Data Residency
Where your data lives, how it moves, and why that matters for DORA, EIOPA, EU AI Act, and BaFin / BSI requirements.
๐ฌ๐ง UK (London) Residency
All primary customer data is stored and processed in Google Cloud region europe-west2 (London, United Kingdom).
For EU/EEA customers, EUโUK transfers are covered by the European Commission's adequacy decision for the UK.
The exceptions are listed explicitly below and in the sub-processor register โ we would rather list them than pretend there are none.
1. What is stored where
| Data category | Primary location | Backup location |
|---|---|---|
| Account data, billing | London (europe-west2); Stripe for payment data | โ |
| SSO identity (Google/Microsoft sign-in) | Firebase Authentication (Google) | โ |
| Agent submissions (endpoint configs, credentials sealed with Cloud KMS) | London (europe-west2) | โ |
| Audit transcripts, reports & certificates | London (europe-west2); audit prompts/responses are scored via the Google Gemini API | Daily automated database backups (same region) |
| Telemetry events | London (europe-west2) | Daily automated database backups (same region) |
| Model-evidence derivation (tenant-independent seed corpus โ no customer data) | Belgium (europe-west1, GPU service) | โ |
| Static assets (this website) | Cloudflare edge network | Cloudflare global edge |
2. What we see, plainly
- During an audit we send adversarial prompts to the endpoint you register and store the responses โ the transcript is the evidence behind the rating.
- Audit responses are evaluated by an LLM judge (Google Gemini API); those prompts and responses transit Google AI infrastructure.
- Telemetry you send via the SDK or website widget is stored as events; the widget sends message text for pathology analysis.
- Stored agent credentials are sealed with Google Cloud KMS and used only to run your audits.
3. Regulatory alignment
- DORA (Regulation EU 2022/2554) โ ICT third-party risk: single-provider posture documented on request; data export available.
- EU AI Act (Regulation EU 2024/1689) โ high-risk AI systems: EU-resident logs supporting Art. 12 record-keeping and Art. 14 human oversight.
- GDPR (Regulation EU 2016/679) โ Art. 44โ50: EUโUK flows under the UK adequacy decision; SCCs for the US-based providers named in the sub-processor register.
- BaFin BAIT / MaRisk โ for German financial-services customers: outsourcing notifications ready on request; Annex III sub-processor list.
- Solvency II โ for insurer customers: SCR operational-risk module supported with auditable evidence packs.
4. Enterprise options
- Customer-managed encryption keys (CMEK): bring-your-own-key via Google Cloud KMS.
- Single-tenant deployment: dedicated Google Cloud project in
europe-west2. - Private endpoint: Google Private Service Connect to your VPC.
- Sovereign cloud option: Google Cloud Sovereign Controls (S3NS for France, partner operator) โ roadmap Q3 2026.
5. Engineering & support access
Engineering and customer-support personnel are located in the United Kingdom. Access to production data is:
- Logged to an append-only audit trail (SHA-256 hash-chained);
- Gated through Google Cloud IAM with mandatory 2FA and session recording;
- Governed by the UK โ EU data-transfer mechanisms in the DPA (UK IDTA Addendum to EU SCCs).
6. Attestations & roadmap
- ISO 27001: not yet certified; planned.
- SOC 2 Type II: not yet certified; planned.
- ISO 42001 (AI management systems): internal self-assessment only; certification audit targeted for 2027. We hold no certification today.
- TISAX (automotive): on roadmap pending customer demand.
Version 2.0 ยท 2 September 2026