Ferrum — GA4GH infrastructure that actually runs.
Complete GA4GH stack on-premise — for clinics, data integration centres, and genomDE data nodes that cannot send raw data to the cloud. Tested, documented, in Rust.
Evidence you can inspect
Five public repositories form the GA4GH stack: Ferrum (data/compute), ga4gh-infra (identity), Lab Kit (deploy), Demo (benchmark), and HelixTest (conformance). Apache-2.0 where stated; BUSL-1.1 covers the integrated Ferrum runtime with a clear research allowance and four-year conversion to Apache-2.0 (see LICENSE).
Why Ferrum exists
Most GA4GH implementations are cloud-first, hard to verify, or simply not finished. Ferrum is built for teams that know their data must stay on-premise — while still needing to interoperate with GA4GH-compatible networks. The GA4GH APIs are good. There should be a system that implements them consistently. So we built it.
National archives hold submitted genomic data. Ferrum is the local side: GA4GH-oriented infrastructure at the clinic or data node before submission. Crypt4GH is implemented in Ferrum — the same encryption many archives use. DRS interface for structured transfer. No cloud as an intermediate step.
Clinical companion: Solum
When you also need clinical/EHDS compliance (enforce · translate · evidence) beside genomic data, Solum is the optional companion — separate product and regulatory perimeter, shared Crypt4GH and sovereignty patterns. Not required to run Ferrum.
Ferrum + Solum together
Genomic plane and clinical compliance plane as one engagement: shared Crypt4GH patterns, separate perimeters, one pilot conversation. Ask about a joint Ferrum + Solum scope.
Ask about Ferrum + SolumCore capabilities
| Feature | Description | |
|---|---|---|
| Portable workflow engines | WES/TES execution for Nextflow, CWL, WDL, and Snakemake — on SLURM/LSF clusters or local runners. | |
| Provenance & RO-Crate export | Lineage metadata and exportable RO-Crate bundles for reproducibility, audit trails, and downstream catalogues. | |
| Offline-first / Edge mode | Runs on a single device with SQLite and local storage. No PostgreSQL or MinIO required for Edge deployments. Recovers cleanly from power loss. | |
| Data residency audit | Cryptographically chained, append-only log of all data movements. Proves data stayed within your institution. | |
| Federated Beacon (P2P) | Ferrum instances query each other directly — no central coordinator, no cloud dependency. Works across slow or intermittent links. |
Orientation, not legal advice
Designed for regulated environments (GDPR, EHDS, NIS2, HIPAA as orientation). Technical evidence and tests — not a compliance certificate and not legal advice.
Institutional pricing (indicative)
Research use under the BUSL Additional Use Grant stays free of licence fees. For production institutional deployments we quote fixed annual licences and optional support — not per-seat SaaS.
| Item | Guide (net EUR) |
|---|---|
| Commercial licence — single node | €15,000–35,000 / year |
| Commercial licence — multi-site (2–5) | €40,000–80,000 / year |
| Bounded pilot (60–90 days) | €10,000–20,000 fixed (credit toward year-1 licence by arrangement) |
| Support | Standard included · Priority +15% · Enterprise +30% (uptime SLA only if SOW defines it) |
Indicative only. Binding terms in writing. Consortium / national nodes: contact us. Africa: documented regional pricing 25–50% below EU tier.
Year-1 worked example (indicative)
A single-site DIC piloting Ferrum + Solum Track A together often lands around €18k–38k in Year 1 before support uplifts: Ferrum pilot €10k–20k (creditable toward year-1 licence) plus Solum Track A pilot €8k–18k. Multi-site and Track B CDR add-ons sit above that band. Binding totals only in writing.
Support tiers
Support applies to paid institutional licences and support agreements for Ferrum (and Solum under the same model).
Delivered by a small team (founder-scale), business hours CET/CEST, Monday–Friday (Baden-Württemberg holidays excluded). Not a 24/7 NOC.
| Tier | First response | Hours / channels |
|---|---|---|
| Standard | 2 business days | Business hours CET · email / ticket · included |
| Priority | 8 business hours | Business hours CET · email + scheduled call · typically +15% |
| Enterprise | 4 business hours | Extended 07:00–20:00 CET · dedicated contact · typically +30% |
First response means acknowledgment and triage, not resolution. BUSL research use may get good-faith community replies without a contractual SLA.
Numeric production uptime percentages are not a standing vendor promise for customer-hosted deployments. Enterprise uptime SLA only if a signed SOW defines measurable scope; otherwise N/A.
What Ferrum is not
- No formal compliance certification (e.g. ISO, NIS2, EHDS)—orientation only.
- Not a fully managed cloud SaaS—Ferrum runs in your environment.
- Not a one-click substitute for governance or organisational process.
Technical depth
Install commands, full deployment options, and architecture live in the citable reports and the GitHub quickstart — short here, deep there.
- SF-TR-2026-001 — Ferrum Architecture →
- SF-TR-2026-002 — Ferrum Field & Edge →
- Quickstart on GitHub →
- Deployment docs on GitHub →
- Field & offline deployment →
- Read the Ferrum & GA4GH white paper →
Ferrum is licensed under BUSL-1.1 — free for research and non-commercial use, with a commercial licence for production deployments. After four years the licence converts to Apache-2.0. You can licence it, request features, or use it as a starting point for your own infrastructure. No vendor lock-in.
Regulatory context: EHDS · NIS2 · GDPR & health data
We typically reply within two business days. Repository and licence details are available on request.