Systems that run where
the data is not allowed to leave.
The Blackfell Group builds software and AI systems that deploy as code into an account you own - commercial cloud, isolated networks, or air-gapped, where the managed services everyone else assumes simply are not there. You keep the data, the keys, and the ability to walk away with both.
A platform, and the products that run on it.
OpenLake
A lakehouse platform assembled from open source - Trino for SQL, Spark for ETL, Iceberg for table storage - deployed as infrastructure as code into your own cloud account, with single sign-on, cloud workstations, and governed access built in. Includes a health interoperability path: FHIR in, OMOP out.
FrontRunner
Fundraising and donor intelligence: public filings and giving history brought together into one queryable picture, refreshed on a schedule rather than reassembled by hand each cycle.
Ledger
Financial documents in, structured spreadsheets out. Ledger reads the PDFs people actually send - statements, schedules, reports - and returns data you can total, check, and reconcile.
Clinical data, without moving it somewhere else.
Health analytics usually means copying patient data into a vendor's tenancy and accepting their word about what happens to it. OpenLake runs inside your account, so PHI never transits our infrastructure - there is nothing for us to hold, log, or lose.
FHIR in, OMOP out
Ingest FHIR resources and land them in the OMOP Common Data Model, so clinical data arrives in the shape research and analytics tooling already expects, rather than as a bespoke schema nobody else can read.
Validated end to end against synthetic patient records - US Core profiles clean, and the resulting CDM reconciled row-for-row against an independent implementation.
PHI controls, on by default
Columns holding identifiers are detected as tables are catalogued and masked unless a role is explicitly entitled to them. Masking is enforced in the query engine, not in a dashboard, so it holds however the data is reached.
Every query is recorded - who ran what, against which columns, and when.
Your keys, your boundary
Storage is encrypted under keys you own and can revoke. Access is single sign-on against your own directory, and the whole platform deploys as code you can read into an account you control.
For teams working under HIPAA, that means the safeguards sit inside your existing compliance boundary instead of alongside it.
Deployed in your account, on your terms.
Your cloud, not ours
Everything ships as infrastructure as code into an account you own. There is no copy of your data on our side, because there is no our side - the platform runs where your data already lives.
Open source underneath
The engines are ones you can hire for and read the source of. That is a deliberate hedge against the day you would rather run it yourself, or hand it to someone else entirely.
Built for regulated work
Encryption under your own keys, CIS-hardened images, audited access, and a delivery path for isolated and air-gapped networks - built as a first-class target, not retrofitted once the commercial version shipped.
Tell us what you are trying to build.
If it sounds like something we build, we will say so. If it does not, we will say that too.