AI infrastructure that's ready for the enterprise, not just the demo.
Epimathea builds open-source AI infrastructure for real organizations. Our projects ship with multi-tenancy, RBAC, audit trails, SSO, and self-hosted deployment built in — the controls security, platform, and compliance teams ask for before anything reaches production.
Open source under permissive licenses. Built to be self-hosted.
Multi-tenant by design
RBAC & tenant isolation
Audit & SIEM export
LDAP / Active Directory
Kubernetes · OpenShift · Helm
On-prem & self-hosted
The Epimathea standard
spec
What we build into every project, from the first commit.
Multi-tenant data model with enforced isolation
Role-based access control on every action
Audit-ready event history with SIEM export
SSO via LDAP / Active Directory
Self-hosted: Docker, Kubernetes, OpenShift
Secure defaults, not optional add-ons
Open source · permissive licenses
The gap we close
Most AI projects are impressive demos. Very few are ready to run a company on.
The AI ecosystem is full of clever tools built for a single user on a laptop. The moment a real organization tries to adopt them, the gaps show. Epimathea starts from the other end.
01
Built for one user, not an organization
No tenants, no roles, no isolation. Fine for a demo; a non-starter the moment more than one team depends on it.
02
No answer when security asks
No audit trail, no SSO, no way to prove who did what. Adoption stalls at the first review.
03
Cloud-only, take-it-or-leave-it
Regulated and high-trust teams need on-prem and self-hosted paths. Most projects never offer one.
Our approach
Enterprise concerns are the starting point, not a later phase.
We come from the enterprise world, so we design for it from the first commit rather than retrofitting it once a project gets popular.
Enterprise-ready by default
Multi-tenancy, RBAC, audit, SSO, and isolation are part of the architecture from day one — not a paid tier bolted on later.
Open source, permissive licenses
Our software is open source and self-hostable. Diodos ships under Apache-2.0. You can read it, run it, and own your deployment.
Built by people who know the enterprise
We've lived inside large organizations. We build for the realities of procurement, security review, and on-prem operations.
AI-native, not AI-bolted-on
Each project is designed around how AI agents, models, and tools actually behave — governed, observable, and controllable.
Projects
A growing family of AI infrastructure projects.
Each project stands on its own, is open source, and is built to the same enterprise standard.
Diodos
Available now
DLP for AI agents and LLM providers
Diodos routes AI egress through a managed gateway and masks sensitive data locally, before plaintext leaves the device. Security, engineering, and finance teams get audit-ready visibility into usage, findings, cost, and anomalies.
Loomic is an on-prem-first platform for orchestrating fleets of agent CLIs across many machines — the agentic successor to RPA. A control plane governs agents, budgets, and policy; a distributed runner fleet does the work, with humans in the loop.
Control plane as the single source of truth
Distributed runner fleet across your machines
Multi-tenant, on-prem-first, air-gap-friendly
Governance, budgets, and audit built in
License: Apache-2.0Public release coming soon.
Enterprise-ready
What “enterprise-ready” means to us.
Not a marketing label. A concrete set of controls we design and build for. Depth varies by project, but the standard does not.
Multi-tenancy & tenant isolation
A tenant-aware data model with isolation enforced in the application (and at the database, where the project calls for it) — not just a filter on a query.
RBAC & permission checks
Role-based access control on every sensitive action, with audit on the ones that matter.
Audit trails & SIEM export
An audit-ready event history you can stream to your SIEM and export for security review.
SSO: LDAP / Active Directory
Authenticate against your existing identity source and map directory groups to roles.
On-prem & self-hosted
Designed to run in your environment, including air-gapped and high-trust deployments, not only in someone else's cloud.
Kubernetes, OpenShift & Helm
Container-first delivery with compose for trials and Helm charts for production clusters.
Cost & usage governance
See real usage and cost, attribute it, and set the limits finance and platform teams need.
Secure by default
Signed policy, typed control planes, and least-privilege defaults — security is the default state, not an upgrade.
FAQ
Questions teams ask first.
What is Epimathea?
Epimathea builds enterprise-ready, open-source AI infrastructure. It is the home for a family of projects that give real organizations a governed, observable, and self-hostable way to adopt AI. The first public project is Diodos, DLP for AI agents, released under Apache-2.0.
What does “enterprise-ready” mean here?
It means the controls organizations require in production are built in from the start: multi-tenancy and tenant isolation, role-based access control, audit trails with SIEM export, SSO via LDAP or Active Directory, cost governance, and self-hosted deployment on Docker, Kubernetes, and OpenShift. Not a demo, and not a paid tier bolted on later.
Which projects does Epimathea maintain?
Diodos, DLP for AI agents and LLM providers, is available now and open source under Apache-2.0. Loomic, a distributed platform for orchestrating fleets of AI agent CLIs, is in development and will be released publicly soon.
Is Epimathea's software open source and free?
Yes. Our software is open source under permissive licenses — Diodos ships under Apache-2.0 — and is built to be self-hosted. Paid enterprise support, managed deployment, or hosting may be offered separately, but the software itself is open.
Can I self-host and run it on-prem?
Yes. Our projects are designed to run in your own environment, including on-premises and air-gapped setups, with Docker Compose for trials and Helm charts for Kubernetes and OpenShift in production.
Who is Epimathea for?
Enterprise security, platform, and infrastructure teams; AI governance committees; CTO and CIO organizations; and regulated or high-trust businesses that want to adopt AI without giving up control of their data and systems.
How is this different from typical AI side-projects?
Most AI tools are built for a single user and stop at the demo. Epimathea starts from the enterprise requirements — identity, isolation, audit, deployment — that decide whether software can actually run inside an organization, and builds the AI capabilities on top of that foundation.
How can I follow or get in touch?
Follow and star our work on GitHub at github.com/epimathea, and reach us at [email protected].
Adopt AI without giving up control.
Explore our open-source projects, self-host them in your environment, or get in touch about your organization's needs.