Data Residency & Trust
Last updated: September 2026
1. How to read this page
This page exists to be quoted in a security review. Three rules govern everything below, and the third matters most.
- Section 5 lists what is held in your region.
- Sections 6 and 7 list what is not.
- The lists are closed. If a category of data is not named in section 5, it is not held in your region. We do not ask you to infer coverage from silence, and you should not accept a residency claim from any vendor — us included — that leaves you to.
We publish it this way because "available in the EU" is not a scope statement, and the gap between a region and a boundary is where security reviews go wrong.
2. Where your data lives today
All customer data on the Cevoriq platform is stored in the United States (). We say this plainly because it is the truth a security review needs first: Cevoriq operates a single region today, and no tenant's records or files are stored outside it.
Storage is not the whole processing chain. Three providers process customer data outside that boundary and are named, with what each receives, in Section 5 of our Privacy Policy: identity and sign-in (Clerk), email delivery (Resend), and any AI provider your organization uses — which for Contract Intelligence receives the full contents of uploaded contract documents. Section 7 below sets out the complete list.
3. Our region strategy: regions, not countries
Like other enterprise platforms (ServiceNow, Salesforce, Atlassian), Cevoriq offers regions, not per-country infrastructure. A region is a full data plane — its own database and file storage — and countries map onto regions: a German organization is served by an EU region, a UK organization by a UK or EU region. Most data-protection regimes (including UK and EU GDPR) do not require in-country storage; they require lawful handling, which a region plus the appropriate contractual mechanisms (adequacy, Standard Contractual Clauses, a Data Processing Agreement) satisfies.
New regions open on committed customer demand, not on a calendar. We deliberately do not publish dates: a region becomes available when a customer contract requires it and the full regional stack has been provisioned and verified. Until then it is listed below as planned — visible direction, no false promise.
4. Region availability
A region is offered only when three independent facts hold at once: reviewed intent recorded in our repository, a provisioned database, and a provisioned object store. These are combined server-side and nothing sets an availability flag by hand, so a region we have not built cannot be offered to you by construction rather than by policy. This table is rendered from that same derivation.
| Region | Identifier | Status |
|---|---|---|
| 🇺🇸 US East (Virginia) | us-east-1 | Planned — opens on committed demand |
| 🇺🇸 US West (Oregon) | us-west-2 | Planned — opens on committed demand |
| 🇪🇺 EU West (Ireland) | eu-west-1 | Planned — opens on committed demand |
| 🇪🇺 EU Central (Frankfurt) | eu-central-1 | Planned — opens on committed demand |
| 🇬🇧 UK (London) | eu-west-2 | Planned — opens on committed demand |
| 🇸🇬 Asia Pacific (Singapore) | ap-southeast-1 | Planned — opens on committed demand |
| 🇯🇵 Japan (Tokyo) | ap-northeast-1 | Planned — opens on committed demand |
| 🇮🇳 India (Mumbai) | ap-south-1 | Planned — opens on committed demand |
| 🇦🇺 Australia (Sydney) | ap-southeast-2 | Planned — opens on committed demand |
| 🇧🇷 Brazil (São Paulo) | sa-east-1 | Planned — opens on committed demand |
5. What is held in your region
Everything your organization creates in the product. This list is closed: see section 1, rule 3.
| Class | Includes | Where it lives |
|---|---|---|
| Operational records | Assets and asset lifecycle, incidents, dispatches, service definitions and SLA records, work items | Your region |
| Commercial records | Contracts, customers, vendors, orders, purchase orders, quotes and sourcing records, engagements, the unit ledger | Your region |
| Logistics records | Shipments, returns, RMAs, warehouse and stock records | Your region |
| Documents & files | Contract documents, purchase-order attachments and every uploaded file | Your region (storage location recorded on every file at write time, so where a file lives is a fact in your data rather than an inference from configuration) |
| Your configuration | Compliance settings, your own AI provider credentials, holiday overrides | Your region |
| Derived data | Embeddings and extractions computed from the above | Your region |
How we can state this as a closed list. Every data model in the platform is classified as either global or regional in a single file, and a build-time check refuses an unclassified one rather than defaulting it to either side. Section 6 enumerates the global side completely, so everything not on that list is in your region by construction. We describe the mechanism because it is what lets this page close its lists honestly rather than aspirationally.
6. What is global by design
A small, enumerated set of records is held once, globally, rather than in any region. This list is complete. The global column is not a policy exception — it is structurally incapable of holding your business data: its schemas have no field that could carry a contract, an asset record or a document, and the same build-time check refuses any reference from a global record into regional data.
| Category | What it is | Where it lives |
|---|---|---|
| Identity | Your people's names, email addresses and sign-in records (via Clerk, our identity provider) | Global |
| Memberships | Which person belongs to which organization, and in what role | Global |
| Platform registry | Organization name and region assignment, module entitlements, subscription facts | Global |
| Reference data | The master catalogue and jurisdiction holiday calendars — shared, owned by nobody | Global |
| Cross-organization links | The registry of links between organizations, their agreed metric scopes, and the approvals for them. A link spans regions by definition, so it cannot live inside one | Global |
| Consolidated reporting metrics | Pre-aggregated, whitelisted numbers only (counts and totals) — computed live, never stored; structurally unable to carry a person, serial number, or address | Global (in transit only; nothing retained) |
| Platform-published documents | Material Cevoriq publishes to organizations (e.g. group master agreements), declared non-resident at upload | Global, by declaration |
| Cevoriq's own billing lines | The aggregated figures Cevoriq invoices against | Global |
7. Processing performed outside your region
Nothing here is an exception granted to us. Each is a deliberate architectural decision, stated so you can price the risk yourself.
| Function | What leaves your region | Retained where |
|---|---|---|
| Application compute | All request processing. Your data is stored in your region and processed in the United States | Not retained; processed in transit |
| Authentication | Sign-in is performed by Clerk in the United States. Choosing a region does not move it, and no setting available to you changes it today | Clerk's infrastructure, United States |
| Email delivery | Message content and recipient addresses for notifications you have configured | Delivery metadata retained by Resend outside your region |
| AI processing | Content you submit to AI features, including the full contents of uploaded contract documents for Contract Intelligence | Per your configured provider's terms |
| Server request logs | Standard request metadata collected by our hosting provider | Outside your region |
| Cached content | Transient caches held by our hosting and delivery layer | Outside your region |
| Database backups | Encrypted snapshots of your regional database. The workflow that produces them executes outside your region | Encrypted, outside your region |
| Support access | Cevoriq personnel may access your data to provide support, from outside your region | Not retained |
If you connect Cevoriq to a service-management system that serves users in more than one region, that integration necessarily moves data across regions. That is your instruction to us as your processor, and it is recorded as an explicit acknowledgement.
8. Storage residency vs. processing residency
Selecting a region governs where your data is stored at rest. Application compute may run outside your region — the same posture as most major SaaS platforms, whose support and operations are global. This is the first row of section 7 and the most consequential entry on this page. If your organization requires strict processing residency (data never leaving the region even transiently), raise it with us during contracting: it is a materially different commitment and we will tell you honestly whether we can meet it, rather than let a region label imply it.
9. Residency is not sovereignty
We offer residency. We do not claim sovereignty, and the distinction is not pedantry. Residency means data is stored in a stated location. Sovereignty means it is beyond the reach of another jurisdiction's legal process. Cevoriq is a United States company, and so are several of its providers, so storing data in a European region would not place it beyond US legal process. Any vendor telling you otherwise while operating under US ownership is describing residency and calling it sovereignty.
If your organization requires a signed Data Processing Agreement or specific transfer safeguards, ask us at legal@cevoriq.com. If your requirement is genuine sovereignty rather than residency, say so early: it is not a commitment we make today.
10. Bringing your own identity provider
Your organization can federate its own directory (Microsoft Entra ID, Okta and other SAML or OIDC providers) for sign-in, configured by your own IT administrator. That gives you the credential check, your own multi-factor and conditional-access policies, and automatic provisioning and deprovisioning, so that disabling a person in your directory revokes their Cevoriq sessions.
It does not move authentication into your region, because our identity provider still brokers the exchange and holds the session. That is the honest limit of what federation buys you on our shared platform, and we would rather state it than let the feature imply more.
11. Encryption
- In transit: all traffic is encrypted with TLS.
- At rest: our database and file-storage providers encrypt all data at rest; integration credentials are additionally encrypted at the application layer before storage.
- Customer-managed keys (BYOK): planned as a paid option for organizations that need to hold their own encryption keys — the ability to revoke a key and render data unreadable to the platform. Like regions, this opens on committed demand; ask during contracting.
12. Retention and deletion
We do not currently advertise automated retention-based deletion, because we will not expose a retention setting before its enforcement exists. Deletion requests are honored through the erasure workflow in Settings, subject to legal holds. When automated retention enforcement ships, this page, the product, and the privacy policy will change together.
13. What we do not offer at all
Stated so it is not mistaken for something merely absent from the lists above.
- Relocating an organization between regions. Region is chosen once.
- In-country infrastructure. We offer regions, not countries — see section 3.
- A choice of where your directory records live. Designed, not yet built; all directory records are held in the United States today.
- Customer-managed encryption keys and automated retention deletion — both planned, neither available.
14. Questions
Security reviews and residency questionnaires are welcome: privacy@cevoriq.com. Ask us to demonstrate isolation — that an organization in one region has no rows in another — and we will show you the result rather than describe it. If a claim on this page and the product ever disagree, the product is the truth and we would like to know.