Software · AI · Restricted environments

Systems that run where
the data is not allowed to leave.

The Blackfell Group builds software and AI systems that deploy as code into an account you own - commercial cloud, isolated networks, or air-gapped, where the managed services everyone else assumes simply are not there. You keep the data, the keys, and the ability to walk away with both.

01 — What we build

A platform, and the products that run on it.

OpenLake

A lakehouse platform assembled from open source - Trino for SQL, Spark for ETL, Iceberg for table storage - deployed as infrastructure as code into your own cloud account, with single sign-on, cloud workstations, and governed access built in. Includes a health interoperability path: FHIR in, OMOP out.

openlake.co

FrontRunner

Fundraising and donor intelligence: public filings and giving history brought together into one queryable picture, refreshed on a schedule rather than reassembled by hand each cycle.

frontrunner.blackfellgroup.com

Ledger

Financial documents in, structured spreadsheets out. Ledger reads the PDFs people actually send - statements, schedules, reports - and returns data you can total, check, and reconcile.

ledger.blackfellgroup.com

02 — AI and data agents

Agents that run where the data already is.

The usual way to put AI on your data is to send the data to the AI. We do it the other way round - the agents run in the account that already holds it, against a model endpoint you own, and they propose work rather than quietly doing it.

A data-ops agent that proposes

It watches the platform's own operational record - failed jobs, stale tables, schema drift - and arrives with a specific change you can read and reject, not an alert. How far it may go is a setting you raise deliberately.

A semantic layer that maintains itself

New tables are catalogued, described, and screened for personal identifiers as they land, with a human confirming before anything is published or masked. Lineage is recorded by the jobs themselves as they run.

Inference inside your boundary

Model calls go through a gateway in your own account, so prompts and the data in them never leave it. There is no Blackfell service in the request path.

How the agents work

03 — Health data

Clinical data, without moving it somewhere else.

Health analytics usually means copying patient data into a vendor's tenancy and accepting their word about what happens to it. OpenLake runs inside your account, so PHI never transits our infrastructure - there is nothing for us to hold, log, or lose.

FHIR in, OMOP out

Ingest FHIR resources and land them in the OMOP Common Data Model, so clinical data arrives in the shape research and analytics tooling already expects, rather than as a bespoke schema nobody else can read.

Validated end to end against synthetic patient records - US Core profiles clean, and the resulting CDM reconciled row-for-row against an independent implementation.

PHI controls, on by default

Columns holding identifiers are detected as tables are catalogued and masked unless a role is explicitly entitled to them. Masking is enforced in the query engine, not in a dashboard, so it holds however the data is reached.

Every query is recorded - who ran what, against which columns, and when.

Your keys, your boundary

Storage is encrypted under keys you own and can revoke. Access is single sign-on against your own directory, and the whole platform deploys as code you can read into an account you control.

For teams working under HIPAA, that means the safeguards sit inside your existing compliance boundary instead of alongside it.

04 — How we work

Deployed in your account, on your terms.

Your cloud, not ours

Everything ships as infrastructure as code into an account you own. There is no copy of your data on our side, because there is no our side - the platform runs where your data already lives.

Open source underneath

The engines are ones you can hire for and read the source of. That is a deliberate hedge against the day you would rather run it yourself, or hand it to someone else entirely.

Built for regulated work

Encryption under your own keys, CIS-hardened images, audited access, and a delivery path for isolated and air-gapped networks - built as a first-class target, not retrofitted once the commercial version shipped.

Tell us what you are trying to build.

If it sounds like something we build, we will say so. If it does not, we will say that too.

Get in touch