Services · Invinite's sovereign data platform

Sovereign data platform

Your data, your environment, your decisions.

Invinite's sovereign data platform gives you control over your data and how it is processed. The platform can be built in your own data centre, in a private cloud, in a public cloud or in a combination of these. Raw data can stay where you want it to be, and the platform's architecture does not tie you to a single cloud or technology supplier.

Why we built our own platform

Building a data platform also means making long-term decisions about where data lives, who can process it and which technologies can be used with it.

In many organisations these decisions are in practice tied to the chosen cloud or platform supplier. If prices, terms of use or needs change later, changing course can be difficult.

For health data, security and security of supply, that is not enough. An organisation must be able to decide for itself where data is processed and with which technologies. That is why we built a platform in which this control stays with the customer, even when technologies or suppliers change.

What sovereign means to us

You decide where the data is

The platform can be built in your own data centre, in a private cloud, in a public cloud or in a combination of these. The architecture does not have to be rebuilt from scratch if the environment changes.

Raw data can stay in your own environment

Sensitive data can be processed where you want to keep it. Only what a given purpose requires, such as pseudonymised data, needs to go to the public cloud. That way you can use the cloud's computing power without moving all your data there.

The platform can also work without external connections

A critical part of the platform can be built in an air-gapped environment. That keeps important data and data production available even when external cloud services cannot be relied on.

Data is stored in open formats

The platform uses established open source technologies and open data formats such as Apache Parquet and Delta Lake. Computation can use Apache Spark, Polars and DuckDB, for example, depending on the need.

Technologies can be replaced

The platform is modular. A single technology can be replaced with another without rebuilding the whole data platform and data production.

The implementation stays with you

Infrastructure definitions, configurations and data production code are under the customer's control and versioned. Development can be continued by your own organisation, by Invinite or by another partner.

What this makes possible

Keep your most sensitive data in your own environment

You do not need to move all your data to the public cloud to use modern analytics and AI services.

Use the cloud where it helps

Cloud computing capacity and services can be used for selected use cases without building the whole data platform on them.

Change technology without starting over

Open formats and a modular architecture reduce dependency on any single technology.

Prepare for disruptions

A critical part of data production can run in an environment that does not depend on the availability of an external cloud service.

Keep the option to put it out to tender

The data, infrastructure definitions and data production code stay with the customer. Changing partner or technology does not mean rebuilding everything.

Complements Databricks and Snowflake – does not replace them

Databricks and Snowflake offer extensive tools for data processing, analytics and AI in the public cloud. Many of our customers already use them.

Invinite's sovereign data platform does not require giving them up. It adds a customer-controlled environment alongside them, where raw data, for example, can be received, processed and prepared before cloud services are used.

SnowflakeDatabricksInvinite's sovereign data platform
RoleManaged data and analytics serviceManaged data, analytics and AI platformCustomer-controlled data platform
EnvironmentPublic cloudPublic cloudOwn data centre, private cloud, public cloud or hybrid
Air-gapped deploymentNot typicallyNot typicallyPossible
Storage formatProprietary format, also supports open Apache IcebergOpen Delta LakeOpen Parquet and Delta Lake
Strongest atManaged data warehouse and analytics in the cloudAnalytics, data science and AI in the cloudRaw data in your own hands and hybrid cloud

Together they work like this: raw data is processed and pseudonymised in the sovereign data platform in your own environment. Pseudonymised data goes to Databricks or Snowflake for analytics and AI. Open formats make it easier to move data between platforms. You get the cloud's computing power and keep control of your raw data.

From our work with customers

3 studies

A hybrid cloud strategy is worked out before it is built

We have carried out three studies: two for wellbeing services counties and one for a national-level organisation. They examined what kind of solution model and approach would enable a hybrid cloud strategy that improves data protection and makes the use of cloud resources more cost-effective.

Ask how a study is done

Data protection is built into the structure

The platform's structure limits where personal data is processed and who can access it. Access control, logs and data protection controls run through the whole platform. That way data protection can be demonstrated rather than merely promised.

The platform is designed for environments where health data and other critical information are processed under strict data protection and information security requirements. Its architecture supports implementing and demonstrating requirements under, for example, GDPR, the Finnish Act on the Secondary Use of Health and Social Data, EHDS and NIS2.

A technical platform alone does not, however, make an organisation compliant, nor does it replace the organisation's own data protection and information security work or, for example, the secure operating environment that the Secondary Use Act requires where one is needed.

The platform and Data as Software together

The platform determines where data is and who controls it. Data as Software determines how data is produced: version-controlled, tested and taken into production in a controlled way. Together they make data production both sovereign and reliable.

Who it is for

Wellbeing services counties, hospitals and national health and social care organisations whose health data requires controlled processing. The same principles suit the security and defence sector and critical industry, where control over data is part of security of supply.

Technical choices

Architecture

A lakehouse architecture that is symmetrical across your own data centre, a private cloud and a public cloud.

Components

Storage in open formats (Parquet, Delta Lake). Apache Spark, Polars and DuckDB as compute engines depending on the use case. All components are established open source projects.

Production readiness

Before the platform goes into critical use, we make sure of ten things:

  1. identity and access management
  2. traceability and logs: who did what and when
  3. data protection controls
  4. separate environments for development, testing and production
  5. controlled releases and the ability to roll back to the previous version
  6. monitoring and alerts
  7. recovery plans
  8. automated enforcement of usage rules
  9. maintainable ways to ingest and transform data
  10. connecting new data sources in the same way every time

Tools. Infrastructure is described as code. Changes go through Git version control and automated testing and deployment (CI/CD). Every change that goes into production is reviewed and approved by an architect.

How the platform is put into use

We start with a definition: what data goes onto the platform, in what environment and with what requirements. After that the platform is built and put into use as a project, and our team can continue developing it with you. If a procurement is ahead, the definition also produces the procurement requirements.

Related pages: Data as Software · Health and social care situation centres and preparedness · Health data: standards and regulation