Data Plane
Tenant-local product plane hosting catalog, control, enforcement, telemetry, AI Graph, and Cockpit functionality.
Where the Control Plane knows about every tenant, a Data Plane knows about exactly one. It runs inside that tenant's own cluster (or namespace, in the shared SaaS path) and is where the actual work of governing AI activity happens — the Control Plane only creates, tracks, and administers Data Planes; it never sees the tenant's tools, policies, or invocation traffic directly.
Its router (data-plane/app/backend/gateway/router.go) mounts the current API under /api/dp/v1, alongside a large set of legacy /api/* compatibility routes the existing React frontend still calls. The module list under data-plane/modules/ reads as the product's full governance pipeline: catalog holds the inventory of MCP servers, tools, resources, and AI Actors; discovery and actordiscovery find and register that inventory automatically; policy authors and evaluates governance rules and compiles them to the Rego bundle the enforcement path consumes; mcpgateway and mcpproxy are the actual traffic paths a governed MCP call goes through; aigraph builds the AI Graph relationship map between actors, tools, and data; telemetry and cockpit turn invocation and decision events into the observability and FinOps surfaces; identity and secrets handle the Data Plane's own auth and at-rest credential encryption for connectors; and edges and connectors manage the MCP connections themselves. nlp is small and specific: it backs the natural-language policy-drafting box, using the same OpenAI key as the policy drafter and falling back to heuristic matching with no key configured.
A Data Plane is also where policy decisions are actually made. The /api/dp/v1/policy-bundle endpoint compiles a tenant's authored policies into a Rego bundle plus resolution maps (tool, table, and column IDs), which a Policy Enforcer — running as a sidecar at the customer's network edge, outside this Go process entirely — pulls and evaluates locally. That split matters operationally: enforcement decisions keep working even if the Data Plane itself is briefly unreachable, because the compiled bundle and the Rego evaluation live with the Enforcer, not the DP. What the Enforcer sends back is telemetry, not a request for a decision — /api/dp/v1/telemetry/batch accepts batched invocation and decision events from any edge Enforcer and writes them into the same gcdm_invocations / gcdm_decision_logs tables that in-cluster gateway calls use, so Cockpit and the Decisions log render both sources identically.
Like the Control Plane, a Data Plane can serve its own baked-in documentation corpus, but it prefers to proxy reads to the Control Plane's copy when one is reachable (/docs), falling back to its own only in standalone deployments — one canonical corpus, projected from wherever is nearest.

Docs