Your infrastructure
Runs on your own servers via Docker Compose — inside the same perimeter as your clinical systems. Patient conversations, files and backups stay in your custody, under your keys.
Industries · Healthcare
Health data is a special category under GDPR — and under Türkiye's KVKK — with stricter processing rules than almost anything else an organisation handles. And the stakes are personal: a leaked roadmap embarrasses a company; a leaked diagnosis follows a human being.
Yet care runs on conversation — handovers, case discussions, shared files, questions between shifts. Every third-party SaaS in that pathway adds another processor, another transfer, another agreement to defend. The safest data flow is the one that never happens.
That is the argument for self-hosting: the collaboration layer runs inside your infrastructure, where patient data already lives and where your existing safeguards, contracts and access policies apply. Polybase is designed around GDPR and KVKK principles — and deployed on your servers, we cannot access your data at all.
Three deployment models, one product. For clinical teams the answer is usually self-hosting — patient data simply never leaves your perimeter.
Runs on your own servers via Docker Compose — inside the same perimeter as your clinical systems. Patient conversations, files and backups stay in your custody, under your keys.
Runs inside your cloud account and region with keys in your cloud KMS — for health-tech teams already operating regulated workloads in the cloud.
We operate the platform in EU regions and your data stays in the EU — suitable for administrative and operations teams working away from patient data.
TLS 1.3 protects data in transit in every model. Self-hosted, at-rest encryption runs on your own disks (we recommend LUKS or your KMS) — keys we never hold.
Role-based access enforced at the database layer, channel by channel — a ward, a case team or a study group sees exactly what it should and nothing more.
Protected file fields and signed share tokens keep documents from leaking past the room they belong to — no anonymous public links by accident.
Message edit history is server-side and append-only, so clinical discussions keep an honest trail. A general audit log panel is on the roadmap.
Self-hosted, patient conversations and files live on your servers under your encryption keys. There is no Polybase-side copy and no path for us to reach them.
Bring your own model keys — including self-hosted models via Ollama or LocalAI — so assistant queries never have to leave your network. Your content is not used to train foundation models.
We don't make a HIPAA-compliance claim. What we offer is architectural: self-hosting keeps patient data inside your infrastructure, where your existing controls, agreements and review processes apply. We answer the architecture questions in your assessment directly.
Self-hosted: on your servers, full stop. The database, uploaded files and backups all stay on infrastructure you operate — Polybase runs where you install it and we hold no copy and no keys.
Yes. Access is role-based and enforced per channel at the database layer, guests are scoped to the channel they're invited to, and protected file fields with signed share tokens keep documents inside the room.
Only what the asking user can already see — the assistant respects the same permissions as a human teammate. You bring your own model keys, including fully self-hosted models, so queries can stay inside your network; your content is not used to train foundation models.
We'll walk through a self-hosted deployment for your environment — network, storage, access roles and backup routine — and answer your security review's questions directly.
Chat, documents, tasks and calls for public institutions — running in your data centre, under your jurisdiction, operated by your own people.
Chat, documents, tasks and calls for banks, insurers and fintechs — with data control you can demonstrate, not just reference in a contract.
Chat, documents, tasks and boards for defense organisations and their suppliers — deployed with Docker Compose on fully isolated infrastructure.
Chat, documents, tasks and calls for engineering and product teams — with GitHub automation, Slack-compatible bot endpoints and a self-hosting path your infra team will respect.
Chat, tasks, docs, whiteboards and calls for creative, digital and marketing agencies — with a clean, permissioned space per client instead of a tool zoo per account.
Chat, task boards, docs and calls for retail and e-commerce operations — campaign rollouts, store channels and shift handovers in one workspace that runs in the browser on any device.
Chat, documents, tasks and calls for insurers and brokers — underwriting, claims and field agents in one workspace, with customer data under your control.
Chat, documents, tasks and calls for law firms and in-house legal teams — organised by matter, walled by need-to-know, and hosted on your own servers.
Chat, documents, tasks and calls for accounting and tax firms — one channel per client, every deadline on one board, and financial data on your own servers.
Chat, tasks, docs and calls for logistics teams — dispatchers, warehouses and drivers coordinating across sites and time zones, in the browser on any device.
Chat, documents, tasks and boards for manufacturers — shift handovers, maintenance queues and supplier threads, self-hosted next to the machines they concern.
Chat, documents, tasks and calendars for schools and universities — a space per course or department, run on infrastructure your institution already operates.