Polnor.
Sovereignty

Your data never leaves your cloud. That isn't a setting, it's the architecture.

Most platforms ask you to trust them with your patient data. Polnor is built so the question never comes up: the data stays in your own infrastructure, in your region, on an HDS-certified host, and the control plane is designed never to see it. We call it health-blind.

Health-blind

We orchestrate the work. We never hold the data.

Polnor runs across two planes. The control plane, operated by us, schedules and compiles work. The data plane, your cloud, your compute, your storage, is where everything actually executes. Instructions cross the boundary in one direction. Patient data crosses it in neither.

Our side · control plane
orchestration · DAGs · scheduling
SQL text · table metadata
access log · task state
no patient data, ever
Your side · data plane
patients · observations (PHI)
lab results · clinical reports
OMOP tables · cohorts · features
trained models · endpoints
$7.42M
average cost of a healthcare data breach. The most expensive sector, 14 years running.

At Polnor there is nothing to exfiltrate. Your data never leaves your cloud: the control plane orchestrates the processing, but sees and stores no patient data. Our attack surface is not yours, and yours does not extend to us.

What sovereignty actually means here

Ownership, not custody.

Sovereignty is often reduced to where a copy of the data is stored. We mean something stronger: you keep possession, control and operation of your data at every step.

No data sprawl

No proliferation of copies across third-party tools and vendor infrastructure. One system of record, yours, instead of a trail of exports you can no longer account for.

We never train on your data

Your data trains your models, never ours. There is no shared pool, no silent reuse, no exception buried in the terms. Your clinical advantage stays your clinical advantage.

You own and operate

Not just storage ownership, you run the compute too. Should the relationship ever end, nothing has to be repatriated: the data, the tables and the models are already entirely yours.

Data residency

Your cloud, your region, an HDS-certified host

Polnor deploys into your own OVHcloud or Scaleway account. The data is created and stored where you choose, within your existing controls, on infrastructure operated by an HDS-certified host. Cloud credentials are encrypted, residency is configurable, and every access to health data is logged.

European hosting on HDS-certified infrastructure
Encrypted credentials, configurable residency, logged access
deployment · your cloudHDS
resourcelocationowner
object storageyour bucket · EUyou
computeyour VPC · EUyou
models · endpointsyour cloudyou
control planeorchestration onlyPolnor
Why not a generalist

A generalist made "health-compatible" still runs on their cloud

Retrofitting a general-purpose platform for healthcare does not change where the data lives. You configure their environment, ingest into their tenancy, and depend on their region and their controls. With Polnor, the platform comes to your cloud, you remain both the owner and the operator of your data.

where does the data live?
generalistPolnor
data locationtheir cloudyour cloud
who runs computethemyou
FHIR → OMOP native, yes
PHI classification, yes
exit costmigrationnone
Compliance

Built to satisfy the frameworks healthcare answers to.

Sovereignty is the foundation; the controls sit on top of it, ready for audit.

HDS hosting

Deployed with HDS-certified hosts (OVHcloud, Scaleway). Your cloud, your country.

GDPR & PHI access log

PHI classification, a full access log over health data, and retention rules. Audit-ready by default.

EHDS export

Export manifests aligned with the European Health Data Space (EHDS).

Sovereignty, in detail

The questions your DPO and security team will ask.

Can Polnor access our patient data?+
No. The architecture is health-blind: the control plane handles orchestration, SQL text and metadata, but the data, and the outputs derived from it, stay in your cloud. There is no path by which patient rows reach our infrastructure, because the work runs on your side of the boundary.
Where is the data hosted, and in which region?+
In your own OVHcloud or Scaleway account, in the region you choose, on infrastructure operated by an HDS-certified host. Residency is configurable and stays within your existing controls; nothing is copied to a Polnor-owned bucket.
Do you train your models on our data?+
Never. Your data trains your models, and only yours. There is no shared training pool and no reuse of customer data, your clinical advantage remains exclusively yours.
What happens if we stop using Polnor?+
Nothing has to be repatriated. Because you own and operate the data plane, your tables, cohorts and trained models already live in your cloud. Ending the relationship removes the orchestration, not your data, there is no exit migration.
What does the control plane retain?+
Orchestration state, job and SQL definitions, table metadata and an access log, the minimum required to schedule and compile work. Derived data, including query outputs, logs and model artifacts, is written back to your storage, not persisted by the control plane.
See it on your own cloud

Prove the boundary for yourself.

In a 30-minute demo we run the full pipeline against your data, in your cloud, and show you exactly what does, and doesn't, cross the line.