Compliance

Data Residency Controls

Data residency policies pin tenant secrets, recordings, and audit events to a specific geographic region (US, EU, APAC, or customer-specified). KMS keys are provisioned in-region, storage buckets are locked to the region, and cross-region replication is disabled. Requests originating outside the allowed region can be blocked (enforce mode) or logged for investigation (audit mode).

Violations -- an access attempt from a disallowed region, or a storage operation that would write data out of region -- are tracked in a dedicated residency violations log and surface on the compliance dashboard. Each tenant can have independent residency settings.

Data Residency Controls screenshot

Key Configuration

  • Allowed regions (US, EU, APAC, custom)
  • Enforcement mode (enforce, audit)
  • Per-workspace residency override
  • Violation alert recipients
All documentation Question about this? Talk to us