Your data never leaves your cloud. That isn't a setting, it's the architecture.
Most platforms ask you to trust them with your patient data. Polnor is built so the question never comes up: the data stays in your own infrastructure, in your region, on an HDS-certified host, and the control plane is designed never to see it. We call it health-blind.
We orchestrate the work. We never hold the data.
Polnor runs across two planes. The control plane, operated by us, schedules and compiles work. The data plane, your cloud, your compute, your storage, is where everything actually executes. Instructions cross the boundary in one direction. Patient data crosses it in neither.
At Polnor there is nothing to exfiltrate. Your data never leaves your cloud: the control plane orchestrates the processing, but sees and stores no patient data. Our attack surface is not yours, and yours does not extend to us.
Ownership, not custody.
Sovereignty is often reduced to where a copy of the data is stored. We mean something stronger: you keep possession, control and operation of your data at every step.
No data sprawl
No proliferation of copies across third-party tools and vendor infrastructure. One system of record, yours, instead of a trail of exports you can no longer account for.
We never train on your data
Your data trains your models, never ours. There is no shared pool, no silent reuse, no exception buried in the terms. Your clinical advantage stays your clinical advantage.
You own and operate
Not just storage ownership, you run the compute too. Should the relationship ever end, nothing has to be repatriated: the data, the tables and the models are already entirely yours.
Your cloud, your region, an HDS-certified host
Polnor deploys into your own OVHcloud or Scaleway account. The data is created and stored where you choose, within your existing controls, on infrastructure operated by an HDS-certified host. Cloud credentials are encrypted, residency is configurable, and every access to health data is logged.
| resource | location | owner |
|---|---|---|
| object storage | your bucket · EU | you |
| compute | your VPC · EU | you |
| models · endpoints | your cloud | you |
| control plane | orchestration only | Polnor |
A generalist made "health-compatible" still runs on their cloud
Retrofitting a general-purpose platform for healthcare does not change where the data lives. You configure their environment, ingest into their tenancy, and depend on their region and their controls. With Polnor, the platform comes to your cloud, you remain both the owner and the operator of your data.
| generalist | Polnor | |
|---|---|---|
| data location | their cloud | your cloud |
| who runs compute | them | you |
| FHIR → OMOP native | , | yes |
| PHI classification | , | yes |
| exit cost | migration | none |
Built to satisfy the frameworks healthcare answers to.
Sovereignty is the foundation; the controls sit on top of it, ready for audit.
HDS hosting
Deployed with HDS-certified hosts (OVHcloud, Scaleway). Your cloud, your country.
GDPR & PHI access log
PHI classification, a full access log over health data, and retention rules. Audit-ready by default.
EHDS export
Export manifests aligned with the European Health Data Space (EHDS).
The questions your DPO and security team will ask.
Can Polnor access our patient data?+
Where is the data hosted, and in which region?+
Do you train your models on our data?+
What happens if we stop using Polnor?+
What does the control plane retain?+
Prove the boundary for yourself.
In a 30-minute demo we run the full pipeline against your data, in your cloud, and show you exactly what does, and doesn't, cross the line.