Security

Security you can inspect. Deployment you control.

Polybase uses TLS 1.3 in transit, permission controls and deployment options that include our EU cloud, your VPC and your own infrastructure.
Encryption
TLS 1.3
Hosting
Self-host
Keys
Yours
Compliance
GDPR by design
The problem

Why your collaboration data isn't as European as you think.

US CLOUD Act · 2018

Most teams assume that if their tools store data “in the EU”, their data is safe under EU law. For US-owned providers, that assumption is wrong.

The US CLOUD Act (2018) gives American authorities the power to compel any US-based company to hand over data it controls — regardless of where in the world that data is physically stored. A US provider's Frankfurt data center doesn't change who can be served the warrant.

This is why Slack, Microsoft Teams, Zoom, Google Workspace and Jira — all US-owned — sit in legal tension with GDPR for sensitive data. European data protection authorities have repeatedly flagged transatlantic transfer as a compliance risk, and the EU has announced work on new cloud rules — a proposed Cloud and AI Development Act — that would weigh provider jurisdiction for sensitive workloads.

The only durable fix is architectural. If a provider physically cannot access your data or your keys, there is nothing for any court — European or foreign — to compel. That's the model Polybase is built on.

Where your data lives

Three models. You pick the boundary.

Choose the data-residency reality your compliance posture needs — and move between models later without rebuilding.

EU Cloud

Our EU cloud

Runs in EU regions. Your data stays in the EU and we operate the platform for you — no servers for your team to manage.

Data stays in the EU
Private Cloud

Your own VPC

Runs inside your cloud account and region using our Docker images. You control the network, storage and access.

Your cloud account
Self-hosted

Your infrastructure

Runs on your own servers — online or fully air-gapped. You own the data and the encryption keys, end to end.

Your servers, your keys
Key management

Who holds the keys?

With self-host, we never hold your keys — so there is nothing for us, or any court, to hand over.

EU Cloud
Where it runs
EU regions, operated by Polybase
Who holds the keys
Polybase-managed
Who can access data
Polybase operators, to run the service
Encryption at rest
Provider-managed disk encryption
Private Cloud (VPC)
Where it runs
Your cloud account & region
Who holds the keys
You — your cloud KMS
Who can access data
Only your team
Encryption at rest
Your cloud KMS / volume encryption
Self-hosted / air-gap
Where it runs
Your own infrastructure
Who holds the keys
You — exclusively
Who can access data
Only you. Polybase cannot.
Encryption at rest
Your disk encryption (LUKS) / KMS
TLS 1.3 protects data in transit across every model.
Our philosophy

Your data never leaves your control.

Security is not a layer we bolted on — it is the ground every query, connection, and user walks over. Polybase is built on strong cryptography, granular access rules, and a full self-host option so the most sensitive teams can trust it. Run our cloud or your own infrastructure — control stays with you.

The Pledge
  • TLS 1.3 encrypted communication in transit
  • Self-host: full control on your own infrastructure
  • Designed around GDPR principles
Security pillars

Every layer designed for defence.

Six core principles — every user and every bit flows through them.

01

Encryption

TLS 1.3 encrypted communication in transit. For sensitive at-rest data we recommend disk-level encryption (LUKS / cloud KMS).

TLS 1.3
02

Self-host option

Run Polybase on your own cloud or on-prem. A single Go binary, zero vendor lock-in.

Docker
03

Granular access

Every collection and field is protected by API rules that evaluate user roles and team memberships.

Row-level rules
04

Portable backups

Portable, SQLite-based database backups you can move anywhere. Uploaded files live on your storage volume and are covered by your standard volume snapshots.

SQLite-based
05

Message audit trails

Message edits are recorded server-side as an append-only history. A general audit log panel is on the roadmap.

Message history · General audit (Soon)
06

Data sovereignty

With self-host you decide where your data lives. Compliance with local data residency laws stays fully in your hands.

Self-host
Architecture

Layered defence in depth.

Every request passes four checkpoints: edge, identity, application, and data. A failure in one component never exposes the entire system — the layers reinforce each other.

To make this auditable, the full rule engine is exposed — your auditors can inspect the policies directly inside Polybase.

  1. 01Edge

    Edge

    Reverse proxy and rate-limiting filter every request. WAF integration is on the roadmap.

  2. 02Identity

    Identity

    Standard email/password and API token authentication. Enterprise SSO/SAML/SCIM/2FA on the roadmap, on request.

  3. 03Application

    Application

    Role- and team-based API rules are evaluated on every read.

  4. 04Data

    Data

    Row-level policy on PocketBase; regular backups; optional disk-level encryption.

Every layer auditable
Compliance

Privacy by design.

We focus on principles over certifications: data minimization, explicit access rules, and full data control via self-host.

By design
GDPR
By design

Designed around EU data protection principles; full data control with self-host.

Active
Self-host
Docker

Run on your own infrastructure with a single command; your data stays on your servers.

Active
Auditable Rules
API Rules

PocketBase API rules are open and auditable; your team can inspect every access policy directly.

Roadmap
SOC 2 / ISO 27001
Roadmap

Not certified yet — SOC 2 and ISO 27001 are on our roadmap. We answer security questionnaires and architecture questions today.

Air-gapped & offline

Built to run with no internet at all.

Deploy Polybase with Docker Compose on isolated infrastructure — no outbound connection required, no telemetry, no dependency on us. It runs fully offline; for video calls you pair it with a self-hosted Jitsi stack inside the same network. You manage backups and access; your data and keys never leave the network. It's the deployment that government, defense, and regulated finance and healthcare ask for — and that almost no all-in-one collaboration suite credibly offers.

For government · defense · regulated finance & healthcare
  • Docker Compose on fully isolated networks
  • No telemetry, no outbound calls required
  • Video calls via a self-hosted Jitsi stack
  • Full data and encryption-key sovereignty
  • You manage backups, updates and access
Architecture

Full control with self-host

Your data, on your servers

Single Binary
Compiled in Go
Docker
One-command deploy
TLS 1.3
Modern encryption
Talk to our trust team

We take your questions seriously.

We answer your questions about architecture, deployment and security. You can request a tailored review for your team.