Data governance and lineage for RAG and GenAI pipelines
Pebblo is an open-source data-governance layer for GenAI apps, from Daxa AI. It scans the documents flowing into your RAG pipeline, classifies sensitive data (PII, PCI, HIPAA, source-code secrets), and builds a live data lineage graph so security teams can answer "what did the model see?" without reverse-engineering a vector DB. It slots in next to LangChain/LlamaIndex and reports to a console.
Who it's for: Platform and security teams at regulated-industry companies who need provable data lineage on their RAG stack, and any team that has had a "wait — did customer data just hit the LLM?" scare.
Detects PII, PCI, HIPAA, secrets, IP, and custom entity classes inside documents before they hit the vector store.
Maps document-to-chunk-to-embedding-to-prompt flow so you can answer "who touched this file" after the fact.
Block or redact in flight — deny-list an entire SharePoint folder, redact SSNs, or route flagged docs for review.
One-click HTML/PDF reports for security review boards and customer audits.
If you are shipping RAG into production at a company with any compliance surface at all, Pebblo belongs in the stack — it solves the input-side data-governance problem that none of the big observability tools touch.