DataFab / Architecture & deployment
Where it runs, and how it is proven
The architecture, in full technical detail.
The same platform, delivered against your estate and your controls — a managed control plane that never holds raw data, a data plane that runs inside your environment, four editions from managed to sovereign, and a signed chain of custody from source to the gate that is yours.
The core architecture
Cloud-grade capability, without cloud-grade loss of control.
The control plane manages orchestration, governance, metadata, configuration, deployment, observability and policy. It understands how the estate is structured, what sources exist, what rules apply, and who — human or agency — may access what. It is not where raw data goes.
A person or an agency asks a question. The caller is authenticated at the gateway and the request is typed against the semantic layer.
The consolidated permission model resolves what this caller may see. Inherited source entitlements are the floor — stricter, never looser.
A query plan is produced against the derived ontology, not against raw tables. Walled entity and relationship types are excluded before planning, not filtered after.
Connectors read the source systems directly, under your credentials, over the pattern your network allows. No record is copied out.
Records are matched and resolved on the way back. Confidence, source and date are carried on every edge.
If the request would cause an effect rather than return an answer, a deterministic gate holds it for an accountable person.
The result returns with its evidence, and the traversal, the exclusions and the disposition are written to the tamper-evident trail.
Not a thin metadata agent. A runtime.
The data plane runs inside your own cloud, VPC, on-premises or air-gapped environment. That is where data is read, processed, indexed, enriched and activated. Query, transformation, enrichment, feature engineering and agency workloads execute on compute inside your environment, close to where the data already sits, with CPU and GPU capacity available where required.
The managed control loop, delivered as a product.
The control plane compiles policy as code, coordinates many private data planes, brokers identity, manages upgrades, monitors health and runs the fleet — the platform-engineering function you would otherwise have to assemble, integrate and staff yourself. That is the difference between ordinary self-hosting and this: self-hosting hands you the burden; here it arrives as a product.
The claim, defined
What raw egress 0 B actually means.
The phrase appears on every page of this site, so it should mean exactly one thing. It does not mean the platform has no network. It means two invariants hold in every edition, and a third thing — where the data plane physically sits — is a choice you make.
Raw records never leave their system of record
The fabric reads in place, over read-only connections, with your credentials. What persists in the fabric is the resolved layer — mappings, derived insight, typed relationships and a snapshot of each cited record. The underlying rows, files and documents are never lifted out of the systems that own them, whichever edition you run.
The control plane never holds raw data
Policy, metadata, catalogue, identity brokering, fleet management and observability. That is the whole of what crosses from the data plane to the control plane — in Foundation exactly as in Sovereign. There is no edition in which your records reach DataFab’s management layer.
What an edition changes is whose environment the data plane runs in. Zero egress is always measured at that boundary. In Foundation, the boundary is a single-tenant environment DataFab operates in the region you choose — your records still never leave their source systems, but the runtime that reads them is ours to operate. From Professional upward the boundary is your own cloud account, your own tenancy, or your own premises, and custody of the keys moves with it. If the distinction matters to your risk function — and in a regulated or classified estate it should — the honest answer is Professional or above.
| Edition | Data plane runs in | Operated by | Key custody | Leaves the source system | Reaches the control plane |
|---|---|---|---|---|---|
| Foundation | Single tenant, your chosen region | DataFab | DataFab, or BYOK on request | Nothing | Metadata and control signals only |
| Professional | Your cloud account and VPC | DataFab, in your account | You | Nothing | Metadata and control signals only |
| In-tenant | Your tenancy, your identity provider | You, with managed upgrades | You | Nothing | Metadata and control signals only |
| Sovereign | On-premises or air-gapped | You | You | Nothing | Nothing — control plane self-hosted |
Every claim in this table is demonstrated against the engineering evidence pack at the assurance stage and recorded in the confirmation register. Deployment-specific values are populated per environment.
Editions
Four editions. One architecture.
The architecture is fixed. What changes between editions is where the planes run, who holds the keys, and how much of the operation you take on. Custody shifts to you from Professional upward.
Foundation
Single-tenant and DataFab-hosted in the region you choose. Your records still never leave their source systems, but the runtime that reads them is ours to operate — see what 0 B means.
Professional
Your cloud account and private connectivity, with key custody moving to you. Suited to enterprises with an established cloud landing zone.
In-tenant
Data plane fully inside your tenancy, integrated with your identity provider, your key-management service and your security-operations tooling.
Sovereign
On-premises or air-gapped, in your accredited environment, under your keys and your jurisdiction. No cloud dependency, no vendor tenancy, no third-party custody.
Edition names describe the deployment posture, not a feature ladder: the enforcement points, the boundaries, the gateway and the model rule are fixed by the architecture and do not change per edition.
The reference deployment, as engineered
Editions, enforcement points, and the journey.
Deployment-time choices
Fixed architecture. Seven decisions.
The architecture is fixed; these seven choices are not. Each has an owner and a stage. Everything else — the boundaries, the gateway, the model rule, the enforcement points — is fixed and does not change per deployment. That is what makes these seven the whole of the deployment-time surface.
| Decision | Set by | When | What it determines |
|---|---|---|---|
| Edition | Customer + DataFab | Design | Where the planes run and who holds custody |
| Region / enclave | Customer | Design | Residency and jurisdiction |
| Network CIDRs | Customer infrastructure | Setup | Address space and connectivity pattern |
| Key management / HSM | Security | Setup | What protects data at rest, and who holds the keys |
| SIEM target | Security-operations team | Setup | Where the audit and telemetry stream lands |
| Recovery objectives | Business + IT | Design | Recovery point and recovery time targets |
| Source list | Data owner | Discovery | What the fabric connects to first |
The deployment journey
Each phase has an owner and an exit gate.
A data plane stands up in hours. Connecting the first sources is typically same-day. Governance is authored as code and evolves from there. What follows is the shape of the engagement, not a multi-year programme plan.
Design
Edition, region or enclave, and recovery objectives agreed. The reference architecture is instantiated against your controls, not redrawn.
Setup
Address space, key management, identity integration and the security-operations telemetry target configured by your teams, with the platform deployed by declarative infrastructure.
Discovery
The first sources are connected read-only. The fabric catalogues, profiles and classifies; the derived model is presented for review rather than authored from a blank page.
Resolution & approval
Entity resolution runs at thresholds you set; uncertain matches route to your people. The semantic layer is reviewed, corrected and approved.
First governed agency
Your own people compose the first agency in the Studio, test it in a sandbox against sample files, and publish it scoped and gated.
Assurance
Enforcement points are demonstrated against the engineering evidence pack, and the audit and lineage stream is proven end to end into your own tooling.
Expand
Each new source deepens the graph, sharpens the semantic layer, and makes the next utility cheaper than the last.
Resilience & disaster recovery
Two failure modes, two answers.
Loss and corruption are not the same problem and do not have the same remedy. Loss is answered by replication and failover. Corruption is answered by rollback and re-derivation — and because the knowledge state is derived from sources that never moved, re-derivation is a real option rather than a restore from a backup of a copy.
Replicate & failover
Recovery point and recovery time objectives are set by the business at design stage and engineered to, not assumed.
Rollback & re-derive
The semantic layer and the resolved state can be rolled back to a version, or re-derived from sources that were never modified.
Custody is explicit
Who may act, and what protects data at rest. Custody shifts to you from Professional upward, and the model is inspectable.
Topology per deployment
Direct TLS, VPN tunnel, private link or agent-based for air-gapped estates — populated by engineering per environment.
Build & release
Signed, inventoried, customer-approved.
In a regulated estate, what runs matters as much as what it does. Releases are signed, the software inventory is published, provenance is attested, and the customer approves what is promoted into their environment.
Enforcement points are demonstrated against an engineering evidence pack and recorded in a confirmation register, so the claim and the proof are the same document.
Document extraction
Extraction, not ingestion.
Most of what an enterprise knows sits in documents no query can reach. Document processing normally builds the very thing the fabric exists to avoid — a second copy of the estate, in a new store, under a new access model. This service accumulates nothing.
No secondary corpus
The source of record is never migrated or duplicated into a DataFab document store, and no secondary corpus is retained. A document is processed and its text returned with the evidence of how that text was produced.
Classified before dispatch
A document cannot be inspected in an external service to decide whether it was too sensitive to send there. Classification resolves from metadata the organisation already holds — before any byte moves. Unclassifiable is treated as sensitive.
Every extraction is defensible
Direct extraction or OCR and by which backend; the classification basis and the routing decision it drove; model version, confidence, source hash, timestamp and duration — captured at processing time rather than reconstructed later.
Where confidence falls below the acceptance threshold, the service flags the region rather than inventing plausible text. Low-confidence output is routed for review, and reprocessing is supported.
Throughput and accuracy targets are drawn from the service specification and are set per engagement. They are targets, not measured results.
Next step
Stand up a data plane and connect one source.
Hours to a running plane, same-day to the first connected sources, and governance authored as code from there. Bring your controls; the architecture is designed to meet them, not to be argued with.