data that are safe to use outside Manetu's secure environment — in data lakes, email, or external systems — without exposing underlying values. Authorized users re-identify with proper permission.
Dynamic Masking
Automatically generate masked versions of sensitive attributes, configurable by type and format, applied globally or per-vault. Queries return the original value or its masked equivalent based on the caller's authorization level.
Tokenization Options
| Token Type | Write Perf | Read Perf | Token Size | Deterministic |
|---|---|---|---|---|
| Graph IRI | Low | High | Variable | Yes |
| Graph UUID | Low | High | Fixed / Small | Yes |
| Ephemeral Token | Very High | Very High | Variable / Large | No |
| Persistent Token | High | High | Fixed / Small | Yes |
Deployment
Deployed On-Premises
Knowledge Graph is deployed within your own infrastructure, keeping data and encryption keys inside environments your organization controls directly. It's designed to sit alongside the systems you already run, extending secure, policy-governed access to your existing data estate without requiring that sensitive data leave your environment.
Part of the Manetu authorization platform: Knowledge Graph supplies the context that authorization decisions depend on — who's related to what, and how. It feeds PolicyEngine™ the context a policy decision evaluates against, and represents delegated authority for agents governed by AgentVisor™, so decisions reflect real organizational structure rather than static roles alone.
Supported Use Cases
Customer 360 with Privacy
Build comprehensive customer profiles spanning multiple systems while maintaining strict privacy controls. SPARQL queries traverse relationships between customers, accounts, transactions, and interactions — with policy-based access ensuring each user sees only what they're authorized to see.
Regulatory Compliance
Demonstrate compliance with GDPR, CCPA, and other regulations using fine-grained control: track data lineage through Tags, expire data automatically through Vault policies, and generate the audit trails regulators require.
Secure Data Collaboration
Share sensitive data across research institutions and multi-party collaborations without exposing underlying values. Partners query the combined dataset and receive masked or aggregated results based on their authorization level.
AI-Grounded Retrieval
Ground LLM applications in private data through Permissioned RAG and GraphRAG — retrieval that respects access control by design, producing responses that are accurate, explainable, and compliant with governance policy.
Availability
Available for organizations of every size
Knowledge Graph is available to both SMB and enterprise customers. Pricing and deployment scope are tailored to your environment and available upon request — contact Manetu to discuss what a deployment looks like for your organization.
Talk to us about Knowledge Graph in your environment
We'll walk through your data estate, your access and compliance requirements, and how a Knowledge Graph deployment fits alongside AgentVisor™ and PolicyEngine™.