Industries

Industries · Public sector

A workspace the state actually owns.

Chat, documents, tasks and calls for public institutions — running in your data centre, under your jurisdiction, operated by your own people.
Best fit
Self-hosted / VPC
Data residency
Your infrastructure
In transit
TLS 1.3
Access control
Role-based (RBAC)
The sovereignty question

Sovereignty is a question of jurisdiction, not geography.

The US CLOUD Act gives American authorities the power to compel any US-based provider to hand over data it controls — regardless of where that data is physically stored. A US suite's data centre in Frankfurt or Ankara doesn't change who can be served the warrant. For a public institution, that means the confidentiality of internal deliberation depends on a foreign legal system.

European data protection authorities have repeatedly flagged transatlantic transfers as a risk, and the EU has announced work on a proposed Cloud and AI Development Act that would weigh provider jurisdiction for sensitive workloads. The direction of travel is clear: public bodies are expected to know — and control — which law their data answers to.

The durable answer is architectural, not contractual. When the workspace runs on infrastructure your institution operates, there is nothing for a foreign court to compel. Polybase is designed around GDPR and KVKK principles and built to be deployed, operated and audited by you.

Deployment

Run it where your mandate requires.

Three deployment models, one product. Most public institutions choose self-hosting — the model where sovereignty is a property of the architecture, not a clause in a contract.

Best fit
Self-hosted

Your infrastructure

Best fit

Runs on your own servers via Docker Compose — online or fully air-gapped. Your institution holds the data, the keys and the audit story end to end. Polybase cannot access any of it.

Private cloud

Your own VPC

Strong alternative

Runs inside your cloud account and region using our Docker images. You control the network, storage, encryption keys and access — with less hardware to operate.

EU cloud

Our EU cloud

For less sensitive teams

We operate the platform in EU regions and your data stays in the EU. A pragmatic starting point for teams whose work doesn't require self-custody.

TLS 1.3 protects data in transit in every model. With self-hosting, we never hold your keys — so there is nothing for us, or any court, to hand over.

Built for institutions

What public-sector IT actually needs.

(01)

Access that follows the org chart

Role-based access with roles drawn from a fixed permission catalog, enforced in database collection rules — auditable, testable, and checked for drift in CI.

(02)

Accountability by default

Message edit history is kept server-side and append-only, so the record of what was said cannot be quietly rewritten. A general audit log panel is on the roadmap.

(03)

Backups you can hold

Portable, SQLite-based database backups you can restore on any infrastructure running our images. Uploaded files live on your volumes and back up with your standard snapshots.

(04)

Your servers, your keys

Self-hosted, the encryption keys are exclusively yours — we recommend disk-level encryption (LUKS or your KMS). Polybase has no path to your data.

(05)

Runs inside your network

No telemetry and no outbound calls required. Polybase runs fully offline; calls use a self-hosted LiveKit server inside the same network.

FAQ

What public institutions ask us.

Yes. Polybase deploys with Docker Compose on isolated infrastructure and runs fully offline — no telemetry, no outbound calls required. Calls use a self-hosted LiveKit server inside the same network.

There is no official GDPR or KVKK certification scheme to hold. Polybase is designed around GDPR and KVKK principles, and — decisively — self-hosting keeps the data on infrastructure your institution controls, under your jurisdiction. For SOC 2 and ISO 27001: not certified yet — both are on our roadmap, and we answer security questionnaires and architecture questions today.

Today sign-in is email/password with magic-link, and the workspace is invite-only with role-based access. SSO/SAML, SCIM provisioning and 2FA are on the roadmap.

Only you. The workspace runs on your servers, the keys are yours, and we operate nothing. There is nothing for Polybase — or any foreign court — to hand over.

Next step

Bring the workspace inside your jurisdiction.

We'll walk through your deployment constraints — network, hardware, identity, audit — and show how a self-hosted Polybase fits them, module by module.

Industries
(02)

Collaboration that stands up in an audit.

Chat, documents, tasks and calls for banks, insurers and fintechs — with data control you can demonstrate, not just reference in a contract.

Read the industry page
(03)

Patient data that never leaves the building.

Chat, documents, tasks and calls for clinics, hospitals and health-tech teams — self-hosted, so conversations about care stay inside your infrastructure.

Read the industry page
(04)

Built for networks that never touch the internet.

Chat, documents, tasks and boards for defense organisations and their suppliers — deployed with Docker Compose on fully isolated infrastructure.

Read the industry page
(05)

ChatOps, docs and tasks — right next to your code.

Chat, documents, tasks and calls for engineering and product teams — with GitHub automation, Slack-compatible bot endpoints and a self-hosting path your infra team will respect.

Read the industry page
(06)

One workspace, every client in its own lane.

Chat, tasks, docs, whiteboards and calls for creative, digital and marketing agencies — with a clean, permissioned space per client instead of a tool zoo per account.

Read the industry page
(07)

One line from HQ to the shop floor.

Chat, task boards, docs and calls for retail and e-commerce operations — campaign rollouts, store channels and shift handovers in one workspace that runs in the browser on any device.

Read the industry page
(08)

Claims data that stays in your custody.

Chat, documents, tasks and calls for insurers and brokers — underwriting, claims and field agents in one workspace, with customer data under your control.

Read the industry page
(09)

Client confidences, kept by architecture.

Chat, documents, tasks and calls for law firms and in-house legal teams — organised by matter, walled by need-to-know, and hosted on your own servers.

Read the industry page
(10)

Your clients' books, in your custody.

Chat, documents, tasks and calls for accounting and tax firms — one channel per client, every deadline on one board, and financial data on your own servers.

Read the industry page
(11)

Every shipment gets one thread — not a phone chain.

Chat, tasks, docs and calls for logistics teams — dispatchers, warehouses and drivers coordinating across sites and time zones, in the browser on any device.

Read the industry page
(12)

Coordination for plants that keep the internet out.

Chat, documents, tasks and boards for manufacturers — shift handovers, maintenance queues and supplier threads, self-hosted next to the machines they concern.

Read the industry page
(13)

A campus workspace your institution owns.

Chat, documents, tasks and calendars for schools and universities — a space per course or department, run on infrastructure your institution already operates.

Read the industry page