Sitelet https://github.com/datacharter/datacharter
Skip to content

About

Your data, explored locally — and your AI agents kept on a leash. A federated data explorer with governed agentic access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

13 stars

Watchers

1 watching

Forks

Latest commit

 

History

226 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

DataCharter

Query all your data locally. Hand agents exactly the columns you choose.

A local SQL workspace over files and databases, federated by DuckDB and governed by charter.yaml. Agents get read-only, PII-masked access to what the contract grants. Apache-2.0. No paid edition.

PyPI Python License: Apache-2.0

datacharter.dev · Docs · Desktop · GovBench · Deploy

Two ways in. Same kernel.

Laptop

Drop a file. Query it. Chart it. An agent sees ••• where PII lives.

uvx datacharter serve          # demo workspace, http://127.0.0.1:8321
# or: datacharter init --from && datacharter serve
# or: datacharter init --template life && datacharter serve --local

No terminal: desktop app (beta). macOS (Apple Silicon) or Windows. Unsigned until Apple secrets exist.

brew install datacharter/tap/datacharter   # macOS
pip install datacharter                    # Python 3.11+

The workspace is a directory: charter.yaml, queries/, guides/. Commit it. Secrets stay out. Optional agent: SpaceXAI, Claude Code, Ollama (--local), or any OpenAI-compatible endpoint.

Company

The same binary, on a shared MCP endpoint. Identities live in git, not on our servers. No rows leave your infrastructure.

datacharter mcp --http --host 0.0.0.0   # OAuth env required off loopback
helm install datacharter ./chart \
  --set oauth.issuer=... --set oauth.audience=... --set oauth.jwksUri=...
datacharter govbench --json             # cite corpus govbench-v1
  • MCP Streamable HTTP (POST /mcp) with optional OAuth 2.1
  • principals: and grants: in charter.yaml (default-deny on HTTP)
  • Helm chart and OCI image
  • Hash-chained audit plus SIEM JSON/OTLP
  • GovBench: frozen 28-attack corpus, grade A-F

Wrap someone else's MCP server: datacharter mcp --guard "npx -y some-mcp-server".

What the contract enforces

PII default-deny, row filters, plain-English policies (aggregates only), canaries, a flight recorder, datacharter redteam, access diff on PRs. CLI reference: docs/cli.md. Security: docs/security.md.

Status: pre-release. V1 in development.

Privacy

Runs on your machine or in your cluster. No telemetry. No DataCharter-operated data plane. Privacy Policy.

License

Apache-2.0

About

Your data, explored locally — and your AI agents kept on a leash. A federated data explorer with governed agentic access.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

13 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages