Services · Invinite's sovereign data platform
Sovereign data platform
Your data, your environment, your decisions.
Invinite's sovereign data platform gives you control over your data and how it is processed. The platform can be built in your own data centre, in a private cloud, in a public cloud or in a combination of these. Raw data can stay where you want it to be, and the platform's architecture does not tie you to a single cloud or technology supplier.
Why we built our own platform
Building a data platform also means making long-term decisions about where data lives, who can process it and which technologies can be used with it.
In many organisations these decisions are in practice tied to the chosen cloud or platform supplier. If prices, terms of use or needs change later, changing course can be difficult.
For health data, security and security of supply, that is not enough. An organisation must be able to decide for itself where data is processed and with which technologies. That is why we built a platform in which this control stays with the customer, even when technologies or suppliers change.
What sovereign means to us
You decide where the data is
The platform can be built in your own data centre, in a private cloud, in a public cloud or in a combination of these. The architecture does not have to be rebuilt from scratch if the environment changes.
Raw data can stay in your own environment
Sensitive data can be processed where you want to keep it. Only what a given purpose requires, such as pseudonymised data, needs to go to the public cloud. That way you can use the cloud's computing power without moving all your data there.
The platform can also work without external connections
A critical part of the platform can be built in an air-gapped environment. That keeps important data and data production available even when external cloud services cannot be relied on.
Data is stored in open formats
The platform uses established open source technologies and open data formats such as Apache Parquet and Delta Lake. Computation can use Apache Spark, Polars and DuckDB, for example, depending on the need.
Technologies can be replaced
The platform is modular. A single technology can be replaced with another without rebuilding the whole data platform and data production.
The implementation stays with you
Infrastructure definitions, configurations and data production code are under the customer's control and versioned. Development can be continued by your own organisation, by Invinite or by another partner.
What this makes possible
Keep your most sensitive data in your own environment
You do not need to move all your data to the public cloud to use modern analytics and AI services.
Use the cloud where it helps
Cloud computing capacity and services can be used for selected use cases without building the whole data platform on them.
Change technology without starting over
Open formats and a modular architecture reduce dependency on any single technology.
Prepare for disruptions
A critical part of data production can run in an environment that does not depend on the availability of an external cloud service.
Keep the option to put it out to tender
The data, infrastructure definitions and data production code stay with the customer. Changing partner or technology does not mean rebuilding everything.
Complements Databricks and Snowflake – does not replace them
Databricks and Snowflake offer extensive tools for data processing, analytics and AI in the public cloud. Many of our customers already use them.
Invinite's sovereign data platform does not require giving them up. It adds a customer-controlled environment alongside them, where raw data, for example, can be received, processed and prepared before cloud services are used.
| Snowflake | Databricks | Invinite's sovereign data platform | |
|---|---|---|---|
| Role | Managed data and analytics service | Managed data, analytics and AI platform | Customer-controlled data platform |
| Environment | Public cloud | Public cloud | Own data centre, private cloud, public cloud or hybrid |
| Air-gapped deployment | Not typically | Not typically | Possible |
| Storage format | Proprietary format, also supports open Apache Iceberg | Open Delta Lake | Open Parquet and Delta Lake |
| Strongest at | Managed data warehouse and analytics in the cloud | Analytics, data science and AI in the cloud | Raw data in your own hands and hybrid cloud |
Together they work like this: raw data is processed and pseudonymised in the sovereign data platform in your own environment. Pseudonymised data goes to Databricks or Snowflake for analytics and AI. Open formats make it easier to move data between platforms. You get the cloud's computing power and keep control of your raw data.
From our work with customers
3 studies
A hybrid cloud strategy is worked out before it is built
We have carried out three studies: two for wellbeing services counties and one for a national-level organisation. They examined what kind of solution model and approach would enable a hybrid cloud strategy that improves data protection and makes the use of cloud resources more cost-effective.
Ask how a study is doneData protection is built into the structure
The platform's structure limits where personal data is processed and who can access it. Access control, logs and data protection controls run through the whole platform. That way data protection can be demonstrated rather than merely promised.
The platform is designed for environments where health data and other critical information are processed under strict data protection and information security requirements. Its architecture supports implementing and demonstrating requirements under, for example, GDPR, the Finnish Act on the Secondary Use of Health and Social Data, EHDS and NIS2.
A technical platform alone does not, however, make an organisation compliant, nor does it replace the organisation's own data protection and information security work or, for example, the secure operating environment that the Secondary Use Act requires where one is needed.
The platform and Data as Software together
The platform determines where data is and who controls it. Data as Software determines how data is produced: version-controlled, tested and taken into production in a controlled way. Together they make data production both sovereign and reliable.
Who it is for
Wellbeing services counties, hospitals and national health and social care organisations whose health data requires controlled processing. The same principles suit the security and defence sector and critical industry, where control over data is part of security of supply.
Technical choices
Architecture
A lakehouse architecture that is symmetrical across your own data centre, a private cloud and a public cloud.
Components
Storage in open formats (Parquet, Delta Lake). Apache Spark, Polars and DuckDB as compute engines depending on the use case. All components are established open source projects.
Production readiness
Before the platform goes into critical use, we make sure of ten things:
- identity and access management
- traceability and logs: who did what and when
- data protection controls
- separate environments for development, testing and production
- controlled releases and the ability to roll back to the previous version
- monitoring and alerts
- recovery plans
- automated enforcement of usage rules
- maintainable ways to ingest and transform data
- connecting new data sources in the same way every time
Tools. Infrastructure is described as code. Changes go through Git version control and automated testing and deployment (CI/CD). Every change that goes into production is reviewed and approved by an architect.
How the platform is put into use
We start with a definition: what data goes onto the platform, in what environment and with what requirements. After that the platform is built and put into use as a project, and our team can continue developing it with you. If a procurement is ahead, the definition also produces the procurement requirements.
Related pages: Data as Software · Health and social care situation centres and preparedness · Health data: standards and regulation