Your own VPC
Runs inside your cloud account and region using our Docker images. Encryption keys sit in your cloud KMS, network and access are yours, and the data never leaves your perimeter.
Industries · Financial services
Financial supervisors across the EU, the UK and Türkiye increasingly treat collaboration software as outsourcing. The questions in a review are concrete: where does the data live, who can access it, how do you monitor the arrangement — and how would you exit it? With a SaaS-only suite, every one of those answers depends on the vendor's goodwill.
That's the structural weakness of renting your workspace: data location fixed by the provider, administrative access held by the provider, exit reduced to export tickets and migration projects. The arrangement may be contractually tidy and still architecturally out of your hands.
Polybase inverts the model. Run it inside your own VPC or on your own servers: data sits in your account and region, access is enforced at the database layer under your control, and backups are portable files you can restore anywhere our images run. Answering the audit becomes a matter of describing your own infrastructure.
Three deployment models, one product. Most financial teams start in their own VPC — full data control with familiar cloud operations — and the strictest mandates go self-hosted.
Runs inside your cloud account and region using our Docker images. Encryption keys sit in your cloud KMS, network and access are yours, and the data never leaves your perimeter.
Runs in your own data centre — online or fully air-gapped. You own the data, the keys and the operational story end to end; Polybase cannot access any of it.
We operate the platform in EU regions and your data stays in the EU — a fast start for teams outside the strictest supervisory perimeter.
TLS 1.3 protects data in transit in every model. In your VPC and self-hosted, encryption at rest runs on your KMS or disk encryption — keys we never see.
Role-based access from a fixed permission catalog, enforced in database collection rules and checked for drift in CI. Deal rooms and counterparty channels stay exactly as closed as you set them.
Message edit history is server-side and append-only — the record of a discussion cannot be silently altered. A general audit log panel is on the roadmap.
Portable, SQLite-based database backups restore on any infrastructure running our images; files live on your volumes. Your exit strategy is a restore drill, not a negotiation.
In your VPC, at-rest encryption runs on your cloud KMS; self-hosted, on your own disk encryption. Either way, the keys never pass through us.
API access uses per-channel keys with fail-closed scopes — an integration can only reach the channel it was issued for, and nothing else by default.
Deployed in your VPC or self-hosted, Polybase is software you operate rather than a service you depend on — data location, access and exit stay under your control, which is what outsourcing frameworks ultimately probe. We support your due diligence with architecture documentation and answers to security questionnaires.
Not certified yet — SOC 2 and ISO 27001 are on our roadmap. We answer security questionnaires and architecture questions today, and self-deployment means your existing infrastructure controls keep applying to the workspace.
Message edit history is kept server-side and append-only. Access roles come from a fixed permission catalog enforced in database rules, so entitlements are reviewable as configuration. A general audit log panel is on the roadmap.
Yes, and you can rehearse it: database backups are portable SQLite files, uploaded files live on your volumes, and both restore on any infrastructure running our Docker images.
We'll map Polybase against your outsourcing and data-control requirements — deployment model, key custody, access model and exit plan — in one working session.
Chat, documents, tasks and calls for public institutions — running in your data centre, under your jurisdiction, operated by your own people.
Chat, documents, tasks and calls for clinics, hospitals and health-tech teams — self-hosted, so conversations about care stay inside your infrastructure.
Chat, documents, tasks and boards for defense organisations and their suppliers — deployed with Docker Compose on fully isolated infrastructure.
Chat, documents, tasks and calls for engineering and product teams — with GitHub automation, Slack-compatible bot endpoints and a self-hosting path your infra team will respect.
Chat, tasks, docs, whiteboards and calls for creative, digital and marketing agencies — with a clean, permissioned space per client instead of a tool zoo per account.
Chat, task boards, docs and calls for retail and e-commerce operations — campaign rollouts, store channels and shift handovers in one workspace that runs in the browser on any device.
Chat, documents, tasks and calls for insurers and brokers — underwriting, claims and field agents in one workspace, with customer data under your control.
Chat, documents, tasks and calls for law firms and in-house legal teams — organised by matter, walled by need-to-know, and hosted on your own servers.
Chat, documents, tasks and calls for accounting and tax firms — one channel per client, every deadline on one board, and financial data on your own servers.
Chat, tasks, docs and calls for logistics teams — dispatchers, warehouses and drivers coordinating across sites and time zones, in the browser on any device.
Chat, documents, tasks and boards for manufacturers — shift handovers, maintenance queues and supplier threads, self-hosted next to the machines they concern.
Chat, documents, tasks and calendars for schools and universities — a space per course or department, run on infrastructure your institution already operates.