Request a technical briefing

Deployment, sovereignty, and privacy

The platform runs where your microdata already lives. It operates only on data your office already lawfully holds, acquires nothing externally on your behalf, and leaves the models it trains with you.

01

On-premises or in-country sovereign cloud

Deployed inside your own infrastructure, or in a sovereign cloud region within your jurisdiction. Microdata does not cross a border. There is no vendor-side copy of your records, because there is no transfer to make one from.

02

Role-based access, fully logged

Role-based access control with integration into your institutional identity systems, so access follows the roles your office already administers. Every action is logged — who ran what, against which round, with which configuration, and what they did with the result.

03

Only data you already hold

The platform operates on your existing microdata, whichever administrative registers you choose to include, and published macro indicators. It acquires no external data on your behalf, and no data source is added without your office's decision.

04

Pseudonymized workflows supported

Analysis can run against pseudonymized records where your disclosure-control rules require it. Identification is not needed for reconstruction; the record key is.

05

Your data and your models stay yours

Client data and the models trained on it remain the client's, inside the client's deployment. Nothing trained on your microdata is carried to another engagement.

06

Nothing is published without you

The platform produces internal reports for analyst review. It has no publication path of its own — releasing a figure remains an act of your office, taken by your staff, through your existing approval process.

The short version

Your microdata never leaves your jurisdiction, no released statistic can be changed by the platform, and the models trained on your data belong to you.

For your data protection officer

The questions that usually come next

  • Where is processing performed? Inside your deployment, within your jurisdiction. There is no processing on vendor infrastructure.
  • What is transferred to the vendor? No microdata. Support work happens against your deployment under your access controls and logging.
  • What is the retention position? Retention follows your office's own policy — the data is on your systems, under your schedule.
  • Who can see individual records? Only roles your office grants, through your own identity system, with every access logged.

Bring your security and data-protection staff to the briefing

We would rather answer the deployment and sovereignty questions early than discover them at contract stage.