Our EU cloud
Runs in EU regions. Your data stays in the EU and we operate the platform for you — no servers for your team to manage.
Security
Most teams assume that if their tools store data “in the EU”, their data is safe under EU law. For US-owned providers, that assumption is wrong.
The US CLOUD Act (2018) gives American authorities the power to compel any US-based company to hand over data it controls — regardless of where in the world that data is physically stored. A US provider's Frankfurt data center doesn't change who can be served the warrant.
This is why Slack, Microsoft Teams, Zoom, Google Workspace and Jira — all US-owned — sit in legal tension with GDPR for sensitive data. European data protection authorities have repeatedly flagged transatlantic transfer as a compliance risk, and the EU has announced work on new cloud rules — a proposed Cloud and AI Development Act — that would weigh provider jurisdiction for sensitive workloads.
The only durable fix is architectural. If a provider physically cannot access your data or your keys, there is nothing for any court — European or foreign — to compel. That's the model Polybase is built on.
Choose the data-residency reality your compliance posture needs — and move between models later without rebuilding.
Runs in EU regions. Your data stays in the EU and we operate the platform for you — no servers for your team to manage.
Runs inside your cloud account and region using our Docker images. You control the network, storage and access.
Runs on your own servers — online or fully air-gapped. You own the data and the encryption keys, end to end.
With self-host, we never hold your keys — so there is nothing for us, or any court, to hand over.
| Deployment | Where it runs | Who holds the keys | Who can access data | Encryption at rest |
|---|---|---|---|---|
| EU Cloud | EU regions, operated by Polybase | Polybase-managed | Polybase operators, to run the service | Provider-managed disk encryption |
| Private Cloud (VPC) | Your cloud account & region | You — your cloud KMS | Only your team | Your cloud KMS / volume encryption |
| Self-hosted / air-gap | Your own infrastructure | You — exclusively | Only you. Polybase cannot. | Your disk encryption (LUKS) / KMS |
Security is not a layer we bolted on — it is the ground every query, connection, and user walks over. Polybase is built on strong cryptography, granular access rules, and a full self-host option so the most sensitive teams can trust it. Run our cloud or your own infrastructure — control stays with you.
Six core principles — every user and every bit flows through them.
TLS 1.3 encrypted communication in transit. For sensitive at-rest data we recommend disk-level encryption (LUKS / cloud KMS).
Run Polybase on your own cloud or on-prem. A single Go binary, zero vendor lock-in.
Every collection and field is protected by API rules that evaluate user roles and team memberships.
Portable, SQLite-based database backups you can move anywhere. Uploaded files live on your storage volume and are covered by your standard volume snapshots.
Message edits are recorded server-side as an append-only history. A general audit log panel is on the roadmap.
With self-host you decide where your data lives. Compliance with local data residency laws stays fully in your hands.
Every request passes four checkpoints: edge, identity, application, and data. A failure in one component never exposes the entire system — the layers reinforce each other.
To make this auditable, the full rule engine is exposed — your auditors can inspect the policies directly inside Polybase.
Reverse proxy and rate-limiting filter every request. WAF integration is on the roadmap.
Standard email/password and API token authentication. Enterprise SSO/SAML/SCIM/2FA on the roadmap, on request.
Role- and team-based API rules are evaluated on every read.
Row-level policy on PocketBase; regular backups; optional disk-level encryption.
We focus on principles over certifications: data minimization, explicit access rules, and full data control via self-host.
Designed around EU data protection principles; full data control with self-host.
Run on your own infrastructure with a single command; your data stays on your servers.
PocketBase API rules are open and auditable; your team can inspect every access policy directly.
Not certified yet — SOC 2 and ISO 27001 are on our roadmap. We answer security questionnaires and architecture questions today.
Deploy Polybase with Docker Compose on isolated infrastructure — no outbound connection required, no telemetry, no dependency on us. It runs fully offline; for video calls you pair it with a self-hosted Jitsi stack inside the same network. You manage backups and access; your data and keys never leave the network. It's the deployment that government, defense, and regulated finance and healthcare ask for — and that almost no all-in-one collaboration suite credibly offers.
Your data, on your servers
We answer your questions about architecture, deployment and security. You can request a tailored review for your team.