Questions
Straight answers
Grouped by who tends to ask them. If yours is not here, ask us; you will get the same kind of answer.
What it is
What is Lake On Rails, in one sentence?
The data operating model a mid-market business runs on: who owns each dataset, what the rules are, and how you prove it. It is the organisational layer that sits above Microsoft Fabric or AWS, or ahead of choosing either.
Is it a data catalogue?
No. A catalogue discovers what exists, captures lineage and classifies columns; Purview, DataZone, Atlan and the rest do that well. Lake On Rails holds what a catalogue does not: a named accountable owner per dataset, a responsibility matrix, written procedures with approvals, and a measure of whether any of it is happening. If you have a catalogue, keep it. The register can read from it.
Is it a data quality or observability tool?
No. Tools like Great Expectations, dbt tests and the platforms' own monitors check the data. Lake On Rails records who is responsible when a check fails, what the procedure is, and whether it was followed. They are complementary.
Why do you keep saying "operating model" rather than "governance"?
Because governance is the content of what we sell, not the label. To most people running a business your size, "governance" reads as cost and bureaucracy, a thing you do after you have had a problem. What this actually is, day to day, is a short list of decisions — who owns what, what the rules are, how you prove it — and a system that keeps them true. That is an operating model.
What do you mean by "trust tiers"?
Three levels a dataset moves through: as it landed, cleaned and checked, and ready to report from. Each has written criteria and moving up needs an approval. If you know the "medallion" vocabulary, they map onto bronze, silver and gold. We say trust tiers because your finance director has never heard of a medallion and should not have to.
Is it for us?
We don't have a data lake. Is this for us?
Yes, and that is the most common situation. Most of the businesses this was built for run Power BI or similar on their application databases and are weighing Fabric against AWS. The decisions recorded here are about your business, not your cloud; they are true whichever platform you choose, and they are the input that decision needs. More on that.
How big do we need to be?
Roughly 50 to 1,000 people, with somewhere between twenty and a few hundred datasets and reports, and one to five people who touch data. Below that, a spreadsheet is honestly still enough. Above it, you probably have a data team and a governance lead already and would be better served by an enterprise tool. Who it's for, in detail.
Do we need a data governance team?
No. It is built for a business where one person is most of the data team and has this as a tenth of their job. What it does need is that one person carrying roughly half a day a week, and a sponsor who cares. If nobody will carry it, it will not work, and we would rather say so up front.
We already run Purview / Lake Formation. Isn't that enough?
For discovery, lineage, permissions and platform audit, yes, and we add nothing to those rows. Each records at most one contact per asset; neither holds a responsibility matrix, a written procedure with a sign-off, or a score that goes down when ownership lapses. That is the gap. How it compares.
What is the fastest way to find out if it fits?
Read one of the seven procedures. We will send you "Onboarding a new dataset" as a PDF, or show it in the first conversation. If it is wrong for your business you will know inside a minute, and if it is right you will know what the rest of the product is like.
Platforms and data
Does it move or store our data?
No. It never moves, transforms or stores the contents of your data. Where you connect it to a platform it reads technical metadata only: dataset names, schemas, owners and refresh times, from Microsoft Fabric and Purview or from the AWS Glue Data Catalog, on a schedule. You can also run it with no connection at all, on metadata you enter yourself or import from a spreadsheet.
Will you recommend Fabric or AWS?
We will tell you what each is good at and where each will cost you engineering time. We will not put a thumb on the scale, because the point of the product is an operating model that holds whichever way you go. Scorchsoft does build on both if you want the same team for the build.
We are on AWS. Is the product weaker there?
The operating model is identical and the Glue connection reads the same metadata the Fabric one does. Our platform-specific notes are deeper for Fabric today and the AWS content is being expanded. If that matters to your decision, ask, and we will show you exactly where each stands.
Does it work with Databricks, Snowflake or an on-premise warehouse?
The operating model does; the capability map has a "custom platform" option and the register can be populated by import. There is no automated metadata connection for those platforms today. If one of them is your platform, say so in the demo request and we will be straight about what that means.
Can our own tools and AI assistants talk to it?
Yes, on Professional and Enterprise. A versioned REST API and an MCP server expose the register, roles, procedures, work items, courses, workflows and audit trail, so you can connect Microsoft Copilot, ChatGPT, Claude or an agent you have built yourself. The point of it is the typing: an assistant can draft descriptions and classifications for a few hundred datasets against your own register, which is the work that otherwise stalls this in month three. How it works, and what stops it going wrong.
How do you stop an AI assistant making a mess of our register?
Five things, all enforced in the product rather than promised in a policy. It ships switched off, and turning it on is an explicit, audited act by one of your admins. Writes arrive as proposals in a review queue by default, with the assistant's stated reason as the first column and a field-by-field diff — applying them directly is a setting you have to choose. A proposal records what it was based on, so if a person edited the same field in the meantime, approval stops and shows you a three-way diff instead of overwriting them. Every change is snapshotted with its reason, marked on the record as AI-assisted, and revertible to the previous version. And permissions are twelve narrow named scopes with no wildcards and no delete, capped by what the person who issued the credential is allowed to do today.
Do we have to use the AI features?
No. The API and MCP server are optional, off by default, and the product is complete without them — every screen works the same way whether or not anything is connected. They are there because most of our customers will want an assistant doing the documentation drafting at some point, and because an operating model that only a human can update is one more system that goes stale.
What it asks of people
How much of our time does it take?
Whoever runs reporting: two days a week for six weeks, then about half a day a week. Each data owner: ninety minutes up front, then about an hour a month. The sponsor: an hour a month at first, then an hour a quarter. For most businesses your size that is bigger than our invoice, and it is the honest reason these programmes stall.
Our department heads are not technical. Will they use it?
That is who it is designed for. Every decision an owner is asked for — accept ownership, set retention, approve access, sign off a procedure — is takeable in a browser, in a minute, in plain English. They are emailed when they are appointed and when something needs them, rather than expected to come looking.
How long before we see something useful?
The workspace is usable on day one: the register structure, tier criteria, responsibility matrix, procedures, workflows and courses are already in place, and a setup wizard walks you through your organisation, roles and first dataset. The first weeks are spent registering datasets and appointing owners, which is real work about your business rather than configuration. We will not tell you an operating model can be stood up in an afternoon. Configuring software is not agreeing accountability.
What happens when the person who set it up leaves?
That is the point of it. What they knew is in the register, the procedures and the matrix, owned by the business rather than by them. The next person inherits a system and a learning path, not a leaver's inbox.
Security and hosting
For IT and information security. If you need the full questionnaire or a signed document, ask and we will send it.
Is our data encrypted in transit and at rest?
Yes. All traffic is encrypted in transit over TLS 1.2 or later with modern cipher suites. The database is encrypted at rest with the hosting provider's native disk encryption (AES-256). Daily logical backups are encrypted before being written to object storage. Application secrets are held in the hosting platform's secrets store and never committed to source control.
Where is it hosted?
Three ways, agreed in the first conversation. The standard service is hosted by Scorchsoft in a UK or EU region agreed with you, with your organisation's data isolated from every other. Where your policy requires it, we set up a dedicated instance, or deploy it into your own Azure subscription under your identity and network controls, with your IT partner operating it if you prefer. What each means commercially.
Are you SOC 2 or ISO 27001 certified?
Not yet, and we are honest about that. A SOC 2 Type I audit is planned, with ISO 27001 work to follow. Today we operate under OWASP-aligned engineering practice, run internal security reviews against the codebase, and publish a responsible-disclosure policy. A security review summary and a gap-to-SOC-2 analysis are available on request for serious evaluations.
Do you support single sign-on?
Yes, on the Enterprise plan, against your own identity provider: Microsoft Entra ID, Okta, Google Workspace and other OAuth or SAML providers. The internal login remains available as a fallback. Because SSO is configured against your provider, Enterprise is set up with our team rather than self-served.
Who at Scorchsoft can see our data?
Access to production is restricted to a small number of named platform engineers whose credentials are scoped, logged and rotated. Support access to a specific customer's tenant needs either your explicit request or an approved incident-response action, and the access is recorded in the application's audit trail. We do not mine customer metadata for analytics. Sub-processor details are in the data-processing addendum, available on request.
What is your backup and incident posture?
Continuous write-ahead-log archiving plus daily logical dumps, a one-hour recovery point objective and a four-hour recovery time objective, with quarterly restore drills. Backups are kept for thirty days rolling with a twelve-month monthly retention for audit. A documented incident-response runbook with severity definitions and communication commitments (a P1 acknowledged within fifteen minutes) exists and is shareable under NDA, along with the drill log.
Can the audit trail be altered?
The application has no edit or delete path for it: every change writes a new event and nothing is overwritten. A database administrator with direct access could still alter the underlying table; that is true of every audit log you already rely on, including your ERP's. What we do about it is restrict direct database access and sign the exports. We would rather you knew that now than found it later.
Does this website track us?
No. It sets no cookies, runs no analytics and loads nothing from a third party. The forms email us what you type and nothing more. The privacy policy is short because there is little to say.
Buying
What does it cost?
Foundations at £8,000 a year, Professional at £18,000 a year, Enterprise at £30,000 a year, excluding VAT, each a 12-month commitment. Foundations and Professional can be paid monthly instead — £780 and £1,750 a month, which is £9,360 and £21,000 over the year. Enterprise is annual only. Consulting is priced separately and is optional. Pricing in full, including a worked first-year example.
Is there a free trial?
There is no free tier and no self-service checkout. A pre-populated trial workspace on Foundations or Professional can be arranged after the first conversation. The first conversation itself is free.
Do we have to use your consultants?
No. The product is complete on its own and does not assume it. Scorchsoft offers a discovery and a six-week implementation for businesses that would rather have it stood up with them, priced on the pricing page.
What happens to our data if we leave?
The register, procedures, matrix and audit trail export in open formats, and the output of any consulting engagement is yours regardless. You do not have to stay a customer to keep what you built.
Can we buy it through the Azure Marketplace?
A listing is planned so you can find and enquire there. Whether a purchase can go through the Marketplace, and whether it can count against an Azure commitment, depend on Microsoft's rules for the offer type, so we will confirm that for your case rather than promise it here. Today we invoice directly.
Do you have customer references?
Not yet. Lake On Rails is new and we have no customer references for it yet, so you would be early. What that buys you — direct access to the people building it, and a say in what comes next — and what it costs you is a conversation for the first meeting, not month four.
Who is behind it?
Scorchsoft, a software and data engineering company in Birmingham, UK, founded in 2010. We built it because every data platform we delivered ended with the same unanswered question: who owns this?
If you are a partner
For MSPs, Fabric and Power BI consultancies and data advisers considering delivering this alongside your own work. The partner programme in full.
Will you end up taking our account?
Not unless you ask us to, and either way it is written into the partner terms rather than implied. The default is that you remain the commercial lead: we register the account to you, we do not contact your customer without you, and we do not pitch development work to them unsolicited. When the operating model surfaces something that needs building, you qualify it and lead or join the proposal. If you would rather we never speak to the customer directly, say so and we will put that in writing too. And if you would rather hand the relationship over entirely — some firms want the introduction to be the end of their involvement — we will contract with the customer directly on a referral fee. Both models, side by side.
You do software development. We do managed services. Where is the line?
Our centre of gravity is the product and bespoke engineering; yours is operating the estate. Tenancy, identity, network, cyber assurance, Fabric capacity, Purview guardrails, the service desk and anything watched at three in the morning are yours. Lake On Rails itself, bespoke applications, APIs, product-owned ingestion and AI embedded in software are ours. Where a piece of work spans both — a security boundary around a workspace, a platform-to-product handover — we scope it jointly and still name one accountable owner rather than pretending there is no overlap. The boundary in full.
Do you need admin access to our customer's tenant?
No. The standard service is hosted by us and reads technical metadata only — dataset names, schemas, owners, refresh times — through a connection your customer authorises and you can scope. Where it runs in the customer's own Azure subscription, you can operate it: we agree in writing who patches, backs up, monitors and responds, and it can be entirely you. Our own people's logins are flagged as ours, do not consume the customer's seats, and appear in the same audit trail as everyone else.
We already sell governance consulting. Does this compete with it?
It is usually the opposite: the product is what your consulting leaves behind. Most governance engagements end with a framework in a document, and the value evaporates over the year that follows because nothing prompts anyone and nothing measures whether it is being followed. Delivering the same thinking into a system that chases owners, records approvals and produces a score gives you a reason to still be in the account next quarter. Where our model and your judgement disagree about a particular customer, take your answer and record it in the product — none of it is locked.
Does it undercut the Purview or Fabric work we sell?
No. It adds nothing to the rows the platform already covers, and it is explicit about that: the capability map shows, per platform, what the cloud covers natively and what still needs a human decision recorded. In practice it scopes platform work rather than replacing it — an owner who cannot be named is usually a conversation about access controls, and a dataset nobody trusts is usually a pipeline job.
Who supports the customer, and who do they call?
Agreed per partnership, in writing, before the first customer goes live. Most partners want first line and to keep the relationship; we take product defects and anything that needs a change to the software. What we will not do is leave it ambiguous — one boundary, one price basis, one documented handover per service, so the customer never has two suppliers each assuming the other has it.
What if our customer wants to buy directly from you?
They can ask, and we will tell you. If you introduced them, the account stays registered to you and the referral or reseller position stands whichever way the paperwork goes; we do not treat a direct enquiry as a way out of that. We would rather lose one sale than have a partner conclude we are a risk to their accounts.
Can we white-label it?
Not today. White-labelling and annual partner fees are deferred until repeated use justifies them, and we would rather say that than sell you a roadmap. What exists now is a cross-customer partner view, a populated instance per customer, and the ten-signs scorecard offered under your name as a conversation-starter with past clients.
Still reading
The plain-English library
Thirteen guides on the things this product is made of — ownership, RACI, trust tiers, retention, lineage, UK GDPR, maturity — and a glossary of forty-six terms, each defined in a sentence you could read to a department head. No sign-up, no gate, no email address.
The first step costs you nothing
Forty-five minutes with whoever runs your reporting
We tell you honestly whether this is worth doing at all, and roughly what it would take. If the answer is not yet, you will hear that. "Not for us" is a fine outcome, and a better one than a slow maybe.