Governed data.
Governed inference.
One tenant at a time.
Zell Analytics is a single-tenant analytics and AI platform built for regulated enterprise use. Azure-first, cloud-agnostic by design, and delivered as SaaS or inside your own cloud account.
Three principles the whole architecture rests on.
The rest is how they're enforced. If you take three things, take these.
Your environment is yours alone.
Every Zell deployment is dedicated to one customer. Nothing is shared with any other.
No AI sees your raw data.
Calculations run inside Zell. Customer data is obfuscated before any AI model is invoked.
Every number is fully traceable.
From the executive narrative back to the source line behind it.
One customer per environment. Nothing shared.
Every Zell deployment is dedicated to one customer. No shared compute, storage, catalog, lineage, audit, secrets, embeddings, vector stores, mapping stores, salts, prompts, logs or insight execution context.
The scope of a single tenant
A dedicated data plane, control plane and intelligence plane — storage, compute, orchestration, catalog, secrets and the Intelligence Layer. One customer's environment end to end.
What customers never share
Compute, storage, metadata catalog, lineage records, audit artefacts, secrets vaults, vector stores, tokenisation salts, mapping stores, LLM prompts, logs and RAG context. No exceptions.
Boundaries are enforced at every layer.
The isolation guarantee only holds if it's enforced everywhere — at the identity layer, the data layer, the network layer and the secret-management layer. Zell aligns to a Zero Trust posture: strong identity, least privilege, encryption end to end, segmented networks, continuous monitoring.
OIDC/OAuth2 and SAML 2.0 federation, MFA via the customer IdP. Access is deny-by-default: every request starts with zero reach, and a role plus a data-tag ACL must explicitly grant a dataset before it resolves — enforced on the server across platform services, data layers, secrets and the Intelligence Layer. Tiers run from administrator to scoped analyst to no-access; a scoped account can't elevate itself, and permissions are resolved server-side, never asserted by the client.
TLS in transit. Cloud-native encryption at rest. Customer-Managed Keys supported where contracted. Restricted classifications blockable from any surface; non-prod data controlled via masking and pseudonymisation.
Per-tenant key vault. Salts and customer secret material stay inside the tenant boundary, with access restricted to dedicated service identities. Consolidation into a managed secrets store with formal key rotation is in progress.
Segmentation by environment, by sensitivity (secrets, mapping, audit) and by exposure (public vs internal). Allow-listed egress only. Service-to-service TLS. Secure admin entry with privileged-session logging.
PII handling: classification runs at ingestion. Where fields are flagged restricted, they are filtered at source and not propagated through the lakehouse — the Intelligence Layer works on data that doesn't carry them.
Wherever your data lives, Zell ingests it.
Every source attaches via a connector that enforces the data contract. Schema validation, classification and CRC integrity checks run at the boundary, before anything lands in Bronze.
Object storage and secure file transfer. Tenant-scoped landing zones with classification at the boundary.
Scheduled and event-triggered. Idempotent retries with backoff; failed records quarantine with reason code.
At-least-once delivery into Bronze with watermarked late-arrival handling.
Change-data-capture from relational sources via standard CDC tooling. Schema evolution handled as a first-class concern.
Where a source isn't standard, the connector is built during onboarding and inherits the same contract guarantees as the rest.
Bronze. Silver. Gold. Gates between every layer.
Data enters the lakehouse under contract — every dataset carries its ID, domain, layer, schema version, partition spec, run ID and pipeline version. Promotion between layers is gated. Failing records quarantine with a reason code. Publish is atomic.
Schema-validated, classified, audited at the boundary.
Business entities reconciled, identifiers aligned, rules applied.
Semantic models and reporting-ready outputs for dashboards, APIs and the Intelligence Layer.
FAILED_TRANSIENTFAILED_STRUCTURALQUARANTINEDTables, time travel, schema evolution as first-class concerns.
Tenant-scoped, aligned to domain and layer.
Rerun-safe, rollback-ready via versioned publish pointer.
Calculation runs in Zell. Narrative comes from a compatible LLM.
The Intelligence Layer separates two things most AI-on-data platforms conflate. Calculation — every reconciliation, every metric, every number — runs deterministically inside Zell. The LLM never produces a number; it generates narrative from the numbers Zell calculated. That separation is what makes agentic output auditable.
The model itself is configurable. Azure OpenAI by default. Anthropic, Google and other compatible major providers can be configured per tenant. The agents depend on specific model capabilities, so the choice is among the providers that support them. Each customer's deployment runs against one chosen model, isolated from every other customer's.
Every call follows the same safety path.
What reaches the model is tightly bounded — anonymised tokens, curated metrics and aggregates, governed contextual facts, and policy-filtered RAG snippets, and nothing else. The architecture forecloses anything outside that envelope.
Intake & authorise
SSO, RBAC and classification checks before the request is accepted.
Anonymise
Deterministic tokens, per-tenant salt held in a secrets vault. Mapping store stays inside the tenant boundary.
Verify
Hard-stop gate. Calls that fail validation emit a reason-coded audit event and stop here.
Invoke
Model call inside the customer's chosen region. Response post-processed and rendered under RBAC.
Contained against prompt injection.
The risk unique to AI on data is that someone hides instructions inside the data, hoping the model treats them as commands. Results come back as structured data, not free-form text, leaving little room to smuggle a command. Even if injected text did reach the model, an analyst-scoped connection cannot trigger anything that changes or publishes data — those actions are reserved for administrators. And because every connection is deny-by-default, nothing beyond what the account was already granted is reachable, however a request is phrased.
And it learns from how your team uses it.
A thumbs-up on one dashboard says little about how a team works. Zell learns from what each team discusses, actions and refines, plus transcripts and audio where shared, and that feeds back into agent context. The insights you see sharpen the longer your team uses them.
Four ways in, one set of controls.
Zell is built to be accessed programmatically, not only through dashboards. Whether you're connecting a BI tool to a SQL endpoint, calling a REST API from a service, or bringing your own AI tools through MCP, every request flows through the same identity, RBAC, classification and audit envelope.
Query reconciled datasets, fetch executive narratives, list available agents. OAuth2-protected; per-request RBAC.
Read-only access to Gold-layer semantic models. Tenant-scoped, classification-aware, query-auditable.
Bring your own AI. The doorway for external AI clients — same boundary, same controls. Covered in detail below.
Power BI, Grafana, Excel (via Power Query) and similar tools connect through the SQL endpoint or REST API. No bespoke connector required.
External AI, governed by the same boundary.
MCP is the doorway through which an external AI client reaches Zell. The MCP server lives inside the tenant boundary — same compute, same storage, same audit envelope as the rest of the platform. Nothing about it loosens the isolation story.
Every MCP call routes through the same controls as an internal one. SSO and RBAC at intake. Deterministic tokenisation at the trust boundary. The verification gate that confirms the call is clean before invocation. The audit envelope that records the call and its outcome. The Intelligence Layer pattern — anonymise, verify, invoke — applies whether the call originated inside Zell or arrived through MCP.
Understand intent
Read the user's natural-language request and identify what they're asking for.
Discover tools
List the MCP servers available, including Zell's tool catalogue.
Fetch context
Retrieve schemas, docs and recipes for the chosen tools.
Execute
Run the tool calls. Auth, RBAC and the Intelligence Layer controls apply per call.
Format
Compose the results. Trigger another discovery cycle if more tools are needed.
Present
Return the answer to the user inside their AI client.
Curated Gold-layer datasets and named agent tools, both inside the customer's RBAC scope. Access is read-only — tools query, they never modify, delete or export source data — and results return structured and size-capped, never raw files or bulk dumps. Same boundary as the Intelligence Layer; the architecture forecloses anything outside that scope.
Tamper-evident by construction.
Every ingestion, promotion, publish, access event, privileged action and Intelligence Layer step emits an audit event. Events land in two stores — an operational NoSQL index for query, and an immutable object-storage system of record that holds the authoritative copy. Each batch manifest carries the hash of the one before it, so any tampering breaks a chain that is easy to detect and hard to hide.
Operational index alongside an immutable system of record.
Batch manifests reference the prior hash — tampering breaks the chain.
Default retention; archival thereafter per policy.
Scheduled batch delivery. Scope and cadence set per deployment.
Azure today, cloud-agnostic by design.
Zell is built on cloud-portable substrate — Apache Spark, Delta Lake, Hive-compatible catalog, OIDC and SAML federation. The current reference implementation runs on Azure: ADLS Gen2 for storage, Azure OpenAI for inference, Azure Key Vault for secrets, Azure regions for data residency. The architecture is not locked to Azure, and the same substrate choices translate to other major clouds for customers who need them.
Zell-hosted
Single-tenant per customer, in your chosen region. We operate the environment end to end.
Your account, our operating team
Customer-managed Azure subscription today. Zell operates inside your account; you retain ownership, billing and custody.
On-premises and non-Azure clouds are possible and we are happy to scope a bespoke engagement. They are not turnkey today. The Intelligence Layer currently targets Azure OpenAI — for other model gateways we align during onboarding.
Taking compliance and security seriously.
Zell Analytics is delivered under the StructureIt compliance umbrella. The ISAE 3000, SOC II Type 2 and FSQS certifications shown below are held at the StructureIt group level — Zell's services are delivered within those controls. Independent certification of Zell Analytics specifically is planned for the next audit cycle.
ICO registered, reference number ZA397954.
Review the architecture with our team.
A one-hour session with a Zell solutions architect. We walk the whitepapers, answer specific questions and scope a pilot tailored to your environment.
Whitepapers sent by email after a brief introduction — Architecture, Data Architecture & Processing, and Security & AI Controls.
