Data Residency & Sovereignty
Your data stays where you need it to stay
Every ManySignal tenant is assigned to a cloud region at creation time. Ingestion endpoints, normalization workers, entity graph storage, AI inference endpoints, and backup storage all run within that region. No silent cross-border data movement.
Available deployment regions
| Region | Cloud | Status | Compliance notes |
|---|---|---|---|
| US East (N. Virginia) | AWS us-east-1 | GA | FedRAMP moderate (in progress) |
| US West (Oregon) | AWS us-west-2 | GA | ITAR-controlled data support |
| EU West (Ireland) | AWS eu-west-1 | GA | GDPR, EBA guidelines |
| EU Central (Frankfurt) | AWS eu-central-1 | GA | GDPR, DSGVO, BAIT |
| Asia Pacific (Sydney) | AWS ap-southeast-2 | GA | Australian Privacy Act |
| Asia Pacific (Tokyo) | AWS ap-northeast-1 | GA | APPI |
| UK South (London) | AWS eu-west-2 | GA | UK GDPR, FCA |
| Canada Central | AWS ca-central-1 | GA | PIPEDA, OSFI |
| GovCloud (US) | AWS us-gov-west-1 | Preview | FedRAMP High, ITAR |
What "data residency" covers end-to-end
Data residency in ManySignal covers the complete processing pipeline, not just storage. Ingestion API endpoints are served from the tenant's designated region. Normalization and enrichment workers run in-region. The entity graph database, event store, and audit log are all stored in-region. AI inference for triage and investigation uses model endpoints in the same region when available; fallback to a secondary in-region endpoint if the primary is unavailable.
Control-plane operations — authentication, billing, tenant provisioning — run from a global control plane in the US East region. If your requirements prohibit even control-plane data from leaving a specific geography, the self-hosted deployment option eliminates this.
Data sovereignty controls
Region-pinned at creation
A tenant's region is set at creation and cannot be changed without a formal migration process. No accidental cross-region data movement after provisioning.
Customer-managed encryption keys
Bring your own KMS key (AWS KMS, Azure Key Vault, GCP CKMS) for all data at rest. Key rotation triggers re-encryption of stored data. Key revocation renders stored data unreadable within minutes.
Cross-region replication controls
Backup replication to a secondary region is optional and must be explicitly configured. Secondary region must be in the same jurisdiction (e.g., EU → EU only).
Data transfer logging
Any data movement out of the primary region — backup replication, support access, diagnostic log shipping — is logged to the audit trail with destination, data type, and authorizing administrator.
Privacy field redaction
Fields designated as PII can be redacted or pseudonymized at ingestion time, before data is written to any store. Redaction policy is per-source, per-field, and auditable.
Deletion on demand
Tenant data deletion completes within 30 days of a deletion request, including all replicas and backups. A deletion certificate is issued with a hash of the final backup that was deleted.
Data Residency — FAQ
Does AI inference move data outside my region?
No. For GA regions, AI inference runs on model endpoints deployed in the same cloud region. We do not route inference requests to a central AI endpoint. For preview regions where in-region model endpoints are not yet available, a data processing addendum covers the temporary cross-region inference.
Can I verify that data stays in my region?
Yes. Network egress logs for the tenant infrastructure are available as a read-only data stream. You can configure a CloudWatch or equivalent alert on cross-region traffic from the tenant VPC.
What about support access?
Support access to tenant data requires customer authorization via a time-limited delegation token. The access session is recorded in the audit trail. No support engineer accesses tenant data without customer authorization.
Is there a data processing addendum for GDPR?
Yes. ManySignal's standard DPA covers all EU regions and is available for signature without a separate negotiation. EU tenant data processing is covered by standard contractual clauses where required.
Which GA regions are available for cloud-hosted tenants?
Current GA regions include AWS us-east-1 (US East), eu-west-1 (EU Ireland), eu-central-1 (EU Frankfurt), ap-southeast-1 (Singapore), ap-southeast-2 (Australia), and me-central-1 (UAE). Additional regions are available via self-hosted deployment. Check /platform/data-residency for the current availability map.
What happens to my data if I choose to leave ManySignal?
On contract termination, a full data export is delivered in JSON format before tenant deletion. Exports include all case records, evidence packages, audit logs, and entity graph snapshots. Deletion of all tenant data from ManySignal infrastructure is completed within 30 days and confirmed in writing.
Can we use customer-managed encryption keys (CMK)?
Yes. Enterprise tenants can supply their own AWS KMS customer-managed key. ManySignal uses your key for all encryption operations but never has access to the key material itself. Revoking the KMS key makes your data cryptographically inaccessible — a nuclear exit option some regulated customers require.
How does data residency work for sub-processors?
ManySignal's sub-processor list is published and updated at /legal/sub-processors. For region-pinned tenants, sub-processors that touch tenant data operate within the same region. EU customers receive a list of sub-processors covered by adequacy decisions or standard contractual clauses.
Is there a sovereign cloud option for government customers?
Yes. Government and public-sector customers can deploy on AWS GovCloud (us-gov-east-1) or Azure Government via the self-hosted deployment path. FedRAMP alignment documentation is available for US federal customers; contact the public-sector sales team for current authorization status.
Your data where your compliance requires it
Talk to the team about your specific residency requirements. Most needs are covered by an existing GA region.