Digital Unity technology · Hexjack Lens

See the bigger picture. Get to the right answer.

Hexjack Lens is a Secure-by-Design, read-oriented MCP server that gives AI systems controlled, evidence-backed access to an organisation's information estate.

Controlled research

Information access, investigation and operations share one bounded security model.

Lens provides a 21-tool read-only MCP contract including research.investigate, with destination-bound source access, evidence provenance, runtime credential isolation and safe operational controls. Operational audit is metadata-only, runtime work is bounded, optional repository caches have an explicit retention model, and credentials rotate outside the application artifact. Cross-cutting security checks tie the public tool boundary, destination controls, secret safety, hostile-content handling, traversal protection and hardened runtime assumptions to executable evidence. Official releases carry immutable artifact identity, SBOMs, signatures and provenance, with verification paths for connected, restricted-network and native deployments. Lens remains standalone, with no Hexjack Agent Control dependency.

The information estate

Your organisation already knows more than any single AI can see.

Useful knowledge is distributed across documentation, issue trackers, source repositories, operational systems and other approved sources. Lens provides a controlled research layer between AI and that information.

Instead of teaching every AI client how every underlying system works, organisations configure their information topology once behind a bounded interface.

One Lens, bounded capabilities

Search

Lens searches configured organisational systems directly and, where enabled, optional local repository caches without exposing arbitrary destinations.

Retrieve

Lens retrieves bounded source evidence while retaining source identity, context and provenance.

Investigate

The public research.investigate operation delegates bounded questions through the provider-neutral Analysis Engine Contract. The configured provider can be local or remote and may own its own authorised workspace or analysis environment.

Evidence first

Know what was retrieved, what was observed and what was inferred.

Lens is designed to preserve the distinction between recorded organisational evidence, observations established during authorised investigation and conclusions inferred from that evidence. Provenance tells an AI where information came from without turning every retrieved document into a trusted instruction.

Evidence & provenance →

Secure by Design

Security from the first decision.

Trust boundaries, least privilege, credential isolation, untrusted content, operational controls, cross-cutting security verification, software provenance and customer-verifiable release evidence are part of the Lens architecture rather than a hardening exercise at the end.

Secure by Design →

Software assurance →

Explore Lens

How it works

Direct source retrieval, optional local repository caching, common evidence semantics and delegated investigation through the 21-tool read-only MCP surface.

Explore →

Deployment

Immutable software, external configuration and customer-controlled boundaries.

Explore →

Secure by Design

The engineering principles governing how Lens is designed, built and operated.

Explore →