Skip to content
Compliance

EU data residency, as architecture rather than a setting

Sessions run on our own bare-metal hardware at OVHcloud inside the EU. There is no region dropdown, because there is nowhere else for the data to go.

Why a region setting is not residency

The question is who the counterparty is


A US-incorporated provider is subject to the CLOUD Act regardless of which datacentre serves the request. That is why a European buyer's data-protection review asks about the vendor, not the region.

One operator, one jurisdiction


Our infrastructure sits with OVHcloud, one of the winners of the April 2026 EU sovereign-cloud tender that excluded AWS on CLOUD Act grounds. The tender itself is the clearest statement of what European procurement now means by sovereign.

Short retention by default


Session replays carry a hard TTL measured in days, not months. Data you never keep is data that cannot be disclosed, subpoenaed or leaked.

Encrypted per tenant


Profiles and credentials are encrypted with per-tenant keys under a root key held in a European KMS, never on the host that runs the browsers.

What is processed and where

Session execution OVHcloud bare metal, EU
Databases and cache Same host, loopback-only, not reachable from a session container
Artifacts and replays OVH Object Storage, EU
Encryption root key European KMS, never stored on the session host
Default session locale de-DE, Europe/Berlin
Sub-processors Published list, EU-based

As of 2026-08-30

Questions people actually ask

Do you offer a DPA?

Yes. A data processing agreement under Article 28 GDPR, alongside a sub-processor list and the technical and organisational measures your review will ask for.

Is this an isolation claim as well as a residency claim?

No, and the distinction matters. Sessions run in hardened containers with user-namespace remapping, dropped capabilities, seccomp, AppArmor and a default-drop network policy. That is strong isolation, but it is not kernel-level isolation. MicroVM isolation is a later phase, and we will not describe it as shipped before it is.

What about the models? Do prompts leave the EU?

Today you bring your own model keys, so that is your routing decision, not ours. An EU-routed inference gateway with a sovereign tier is on the roadmap; until it ships we would rather you knew exactly where your prompts go than assume we handled it.

Are you certified?

An ISO 27001 programme is scoped and BSI C5 is a later objective. Neither is complete today. We publish the roadmap rather than implying attestations we do not hold.

Bring the compliance questionnaire

Most evaluations start with a data-protection review. Book a call and bring yours; we would rather answer it early than late.