Spreadsheets pasted into chats
Without a secure connection, people copy sensitive data into AI tools, beyond any control.
Kortex · Governed AI on your data
Kortex connects claude.ai, ChatGPT, Copilot and the AI tools your team already uses to your data warehouse. Everyone asks with their corporate identity, sees only what their role allows, and every query is audited. Your data never leaves your infrastructure.
Currently being implemented at a Chilean pension fund (AFP).

A real query in claude.ai: Kortex automatically applies the EMEA region filter from the user's role.
The problem
Without a secure connection, people copy sensitive data into AI tools, beyond any control.
An integration with a single service account sees everything, and nobody knows who asked what.
Letting AI write free-form SQL produces made-up joins, inconsistent KPIs and answers nobody can defend.
How it works
AI assistants
claude.ai, ChatGPT, Copilot Studio, Claude Desktop, Claude Code, Cursor
Kortex
Identity, permissions, semantic layer and auditing
Your data warehouse
Read-only user, aggregate queries
The person asks in plain language, in the assistant they already use.
Kortex verifies who they are through corporate SSO: Entra ID or Google.
It applies their roles: which metrics and which rows they can see, server-side, on every query.
It translates the question into an aggregate query over the metrics defined by your data team.
It returns the result to the assistant and logs who queried what, when and from where.
Real permissions
"How are we doing this month?"
EMEA Sales
Sales and orders, for their region only.
Finance
Revenue, margins and costs across the whole company.
Regional HR
Headcount and absenteeism for their region, no sales data.
No role assigned
Nothing. Having a directory account isn't enough.
Semantic layer and cubes
Kortex doesn't let AI guess at tables. Your data team defines cubes with the business's metrics, dimensions and relationships, and every assistant answers using those same definitions.
Each cube describes part of the business in its own language: what counts as revenue, how margin is calculated, what an active customer is. Joins and calculations are defined once, and the agent only chooses which metric to request.
Cubes can declare pre-aggregations that Kortex materializes and keeps up to date inside your infrastructure. Common questions are answered from those aggregates, without scanning millions of warehouse rows: the agent gets in seconds what would otherwise take minutes.
cubes:- name: ventassql_table: dwh.ventasdescription: Ventas netas, sin impuestosmeasures:- name: facturaciontype: sumsql: monto_netodimensions:- name: regiontype: stringpre_aggregations:- name: ventas_por_region_mesmeasures: [facturacion]dimensions: [region]granularity: monthrefresh_key: {every: 1 hour}
The semantic layer lives in YAML configuration files, in a repository your company owns. Your team edits it like any code: with pull requests, review and automated validation. Every approved change reaches production in seconds, with no restarts.
Excel and BI tool connectivityComing soon
The same governed metrics and the same permissions, from Excel and your BI tools too.
Why Kortex
General comparison. Each platform's capabilities vary by product and license tier.
The console
Your team manages access, roles and filters from a web console, and can answer the question auditors care about most in seconds.

Access matrix: every user, their roles, how much of each cube they see and which row filters apply to them.

Row filters by role: anyone with EMEA Sales only sees rows from their region, across every cube.

Reverse lookup: which roles and people can see revenue, and with which filters.
Capabilities
A single URL connects Kortex to claude.ai, ChatGPT, Claude Desktop, Claude Code, Cursor and VS Code. For custom GPTs and Copilot Studio, actions with a ready-to-paste OpenAPI spec.
Everyone signs in with their Entra ID or Google account. No shared accounts or local passwords.
Define per role which measures and dimensions are visible and which rows, e.g. region = EMEA. Enforced server-side, so the agent can't bypass them.
Answers come from a semantic layer with curated business definitions, versioned in your Git with review and automated validation.
No free-form SQL: only aggregate queries over the semantic layer, with a read-only database user.
The agent finds the right metric by meaning, in multiple languages, and only among those the person is allowed to see.
Every query logs who, when, from which app, which metrics, which filters and with what outcome. Returned data is never stored.
A who-can-see-what matrix, reverse lookup by metric ("who can see revenue?") and effective permissions per person.
Users, roles, connected apps, SSO, data sources and auditing in one web console. Changes apply without restarts.
For IT and security
Kortex is installed in your cloud or on your servers. It doesn't copy or index business data: only the model's names and descriptions.
No remote access, agents or tunnels. Your team decides when to install each version.
Agents call Kortex, not the other way around. No outbound access to AI providers required.
AES-256-GCM, with the master key kept outside the database. A backup reveals no passwords.
No role means no access. The admin console only responds from your network's IP ranges.
If you enable it, only counts and latencies are sent, and you see the exact payload before it goes out.
Implementation
A script that only asks for two DNS names and an email address. SSO and the warehouse connection are configured from the console.
Roles are defined and tested with real users in a development environment.
The setup is replicated in production, everyone connects their assistant and administrators are trained.
< 10 s
for a semantic model change to reach production, no restart needed
~1 min
to upgrade versions, with a prior backup and rollback
90 days
of audit history by default, with activity charts and per-person summaries
FAQ
Only the metrics their roles allow and only the rows their filters allow. No role, no access. Permissions are checked server-side on every query.
We'll show you Kortex running with a real assistant and sample roles, and walk through your IT team's requirements together.
How we start
You complete a short form about your process, systems and volumes to validate fit before meetings.
We meet to understand the challenge, estimate the solution's potential value, and confirm whether a clear opportunity exists.
If there is a clear opportunity, we prepare a proposal with scope, timeline and pricing adapted to your operation.
Contact us
Fill out the form and we will get back to you by email to schedule a conversation.
We will reply by email to arrange a first conversation.