HealthcareGoverned collaboration

Platform journey

A governed healthcare collaboration, from source data to a signed model

How Daulat carries protected clinical data through governed acquisition, cross-institution sharing, federated training, and a signed model with complete lineage—without the data leaving its custodian.

  • Healthcare
  • Multi-institution training
  • Data stays with its custodian
  • Signed model lineage

The constraint

The data cannot move. The work still has to happen.

Healthcare collaboration usually stalls in the same place. The research question needs data from several institutions, and every one of those institutions has an obligation it cannot delegate: the records stay under its control. Pooling the data into a shared environment answers the research question by dissolving the constraint that made the data protected in the first place.

Daulat resolves it the other way around. Institutions connect through a shared trust layer, not shared infrastructure. Each participant keeps its own environment; the platform moves approved compute to the data and carries the governance with it.

The path below is one collaboration end to end—governed acquisition, sharing under policy, federated training, and a signed model. The same path applies wherever the constraint is the same: the data cannot move, and the parties are independently governed.

The path

From source data to a signed model, without pooling.

  1. 01 Acquire Data is acquired into the custodian's own environment through a governed pipeline, profiled and quality-checked in place. Nothing is copied into a central pool.
  2. 02 Publish The custodian publishes an immutably versioned dataset that stays where it lives. The catalog carries the description and the lineage—never the records.
  3. 03 Authorize Participation, purpose, custodian approval, consent coverage, and licensing are evaluated before any work begins. A run that fails any one of them does not start.
  4. 04 Execute Platform-approved, signed runtimes execute inside each participant's boundary, pinned by immutable image digest. Compute moves to the data; the data does not move.
  5. 05 Verify Secure-aggregated rounds produce a signed model version carrying source-to-model lineage—which data, which algorithm, which runtime, which policy decision, at which version.

The platform

What Daulat does

  • Each institution keeps custody of its own data, in its own cloud, on-premises, or hybrid environment.
  • A proprietary algorithm executes without exposing its source, so algorithm owners can participate without surrendering their IP.
  • Every round is authorized before it runs, against policy the custodian controls—authorization is not granted once and assumed thereafter.
  • Only platform-approved, signed runtime images execute, pinned by immutable digest rather than by name.
  • Every result carries verifiable lineage from source data to published model, reproducible at exact versions.

Your side of the boundary

What stays yours

  • Your data stays in the environment you govern, under the custodian you designate.
  • Your approvals gate every run, and you can withdraw them.
  • Your policy decides participation, purpose, and licensing—not the platform operator, and not another participant.
  • Your algorithms and models remain yours; the platform governs their use without taking custody of them.