Unified Data Foundation
The single source of truth: every event stored once, in an open format, with metadata and governance applied consistently across raw, curated, and analytics-ready data.
🗃 CXOS Data Lakehouse
Apache Iceberg + S3 Compatible Storage
Raw → Curated → Analytics Data Marts
The three-tier structure every event passes through in the lakehouse.
Open Table Format (Iceberg)
The open format that makes zero-copy, multi-engine access possible.
Zero-Copy Architecture
One physical copy of data, queried by many engines.
Time Travel & Versioning
Query the lakehouse as it existed at any point in the past.
Schema Evolution
Add or rename columns without rewriting existing data.
Partitioning & Clustering
The data layout strategy that keeps billion-row queries fast.
Lifecycle Management
Automated policies that age and expire data over time.
How to Consume
Cxos.Foundation.Infrastructure · Both
-- Any Iceberg-compatible engine attaches directly, no CXOS API in the read path: SELECT * FROM curated.identity_stitched_events WHERE event_date >= '2026-07-26'; -- location: abfss://lakehouse@cxosdata.dfs.core.windows.net/curated/events
🧠 Metadata Layer
Central Nervous System
Catalog
Searchable index of every table, schema, and owner.
Lineage
Traces exactly which sources and transforms produced a table.
Data Dictionary
Human-readable definitions for every table and field.
Policies & Entitlements
Metadata-driven rules for who can access what.
How to Consume
Cxos.Foundation.Api · Query
GET /v1/catalog/tables/curated.identity_stitched_events
{ "owner_team": "platform-engineering", "row_count_estimate": 2847193021,
"lineage": ["raw.events"], "last_updated": "2026-08-02T09:00:00Z" }
🔒 Governance & Security
Access Control (RBAC/ABAC)
Enforces who can read or modify data by role and attribute.
Privacy & Consent
Ensures stored data is only used for consented purposes.
Data Classification
Tags every field with a sensitivity level.
Audit Logs
Immutable record of every access and policy decision.
Encryption (At Rest & In Transit)
Keeps data unreadable without proper authorization, always.
How to Consume
Cxos.Foundation.Api · Both
// Policy is checked automatically on every read via the shared policy library —
// not something a caller invokes separately. To inspect a decision:
GET /v1/governance/access-decision?principal=agt_302&resource=curated.customer_profile
{ "decision": "allow", "constraints": { "column_mask": ["email", "phone"] } }
🔌 Platform Connectors
The engine attachments every Iceberg-compatible consumer connects through — no data copy required.
| Connector Package | Consumer |
|---|---|
| Iceberg REST Catalog | Query & Analytics Engine (DataFusion) · ad hoc Spark/Trino |
| Snowflake external tables | Snowflake / BigQuery (Destinations & Activation) |
| Databricks Iceberg connector | Databricks / Redshift (Destinations & Activation) · Predictive Models |
| Azure Purview scanners | Catalog · Lineage · Data Dictionary |
All events are stored in the data lakehouse once, in open formats. You can query raw events from yesterday or aggregated data from last year without moving or duplicating data.