OntoKai - Knowledge Representation and Ontology Management software
OntoKai is a new kind of software for envisioning, managing, translating and merging detailed knowledge representations such as taxonomies, ontologies and data models. It supports work in data sharing/interoperability, data standards, data quality and improving data skills; key problem areas targeted by the National Audit Office to improve government data.
Features
- Structuring unstructured data to support next generation AI modelling tools
- Visualisation of data assets, flows and relationships, internally and externally
- Ontologies to make data and data structures accessible to generalists
- Data condition assessment and tracking of change
- Audit of data ownership, governance and absent accountabilities
- Identification and resolution of data gaps and overlaps across agencies
- EU AI quality and transparency compliance for high-risk systems
- Data pre-processing, normalization and transformation
- Data selection by complex criteria from multiple data sources
- Adding ontological context to AI models
Benefits
- Accelerates data projects reducing time, cost and technical dependencies
- Prevents costly duplication by identifying redundant data across systems
- Reduces vendor lock-in through open standards-compliant data structures
- Delivers business cases for data investment with value-weighted prioritisation
- Builds sustainable data capability affordably within existing teams
- Enables faster system integration reducing information rework and friction
- Provides AI-ready semantic infrastructure supporting institutional context and governance
- Improves cross-organisational data sharing accelerating collaboration and interoperability
- Reduces risk through improved data quality trust and provenance
- Empowers strategic decisions with comprehensive visible data supply chains
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 4 4 5 4 5 3 3 5 9 9 4 3 2 9
Contact
Kaiasm
Steve Johnston
Telephone: 0330 223 1164
Email: info@kaiasm.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
-
- Scalable Vector Graphic capable web browser
- Some JavaScript libraries that run in the client browser.
User support
- Email or online ticketing support
- Yes
- Support response times
-
UK operational hours (Monday to Friday, 9-5, excluding bank holidays), unless the SoW between the client and supplier specifically includes provisions for extended support.
SLA response time within 2 hrs to within 16 hrs depending on trouble. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- OntoKai can inherit 3rd party solutions such as Teams/Slack. Built-in capabilities are therefore not natively included though could be provided at additional cost.
- Onsite support
- Yes, at extra cost
- Support levels
-
Support levels and pricing agreed on a per contract basis.
Typical SLA outline provided in the accompanying Terms and Conditions Document.
Ranges from no support required through to extensive consultancy support. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We provide
- onsite training
- offsite training
- user documentation
- in-application help - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Google Docs
- Microsoft Word
- End-of-contract data extraction
- A user may download their data, as a whole or in part, at any point, in a variety of web standards formats including JSON, CSV, TTL, OWL and RDF/XML.
- End-of-contract process
- Client may opt to continue the service at a different service level, or cancel the service.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Utilises existing accessibility of the publishing platform.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The service provides both human-facing and programmatic service interfaces. It includes a browser-based web user interface used by end users and administrators for normal operation and service management, including user management, security roles, and sensitivity or classification controls. The service also exposes a RESTful API with a published OpenAPI specification to enable integration with external systems. It is further designed to support Model Context Protocol (MCP) to allow AI systems to consume contextual and reference data. Authentication and authorisation use industry-standard identity management, with Auth0 by default and support for federation with enterprise identity providers such as Microsoft Entra ID.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- We test using the iOS default assistive techology VoiceOver.
- API
- Yes
- What users can and can't do using the API
- The service provides a RESTful API that supports read-only access to ontology, architecture, and metadata held within the platform. The API exposes versioned endpoints and allows clients to retrieve nodes, taxons, architectures, sources, relationships, and associated meta-characteristics. It offers flexible scoping, entity type selection, filtering, sorting, pagination, and windowing to enable efficient downstream consumption and analysis. Responses are returned in a structured JSON format, with support for conditional requests and caching via standard HTTP mechanisms. The API also supports direct export of published architectures in multiple standard formats, including Turtle, XML, N-Triples, and CSV representations. The API is designed to operate with standards-based authentication and authorisation, using conventional HTTP status codes for access control and error handling.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service is designed to be highly customisable.
For example,
- Custom views can be defined and bookmarked by any user.
- Custom entity and relationship attributes can be defined for particular use cases.
- Data validation rules can be defined for particular use cases.
- Test, warn and task rules can be defined for particular use cases.
Customisations which affect other users are reserved for users with at least editor level permissions.
Scaling
- Independence of resources
-
Service is deployed either within AWS or for certain sovereign applications, in Civo or OVHcloud (in which case these third party SLAs apply), or within a client's own cloud tenancy.
Service can be instantiated on local hardware where required in high security environments. In this case an authentication service integration will be required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The web application is instrumented for Google Analytics (this can be removed on request for secure environments)
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Other
- Other data at rest protection approach
-
Depending on client need, an extra level of security can be applied by holding all data at rest on AWS cloud instances as encrypted, at no additional cost, but at a slight reduction in system performance.
Physical access control is inherited from our Cloud Services providers.
All data in flight is encrypted by default. - Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- User interface option for multiple, on-demand, views or extracts in open standards formats.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- RDF/XML
- OWL
- TTL
- SKOS
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- OWL
- RDF/XML
- JSON
- SKOS
- Excel
- Log files
- TTL
- Any other data format by request (additional cost)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
If the service is hosted by Kaiasm, then uptime of covered services is guaranteed to a certain percentage of time within UK office hours, which is 9am-5.30pm Mon-Fri excluding bank holidays (the services will normally also be available outside these hours). The level of guaranteed uptime ranges from 95% to 99%, depending on the priority level of the service.
Uptime is calculated to the nearest minute, based on the number of minutes in the given month within the scope of the SLA. If uptime for any item drops below the relevant threshold, a penalty will be applied in the form of a credit for the client. The following month’s fee payable for the named service will be reduced on a sliding scale, or additional time will be added to the end of the contract, at the client's discretion.
Penalties range from 1% to 5% of the covered service per hour of downtime, depending on the priority of service. Uptime penalties in any month are capped at 100% of the total monthly fee of the covered service. Uptime measurements exclude periods of routine maintenance. These must be agreed between the supplier and client in advance. - Approach to resilience
- Information on resilience is available on request.
- Outage reporting
- Email and chat alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
As per user authentication plus, optionally:
- IP Whitelist/Firewall
- VPN
- Role based permission control - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
Information security policies are available on request and include:
- Firewalls;
- Secure configuration;
- User access control;
- Malware protections;
- Patch management.
General infosec policies include:
- Use and misuse;
- Working Remotely;
- Bring Your Own Device (BYOD) & Working from Home;
- Information classification;
- Backups;
- Access control, including administrator access policy;
- Password policy;
- Cryptographic controls;
- Social media & Personal Devices;
- Whitelisted Apps.
Policy compliance ensured via Cyber Essentials Plus certification, as well as internal controls (managed on an ongoing basis, including weekly patch scanning, and an annual compliance audit).
As we are a small company, reporting structure would be directly from IT or ops engineer to a member of senior management. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Status, location and configuration of service components (both hardware and software) are tracked throughout their lifetime.
Changes to the service are assessed for potential security impact. Then managed and tracked through to completion. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Cybersec risk/threat assessment performed annually as per Cyber Essentials Plus.
Patching timescales as per Cyber Essentials Plus or better (we run a 7-day patch cycle):
- If evidence suggests a vulnerability is being actively exploited in the wild, mitigation to be put in place immediately.
- ‘Critical’ patches deployed within hours
- ‘Important’ patches deployed within 2 weeks of a patch becoming available
- ‘Other’ patches deployed within 8 weeks of a patch becoming available
Information on potential threats sourced from
- Endpoint Central patch scanning
- NCSC Early Warning service
- Mailing lists (various) - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
The system supports extensive event auditing.
Further details on protective monitoring approach available on request. - Incident management type
- Supplier-defined controls
- Incident management approach
- Kaiasm operates a documented incident management and disaster recovery process aligned with NCSC guidance and integrated with business continuity arrangements. Pre-defined procedures exist for common incident types, including security incidents, data breaches, service outages, and supplier or infrastructure failures. Incidents are classified by severity based on impact to availability, confidentiality, and integrity, with escalation to named senior staff. Users report incidents via established support and account management channels, with incidents coordinated through a dedicated internal incident channel. Clients are informed of incidents. Incident reports cover cause, impact, actions taken, and lessons learned.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
OntoKai can be made available to organisations wanting to evaluate the service.
A trial instance of OntoKai includes anonymised test data and the ability to view, write, edit, merge and download capabilities.
Trials run for 7 to 30 days, depending on requirements.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F3f4fe36-930e-425c-84c9-afaa4d99958a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-