NHS Sovereign Federated Data Platform · Overview

NHS Sovereign Federated Data Platform

Open, deterministic public infrastructure for connecting NHS operational systems without transferring permanent control of the resulting platform to one supplier.

v0.1.0 AGPL-3.0-or-later Executable reference release Synthetic data only

Core position

National coordination does not require a closed supplier runtime

The software separates source integration, canonical operational data, deterministic execution and reusable products. Local organisations retain authority while registered federation routes support regional and national coordination.

Existing systems EPR, PAS, referral, waiting-list, theatre, bed, workforce and diagnostic sources remain authoritative.
Preserve & validate Original payloads are retained. Structure, identity, dates, relationships and freshness are checked.
Canonicalise Versioned mappings create stable operational records without erasing source meaning or provenance.
Execute rules Fixed inputs, rule versions and pipeline versions produce reproducible states, tasks and alerts.
Operate & exit Accessible products, audit, exports, migration evidence and replaceable deployment assets remain under NHS control.

Six non-negotiable positions

The governing architecture

01

Local control

NHS organisations retain control of local data, configuration, identity, keys and operational authority.

02

Controlled federation

National coordination uses declared datasets, purposes and registered routes rather than unrestricted central access.

03

Source evidence

Original records remain separate from canonical and derived states. Failed data is retained and visibly routed.

04

Deterministic execution

The same validated state, schemas, rules, pipelines and configuration must produce the same result.

05

Replaceable components

Products, rules, pipelines, connectors, databases and deployment assets can be inspected, tested and replaced.

06

Exit before dependency

Export, reconciliation, rollback, data return and supplier withdrawal are designed and tested before lock-in is accepted.

What the release contains

Architecture, software and exit machinery in one inspectable release

The reference package aligns the written specification with runnable assets instead of treating architecture diagrams as delivery evidence.

SOFTWARE

Executable operational core

  • Python, FastAPI, Pydantic and SQLAlchemy
  • PostgreSQL operational data model
  • Accessible HTML, CSS and JavaScript interface
  • Deterministic RTT validation product
CONTRACTS

Versioned public interfaces

  • Canonical patient and pathway schemas
  • Rule, pipeline and product manifests
  • Typed API and event boundaries
  • Audit, provenance and export records
DEPLOYMENT

Portable execution route

  • Docker Compose reference deployment
  • Kubernetes and OpenShift manifests
  • Separated web, API and database layers
  • Backup, restore and alternative-hosting requirements
EVIDENCE

Repeatable test contract

  • Fixed synthetic source records
  • Exact expected states and calculations
  • Idempotent task creation
  • Release hashes and retained limitations
MIGRATION

Controlled transition

  • Asset and dependency inventory
  • Parallel running and reconciliation
  • Cutover and rollback evidence
  • Non-cooperative supplier protocol
LICENCE

Public infrastructure licence

  • AGPL-3.0-or-later software release
  • Source availability for network deployment
  • Modification history and attribution
  • No licence-based authority to access NHS data

What this is

  • An executable reference implementation.
  • A deterministic RTT and waiting-list demonstrator.
  • A complete architecture and public contract model.
  • A migration, reconciliation and supplier-exit framework.
  • A practical public option for evidence-led development.

What this is not

  • Not a production national FDP today.
  • Not connected to live NHS systems or patient data.
  • Not a substitute for DTAC, DCB0129/0160, DSPT or local assurance.
  • Not evidence of production scale, resilience or penetration testing.
  • Not dependent on generative AI for operational decisions.