The analytics layer that makes European health data usable.
From fragmented health data to causal prevention intelligence, without the data ever moving.
Loretta is federated causal inference AI infrastructure for European health data, deployed on sovereign EU cloud. The computation travels to where the data already sits. The data never moves. We hold no data, we broker no access, and we make granted access computable.
We run it on our sovereign EU cloud. Your data still never leaves the institution. Run it in your own environment. Your infrastructure, your keys, your control.
Platform
Four layers of infrastructure. One outcome: prevention you can act on.
Our architecture is modular. Each layer delivers value on its own and can be deployed without the others, because in sensitive sectors, infrastructure that demands full adoption before it delivers anything never gets adopted at all.
Federated foundation
Models train across distributed sites without centralising a single record. Only encrypted model weights move between locations; patient data never does. Built on sovereign EU cloud to remove supply-chain dependence on non-European hyperscalers, so every component holds up to regulatory scrutiny.
Causal inference engine
Federated causal learning, not just federated training. This layer builds directed acyclic graphs and applies targeted maximum likelihood estimation across sites to identify what actually drives health outcomes. Correlation at population scale is not prevention intelligence. Causality is.
Exposome context
Not every determinant of health lives in clinical data. Environmental exposure, occupational conditions, and socioeconomic factors shape outcomes as decisively as any biomarker. This layer folds those determinants into the causal model, with differential privacy preserving their sensitivity.
Auditability by design
In regulated sectors, what cannot be audited cannot be deployed. Every inference, every access decision, and every model output is human-auditable and verifiable, not merely human-readable. Compliance built in from the first line of code, not retrofitted to pass review.
Auditability by design
Hash-chained and tamper-evident. Each record carries the previous record's hash, so the trail verifies itself and any edit is detectable. A compliance record by design, not an add-on.
Ecosystem
An ecosystem, not a vendor relationship
Loretta develops alongside the institutions shaping the European health data space, from the clinical partners who steward the data to the regulators who write the rules. We build our infrastructure in the open, with the partners who will use it.
Fraunhofer HHI
Research Partner, exposome context layer.
STACKIT, Schwarz Digits
Sovereign infrastructure partner.
DUCAH
Ecosystem and translation partner within the digital care and health innovation network.
sphin-X e.V. Voting member
Co-defining standards for sovereign, privacy-preserving health data infrastructure in Europe.
Ways to collaborate
Contribute data to a federated study
Run causal models across your institution's data without the data ever leaving your environment.
Co-develop the infrastructure
Shape the standards, the models, and the compliance posture alongside us as an ecosystem partner.
Deploy sovereign analytics in your setting
Bring pre-vetted, EU AI Act-ready infrastructure into your operational environment.
Our position
We were not built into the ecosystem. We were built within it.
Loretta develops together with the actors defining the European health data space, from the regulators writing the rules to the institutional partners deploying infrastructure in the field. We are not here to disrupt. We are here to build. That means building on what already exists, setting standards with the system rather than around it, and acting as a steward of a common good.
Healthcare is painstaking. It rewards meticulous attention to detail, incremental progress, and the discipline to resist miracle-cure thinking. There is no shortcut to trust in this system. We earn it by building correctly, transparently, and in service of the institutions we work with.
Regulatory co-development
We design infrastructure alongside the EHDS, the EU AI Act, and the GDNG, rather than retrofitting after publication. Our compliance posture is shaped by direct engagement with the policy environment.
Research partnership
We collaborate with leading European research cohorts and academic partners to validate causal models and advance the science of privacy-preserving population health analytics.
Ecosystem infrastructure
We are embedded in sector-wide efforts to harmonise the European health data landscape, defining standards and building the shared foundations the system needs.
What sets us apart
Others federate. We federate and explain why.
The market has federated learning frameworks and health data platforms. None combines privacy-preserving federation with causal inference for chronic disease prevention, and none does so without taking custody of the data.
Per-patient causal effects, validated against known ground truth. The same output is human-readable and auditable, so an institution can see why a recommendation was made, not only that it was.
Causality, not correlation
Federated training alone produces predictions. Federated causal learning produces explanations of which interventions change which outcomes, for which populations, under which conditions. Prevention requires understanding mechanisms, not just patterns.
Prevention, not drug discovery
Purpose-built for chronic disease prevention and population health. We target the origin: what makes people ill, and what can be changed before they become ill.
Equity by architecture
Fairness-aware models that account for socioeconomic proxies and structural determinants are not a feature; they are foundational. Equity constraints are built into the model architecture, not applied afterward as an audit layer.
Compliance by design
Sovereign technology on EU cloud infrastructure that removes supply-chain dependencies that fail regulatory review. Every layer is designed from the first line of code to meet the EU AI Act, GDPR Article 9, and EHDS secondary-use requirements.
Who this serves
Every actor in the health system faces the same structural gap
Health data exists. Legal access is growing. But without sovereign, privacy-preserving analytics infrastructure, that access produces no insight, no prevention, and no value.
Health systems and payers
Payers and public health bodies need population-level analytics that work across institutions without moving sensitive data. Past initiatives created components, not a usable, compliant analytics layer. Loretta is that layer.
Pharma and research
Population-scale real-world evidence is legally visible but analytically out of reach. Without sovereign federated computation, that data stays inaccessible to research and the insight it could yield goes unrealised.
Public health and regulators
Preventable disease keeps going undetected, not because data is missing, but because nothing connects fragmented datasets across institutions and borders into actionable prevention intelligence.
Security
Encrypted by architecture, sovereign by hosting
Loretta is built by a security and GRC team from the first commit, not hardened after the fact. Protection comes from how the system is assembled: asymmetric encryption on everything that crosses a boundary, decryption keys the institution controls, and sovereign European infrastructure underneath.
Public-key cryptography, end to end. The model update is encrypted before it leaves, and only the holder of the matching private key can open it. The key itself never travels.
Asymmetric encryption end to end
Every artifact that crosses a boundary is protected with public-key cryptography. Model updates are encrypted before they leave a node and can be opened only by the holder of the corresponding private key. Data in transit and at rest is protected the same way. Raw data never crosses a boundary; only encrypted parameters do.
Keys the institution controls
In self-hosted deployments the institution holds its own private keys, so decryption authority never leaves its environment. Loretta cannot read what it has not been given the key to read. Your infrastructure, your keys, your control.
Sovereign hosting on STACKIT
Hosted deployments run on STACKIT, the sovereign European cloud operated by Schwarz Group, with data centres exclusively in Germany and Austria and no non-European jurisdiction over the data. ISO 27001 certified, GDPR-compliant, built on open source to avoid vendor lock-in, with confidential computing protecting data even during processing.
Minimal attack surface, verifiable operations
Loretta holds no patient data and moves none, so there is little to intercept. Every access decision and model output is written to a hash-chained, tamper-evident audit trail, and access follows least-privilege by default.
Compliant by design, verifiable by architecture
Loretta processes no personal health data outside the responsible institution. Models run locally; central systems handle only aggregated, non-traceable parameters.
The analytics layer for European health data will be built. The question is by whom.
Loretta develops alongside the regulators, research institutions, and industry leaders shaping the European health data space. Our infrastructure is designed together with the policies that govern it, not retrofitted afterward. Whether you steward a health system, lead research, or are building the foundations of this ecosystem with us, this is the conversation to be part of.