Sovereign data & AI platform

From raw data to AI agents in production.On your infrastructure.

graal brings connectors, pipelines, lakehouse, notebooks, models and generative AI together in a single platform, installed on your infrastructure. Your teams and your AI agents run it with the same permissions, and every action is traced.

  • On-premises
  • Private cloud
  • Qualified hosting provider

Demonstration

A node fails. Watch the pipeline recover.

conso-regionale-daily

  1. The pipeline runs
  2. A node fails
  3. The agent diagnoses and reruns

Job code

import pandas as pd # Aggregate consumption by region and by daydef agregation(df: pd.DataFrame) -> pd.DataFrame:    return (        df.groupby(["region", "jour"])          .agg(conso=("conso_mw""conso_mwh", "sum"))          .reset_index()    )

Console

  1. # conso-regionale-daily · run-1285
  2. INFO ingest: 12 regions, 1,216,488 rows
  3. INFO cleaning: 0 duplicates
  4. ERROR agregation: KeyError: 'conso_mw'
  5. WARN retry 2/3: same error
  6. ◆ agent: the source now names the column conso_mwh
  7. INFO run-1286: agregation finished in 38 s

Event timeline

conso-regionale-daily · run-1285 → run-1286

  1. run-1285 started
  2. ingest
  3. cleaning
  4. agregation
  5. agregation · KeyError
  6. retry 2/3
  7. run failed · alert
  8. get_run_logs
  9. diagnosis: column renamed
  10. upload_code · fix
  11. approved by a human
  12. run_job · run-1286
  13. run-1286 succeeded

Animated illustration of a demonstration scenario, not a console screenshot: job, columns and identifiers are fictional.

The job list of a project in the graal console: name, type (Spark, Python, low-code, bash), status, last run, duration. Several rows carry an “Agent” badge.The job list of a project in the graal console: name, type (Spark, Python, low-code, bash), status, last run, duration. Several rows carry an “Agent” badge.

The jobs of a project, their status and their last run. Rows marked “Agent” were created by an AI agent through MCP.

Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).

Activity feed of an AI agent: creating, running and then scheduling the prevision-conso job.
Agentagent · claudeLive
  1. create_jobprevisions/prevision-conso✓ created
  2. run_jobprevision-consorunning
  3. schedule_job0 6 * * *✓ scheduled

Service account agent-previsions · project previsions

Built on open standards

  • Kubernetes
  • Helm
  • Apache Iceberg
  • Trino
  • Apache Spark
  • Jupyter
  • MLflow
  • Keycloak
  • PostgreSQL
  • S3
  • MCP

Platform

The whole data & AI lifecycle, on one platform

From the first connected source to the model served in production, without stitching ten tools together.

Connectors

Your databases, files, APIs and Hadoop estate, connected in minutes.

Low-code pipelines

Draw a pipeline: graal writes the Pandas or PySpark code, and it is yours.

Lakehouse and SQL

Iceberg tables on your S3 storage, federated SQL with Trino, catalog and lineage.

Notebooks

Jupyter and VS Code in the browser, with a coding assistant wired to your own model.

ML and generative AI

Experiments, model registry and serving; an LLM gateway and RAG over your documents.

AI agents

An MCP server so your agents create, run and schedule work, under your rules.

Governance

Per-project permissions, an audit trail of human and agent actions, encrypted secrets, costs and quotas.

Openness

Exportable code, open formats, REST API, MLflow and MCP: nothing locks you in.

How it works

From raw data to a model in production

One source, one secret, and it's wired.

  • Databases, files, S3, SFTP and REST APIs
  • Encrypted credentials, never written into code
  • Schema detection and data preview
Interface illustration

AI agents

Your AI agents run the platform. Under your rules.

graal exposes an MCP server. Claude, or any compatible client, creates, runs and schedules jobs through a service account scoped to one project, and every action shows up live in the console.

  • One service account per project
  • Human approval for sensitive actions
  • No destructive tool enabled by default
  • Every call visible live
  • Instant revocation
  • Audit trail of humans and agents

You choose the model: hosted on your premises, or with the provider of your choice.

Activity feed of an AI agent: listing runs, reading logs, creating, running and scheduling a job.
Agentagent · claudeLive
  1. list_runsprevisions✓ 12 runs
  2. get_run_logsrun-1284✓ read
  3. create_jobprevisions/prevision-conso✓ created
  4. run_jobprevision-consorunning
  5. schedule_job0 6 * * *✓ scheduled

Service account agent-previsions · project previsions

The “Agents” panel of the graal console, open next to the job list: connected agents, their permissions (read, write) and their live activity (get_run_logs, run_job, schedule_job, create_job).The “Agents” panel of the graal console, open next to the job list: connected agents, their permissions (read, write) and their live activity (get_run_logs, run_job, schedule_job, create_job).

The “Agents” panel: who is connected, with which permissions, and every tool call live.

Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).

Deployment

Installed on your infrastructure. In a few commands.

One Helm chart, no cluster-admin rights and no custom resources: graal runs where your data lives.

  • Helm
  • OpenShift
  • High availability
  • Offline (air-gapped)
  • GitOps
  • Backup and restore

Your teams · SSO

◆ Your AI agents · MCP

graal · control plane

  • Console
  • REST API and MCP
  • Identity · Keycloak
  • Metadata · PostgreSQL

graal · execution

  • Jobs and workflows
  • Notebooks
  • Distributed Spark
  • Model serving

Your resources

  • S3 storage
  • LDAP / AD directory
  • Image registry
  • Observability

Your Kubernetes cluster · on-premises, private cloud or qualified hosting

On-premises

Your datacenter, your Kubernetes or OpenShift.

Private cloud

Your cloud, your account, your network rules.

Qualified hosting

Deployable with a SecNumCloud-qualified or HDS-certified hosting provider.

Use cases

What you build with graal

Energy

Forecast energy demand

Temperatures and regional consumption in a thermosensitivity model, refreshed every morning.

IndustriesBrowse industries

Who it's for

One platform, five requirements

One platform instead of seven building blocks, on your infrastructure, at a predictable cost.

See pricing
  • Per-vCPU license, unlimited users
  • Exported code and open formats
  • Installed and upgraded with Helm and GitOps

Trust

Trust you can verify

  • Restricted pods (PSA restricted)
  • SSO with OIDC, SAML and LDAP directories
  • Permissions per project and per resource
  • Secrets encrypted at rest (AES-GCM)
  • Audit of human and agent actions
  • No telemetry, no third-party service

Sovereign, strictly defined

  1. 01The platform and the data run on the infrastructure you choose.
  2. 02No third-party service is required for it to work: no SaaS, no telemetry, no external fonts or captcha.
  3. 03The vendor, which also integrates and supports the platform, is a French company (GRAAL.SYSTEMS SAS).
  4. 04Pipeline code is exportable and formats are open (Parquet, Iceberg, SQL, MLflow API).
Trust center

Get started

Start with an 8-week pilot

One use case end to end, on your data, in your infrastructure. Then you decide, on evidence.

Discover the pilot
  1. Week 1

    Scoping: one use case, clear success criteria

  2. Weeks 2–3

    Installation on your infrastructure

  3. Weeks 4–7

    The use case end to end, on your data

  4. Week 8

    Review and decision

Frequently asked questions

Do we need a Kubernetes cluster?

Yes. graal installs on your Kubernetes or OpenShift, on-premises or with a hosting provider. If the cluster still has to be built, we help you.

Which model drives the agents?

The one you choose: a model hosted on your premises and served by graal's LLM gateway, or the provider of your choice. graal speaks MCP, an open protocol.

Is graal SecNumCloud-qualified or HDS-certified?

Those labels qualify hosting offers, not software. graal deploys with a SecNumCloud-qualified or HDS-certified hosting provider, just as it does in your own datacenter.

Does our data leave our infrastructure?

No. The platform and the data stay with you. If you connect an external model, it only receives what the tools it calls return.

Can it be installed without Internet access?

Yes. graal installs offline, from your own image registry.

How is pricing calculated?

An annual license per vCPU allocated to workloads, unlimited users, no usage-based billing.

Who provides support?

The vendor. graal Services cover integration, migration, training and operations.

What if we want to leave?

Pipeline code is exportable and formats are open: you leave with your work.

Let's see graal on your data