HENQ is an open-source software platform for building and operating applications. It manages their data, permissions, AI execution and shared services on infrastructure your organization controls.
The institutional proposition
Establish a common reference foundation and require projects to build on it or demonstrate conformity. Institutions retain control of adoption, conformance requirements and procurement, while suppliers compete on the systems they build.
HENQ provides the software, published architecture and repeatable tests to put that foundation into practice.
+Open architecture+Institution-owned data+Governed AI
How it fits together
Your products
Applications your teams build
Public services · Healthcare · Finance
The software platform you operate
HENQ
Data & permissions
AI & workflows
Files & exchange
Your environment
Infrastructure you choose
Computing · Storage · Service providers
Your teams build the applications. HENQ provides the services they run on.
01 / What HENQ is
Your teams build the applications. HENQ provides the services they run on.
A hospital builds a referral service. A bank builds a review system. An agency builds a permit service. Each defines its own work and uses HENQ to manage the data, permissions and shared services behind it.
The platform
Software your organization operates.
Install and operate HENQ on infrastructure you control. Application teams define their data models, relationships, workflows and user experience. They call HENQ services to store information, check permissions, run approved work and exchange data.
Teams do not need to assemble those shared services again for every application.
An architecture you can inspect.
The published design explains how the software works, how its controls fit together and what an application can rely on.
Requirements you can adopt.
Institutions can make those requirements part of procurement and acceptance. Projects can use HENQ or demonstrate that another foundation meets the adopted requirements.
Open architecture means inspectable code, documented interfaces and requirements institutions can reuse. HENQ uses the Apache 2.0 license.
02 / Control, built in
Powerful systems. You set the limits.
↳
Your data stays yours.
HENQ manages the data and controls how applications access it. Applications cannot bypass those controls with direct database access. Your institution chooses where the system runs and which providers it uses.
◇
Protection follows information.
Sensitivity, compartments and handling rules govern access, derived results and release. An AI-generated summary is not permission to disclose its sources.
⌁
AI acts within a mandate.
Models and agents work inside approved scopes, with human review where required. Generating a proposal and authorizing an action remain different powers.
≡
Decisions leave evidence.
Each operation records who acted, what permitted the action and which version of the information was used. Investigators and auditors can follow that record.
03 / Across sectors
Built for the work institutions do.
Protect a patient record, approve a financial decision or share an intelligence assessment. The applications differ; each needs control over access and clear responsibility for decisions.
Healthcare
Connected care. Appropriate access.
Give care teams the records they need and use AI to support clinical work. Access to a patient’s information follows the care relationship and the purpose of the task.
Example
A specialist referral
Identify the care team and the permitted purpose.
Prepare only the approved records and attachments.
Authorize the release and record the decision.
The specialist receives the approved information for the referral.
Finance
Financial judgment. Clear responsibility.
Support investigations, risk analysis and approvals with a record of the evidence and decisions. An automated recommendation still needs the required authorization before money moves or an account changes.
Example
A high-impact review
Limit an analyst’s access to the assigned matter.
Generate a proposal with its supporting evidence.
Require independent approval of the exact version.
The analyst prepares the recommendation. A separate reviewer approves it.
Public administration
Connected services. Controlled sharing.
Let agencies verify the facts needed for permits, benefits and public services. Each exchange has an approved purpose and recipient; agencies do not need permanent access to one another’s databases.
The application manages a permit request. HENQ manages access to its records, approval permissions, supporting documents and exchanges with other agencies.
Example
An interagency verification
Identify the receiving service and its legal purpose.
Approve the specific fact or document for release.
Apply the exchange policy and record what was delivered.
Agencies can verify a fact without requesting the citizen’s entire file.
Education
Personalized learning. Human judgment.
Help educators prepare learning plans and use AI in their teaching. Student records stay restricted to authorized users, and educators retain responsibility for decisions that affect learners.
Example
A learning-plan proposal
Use only the learner information authorized for the task.
Produce a proposal tied to its exact source version.
Let the authorized educator review before adoption.
The educator decides whether to adopt the AI-assisted proposal.
Defense & intelligence
Informed missions. Need-to-know access.
Give analysts access to authorized sources and preserve the origin and restrictions of their findings. Combining or summarizing information does not remove its classification or release requirements.
Example
An assessment for a partner
Restrict source access to the authorized mission.
Carry applicable restrictions into the assessment.
Require separate release authority for the recipient.
Sharing requires a release decision. Analysis alone does not declassify information.
04 / Information exchange
Share what is needed. Agree how it is used.
Manage records, files and information exchange under the same permissions, protection and audit rules.
01 / Governed source
Records & files
Known versions. Integrity and protection rules.
→
02 / Approved release
A release agreement
Recipient · purpose · permitted data Expiry · access limits · delivery record
→
03 / Destination
Another system
A trusted HENQ installation or a conventional external client.
Connect through familiar interfaces. A documented exchange contract tells partners how to authenticate, request approved information and meet its handling requirements.
Know the limits after delivery. Expiry and access limits govern requests to HENQ. Downloaded copies cannot be recalled, and offline reading cannot be counted. Recipient trust and agreed handling conditions still matter.