Mesh Talk to us
Architecture

Analyse data without centralising it

In short

To train a model on data spread across several sites or several organisations, you can move the computation instead of the data. The model is sent to each holder, trained locally, and only the learned parameters travel back, end-to-end encrypted. A coordinator aggregates them into a shared model that everyone gets. No copy of the data is built. That is what Mesh (Mesh Universe) builds.

On this page

Why data gets gathered in the first place

For a good reason: a model learns better when it sees more cases. A plant that has only recorded a few dozen failures has nothing to learn from. A hospital sees enough cases to treat patients, rarely enough for a model to spot rare situations. A bank discovers a fraud pattern that the next one has never seen.

The historical answer has been to bring everything into one place, an analytics warehouse or a data lake. It works, and at the same time it creates a convergence point that concentrates both the data and the access to the systems it came from. That point became the path of several French breaches in 2026, documented by the affected organisations themselves: see the breach comes from the copy.

And in many situations, gathering is not even possible. Two competitors do not exchange their shop floor records. A subcontractor does not show its costs to its client. A hospital does not release patient files. The project stops there, and not for a technical reason.

Moving the computation rather than the data

The alternative reverses the flow. Instead of bringing the data to the computation, you bring the computation to the data.

At the end, each participant holds a model that learned from the whole of the data, without a single record changing hands. That is the principle of federated learning, and it works between the sites of one company as well as between separate organisations.

What travels is parameters, never records. Transport is end-to-end encrypted, with RSA-OAEP 2048 for key exchange and AES-GCM 256 for content. Mesh does not compute on encrypted data: the participant decrypts the model before training it, and the coordinator decrypts the updates before averaging them. Enclave execution and advanced hardening are offered as options.

What it changes about exposure surface

This architecture does not reduce the probability that a piece of software is vulnerable. An unpatched tool stays exploitable, a stolen credential stays usable, each site still has to be protected as before.

What it changes is what is reachable when something falls. An intrusion at one participant reaches that participant's data, not the others', because there is nowhere that they were brought together. There is no gathered copy to exfiltrate, and no central instance holding the credentials of every database in scope.

It is also the data minimisation reading of the GDPR: data you do not copy is data you do not have to protect elsewhere, nor notify elsewhere.

What it does not replace

Federated learning covers model training on distributed data. It does not cover everything.

So the useful question is not to remove every warehouse. It is to look, use case by use case, at which ones never required the copy that was built for them.

When it is worth it

Three configurations come up.

Several sites of one organisation, each with too little history to train a useful model alone, where gathering would raise a sovereignty, contractual or transfer volume problem.

Several organisations with the same problem that cannot open up to each other, because they compete, or because the data is covered by trade secret or by a specific protection regime.

A value chain where each actor only sees its own link, and where the quantity being sought depends on all of them.

Conversely, if the data is already legitimately gathered, held by a single party with no sharing constraint, federated learning adds complexity without adding value.

How it gets set up

How a project works sets out the stages and the cost structure. The usual order: frame the question the model has to answer, check that each participant holds the necessary variables, agree on a shared vocabulary, then run a first training cycle on a reduced scope before widening it.

A demo on real public data shows the mechanism at work on open, cited datasets, with their source and licence.

Mesh is at launch stage. No production deployment exists to date, and the demo simulates participants inside a single process. The ROI calculator gives an order of magnitude of the expected gain by number of participants.

FAQ: analysing without centralising

Can you analyse data without centralising it?

Yes, for part of the use cases. Training a model on distributed data is done by moving the computation instead of the data: the model is sent to each holder, trained locally, and only the learned parameters travel back, encrypted. A coordinator aggregates them into a shared model. Uses that require reading records row by row still need direct access.

What does this change about breach risk?

It does not change the probability that a piece of software is vulnerable. It changes what is reachable when it is: if no gathered copy exists, there is no gathered copy to exfiltrate. That is a reduction in exposure surface, and it removes none of the security measures needed on each site.

Does federated learning replace a data warehouse?

No. It covers model training on distributed data. Operational reporting, regulatory reporting and ad hoc exploration keep their tools. The useful question is to see which uses never required the copy that was built for them.

What exactly travels?

Model parameters, never records. Transport is end-to-end encrypted: RSA-OAEP 2048 for key exchange, AES-GCM 256 for content, with a session key for each exchange. Mesh does not compute on encrypted data: the participant decrypts the model before training it, and the coordinator decrypts the updates before averaging them. Enclave execution is offered as an option.

Can the shared model reveal a participant's data?

That is the re-identification risk from shared parameters. Differential privacy is applied to mitigate it, without a guaranteed ε budget at this stage: that parameter is set per deployment. The security page sets out what is built in and what is optional.

Which uses never needed the copy?

Describe your case in a few lines: the sites or organisations involved, the question the model would have to settle. We reply with the material that fits.

contact (at) meshuniverse.fr