Grid documentation and route plans
Where each line runs is information about critical infrastructure. It has no place in a data center outside your control.
LOKI runs entirely inside your network: read-only connectors, no write permissions on the control systems. It opens up grid documentation, operations logs (Betriebstagebücher) and regulatory files in response to one question. Every answer names its source.
Burst pipe on Gartenstraße. What’s down there, and what do I need to watch out for?
Last excavated in 2009: drinking water DN 150 at a depth of 1.40 m, with a bundle of empty conduits alongside [1]. The construction log names the civil-works contractor and the compaction report [2]. And a note from 2011 records that the shut-off valve sits ahead of the branch, deviating from the plan [3].
Another UTILMD rejected, same APERAK error. Didn’t we have this back in March already?
The case matches the rejection from 12 March: identical APERAK error code [1]. The clarification note describes the fix: the mandatory field for the market location was still filled in the old format [2]. The market partner confirmed the correction within two working days back then [3].
Cost review, base year 2023. What evidence do we have for that line item?
The item comes from the 2023 financial statements; account and posting text are on file [1]. The auditor’s report confirms the allocation [2]. In the previous period the authority raised a query about it, and the answer given then is in the correspondence [3].
From family-run businesses to DAX corporations. Machine building, chemicals, and the public sector.
You operate critical infrastructure and manage citizens’ data.
Where each line runs is information about critical infrastructure. It has no place in a data center outside your control.
Personal data of citizens of the same municipality. At a municipally owned company, every data-protection incident becomes an item in the city council.
Informational unbundling under Section 6a of the German Energy Industry Act (EnWG) requires that commercially sensitive grid data does not flow into the retail business. A company-wide cloud index is structurally incompatible with that.
86 percent of municipal utilities rate the influence of regulatory requirements as somewhat to very negative; the frequency of changes during ongoing operations draws explicit criticism. At the same time, around 25 percent of the industry’s positions will need to be refilled over the next ten years, at an average age above 45.
Unbundled activity accounts under Section 6b of the EnWG. Data-collection forms for the cost review under ARegV, base year three years before the period starts. The annual EEG report with auditor’s attestation, due 31 May. The annual surveillance audit for the ISMS under ISO 27001 and 27019. The TSM assessment. And risk management under the German Drinking Water Ordinance (TrinkwV), which the public-health office checks for completeness.
GPKE deadlines of three to six working days, UTILMD discrepancies, APERAK errors, clarification-case lists. With MaKo 2026 the mandatory-field definitions have become stricter, and the migration from file-based EDIFACT to synchronous API web services has begun.
Construction crews have historically worked with paper plans and PDFs; as-built returns are re-entered by hand. Cable-location enquiries arrive partly on paper, partly as PDF attachments, partly through the portal. And under Redispatch 2.0, some grid operators transmit digitally, others by post or fax.
The knowledge is in the building. It is just scattered across Smallworld, Lovion, SAP, Schleupen, BelVis, operations logs, supervisory-board papers and thirty years of inboxes.
Your knowledge lives in four worlds that don’t know each other: GIS as-built plans, ERP records, operations logs and three decades of inboxes. LOKI lays one search across all four, with tenant separation and role-based access, so your unbundling boundary stays reflected in the permission model.
GIS as-built plan, ERP record, operations log, mail thread.
LOKI opens up all four, read-only, following your role-based access.
No system knowledge, no file names, no folder hunting.
Every statement carries the source it came from.
One question. Four systems. One answer that tells you where it knows it from.
Tuesday, 3:20 a.m. A water pipe bursts in a street last worked on in 2009. The on-call crew asks from the tablet.
Burst pipe on Gartenstraße. What’s down there, and what do I need to watch out for?
Last excavated in 2009: drinking water DN 150 at a depth of 1.40 m, with a bundle of empty conduits alongside [1]. The construction log names the civil-works contractor and the compaction report [2]. And a note from 2011 records that the shut-off valve sits ahead of the branch, deviating from the plan [3].
The information that used to sit in a colleague’s head is available at 3:20 a.m.
Your team wants to work with the best models, and does so anyway, if need be around the official toolbox. LOKI turns that into an official path: you connect external models, and every request passes through a check first. Names, order numbers, part identifiers and amounts are detected and redacted before the prompt leaves the building.
Write me a reply to K. Weber[NAME], Gartenstraße 12[ADDRESS]. He’s asking why the monthly installment for meter 4711-BN[METER NUMBER] has gone up.
Protokoll09:12 · S. Brandt · Claude Opus 4.8 · 3 findings redacted · sent
Name recognition and configurable patterns find what must not go out.
The user sees in the chat what was found and chooses: send anonymized, send unchanged, or cancel.
Every call is in the log, with user, model, time and the result of the check. Including the cancelled ones.
And this is what the switch looks like in the product: choose a cloud model and it tells you right above the input field.
That’s the difference between a ban that gets bypassed and a path you’re allowed to take.
We don’t have to vouch for the architecture ourselves. The conference of Germany’s data-protection authorities (DSK) described it before we built it.
The DSK’s guidance on AI and data protection states that technically closed systems are preferable from a data-protection perspective: in open systems, the input data leaves the users’ protected environment. With LOKI it doesn’t.
Inside a language model itself there is no way to control who may see which information; the supervisory authorities state this explicitly. In the knowledge system in front of it, tenant separation and role-based access do work. That’s why LOKI is built this way. And that’s why individual entries can be deleted deliberately instead of disappearing into a model.
Germany’s Federal Office for Information Security (BSI) warns about agentic systems in which language models are coupled with external tools, and we share that concern: LOKI reads and generates documents, it does not switch anything. No write permissions in SCADA, control systems or grid operations; a human confirms sensitive actions; every tool call is logged. For your approval process we deliver a data-flow diagram, a permission model, a classification under the EU AI Act and the building blocks for the data-protection impact assessment. And your ISMS under Section 11(1a) of the EnWG can still document the system, because it runs within your area of responsibility.
The regulators call this a mitigating measure, not a blanket solution, and name open questions around transparency and data-subject rights. We put it exactly the same way.
Access is read-only. You decide which sources are visible to which role; we don’t.
No access to control systems, SCADA or grid operations. These systems are deliberately kept off the list.
A supplier switch gets rejected via APERAK, and the GPKE deadline is running. LOKI finds the comparable case from the spring, the internal clarification note, the email exchange with the market partner, and the pointer to which mandatory field has to be filled differently since MaKo 2026.
Clarification cases get solved once and then reused.
The data-collection form for the cost review demands documentation from the base year, three years in the past. LOKI delivers the line items from the financial statements of that year, the auditor’s report, the internal rationale for the allocation and the correspondence with the authority from the previous period.
Preparation starts from last time instead of from zero.
Four decades of faults, conversions and workarounds, documented in records, emails and operations logs. The successor asks why a substation is wired the way it is. LOKI finds the conversion note from 2011, the fault history and the peculiarity that led to switching errors three times.
Experience becomes retrievable without anyone having to write it down first.
Likewise: preparing concession proceedings from the files of twenty years ago · documenting TrinkwV risk management across the supply chain · heat planning under the German Heat Planning Act (WPG): data collection and inventory analysis · answering council and citizen enquiries · preparing supervisory-board papers from previous years’ files · preparing the ISO 27001 surveillance audit
With our locally installed AI assistant from IGNAITE, our employees can access company knowledge much faster. For example, information from past projects. This enables higher productivity and, above all, more comprehensive knowledge sharing.
In our collaboration with IGNAITE, we built a practical, high-performance computer-vision solution that has sustainably improved our incoming-materials processes. What particularly convinced us was the structured approach, the deep process understanding, and the ability to translate complex requirements into pragmatic solutions.
LOKI opens up what was written down. But much of what happens at your assets never makes it into a document: temperatures, runtimes, switching cycles, load profiles. MINERVA captures them, with its own boards in your network and without touching the control systems, and turns them into sources LOKI can cite.
Extendable with MINERVABoth products follow the same principles: sovereign, source-based, local. You start with one and add the other when you need it.
Compliance first, technology after — in that order, because your approval is the critical path.
30 minutes. We bring the documents your review process needs.
Data-flow diagram, unbundling boundary, classification under the EU AI Act, before any hardware is ordered.
One clearly bounded area with a clean permission boundary instead of a big bang across all divisions. Expansion once the pilot has convinced you.
Through tenant separation and role-based access: LOKI shows only sources the person asking is authorized to see. The permission model mirrors your unbundling requirements and is set up together with your compliance team before the rollout.
No. That is an architecture decision rather than a configuration someone could accidentally change. LOKI receives no write permissions on OT systems.
Yes. We deliver a data-flow diagram, a description of the processing chain, the permission model, a classification under the EU AI Act and the building blocks for your data-protection impact assessment. In our experience, this is the point where cloud providers have to refer you to their own vendor documentation.
Think of it as a different layer instead of a second system. Editorial systems live on skilled staff writing guides, which costs the time of the same skilled staff who are already scarce. LOKI opens up what has already been written: records, reports, emails, as-built documents. Without editorial effort and without an approval process before the first answer.
A fixed monthly price plus a one-time setup fee that includes the server hardware. The license covers unlimited users. There are three packages that differ in hardware sizing. Operation, maintenance, updates and support are included. We’ll give you the specific price in the intro call.
Going live typically takes under four weeks. Extending to further divisions depends on the number of source systems. We tell you up front which ones are unproblematic and which are not.
The industry pages show LOKI in the everyday work of individual industries. If yours is missing, that only means we haven’t written it up yet.
30 minutes, and feel free to bring your IT security along right away. We’re based in Hoppstädten-Weiersbach on the Nahe, and we come to your site.