CogniveilDemo

Trust · Data residency

Data residency

For a regulated organization, a correct answer stored in the wrong jurisdiction can still be a violation. That is why residency in Cogniveil is a property of your tenant, decided before anything is provisioned, and held across every channel and workflow. It is not a setting someone can quietly change later.

Where your data lives is part of compliance

There is no single answer to "where is my data". There are four, depending on how you deploy.

Cloud account or physical machine, the boundary comes first

Storage is only one part of residency. The processing runtime, model path, indexes, workflow state, audit record, backups, and recovery environment must follow the same decision.

Region-pinned operations

Managed cloud

A dedicated Cogniveil tenant is operated on AWS or Microsoft Azure in the region agreed before provisioning.

AWSMicrosoft Azure

Residency boundary

What stays together

  • Source documents and indexes
  • Workflow state and audit records
  • Encrypted backups and disaster recovery

Cogniveil operates the environment. The selected region sets the residency boundary.

The provider does not decide residency. The selected architecture, region, and network boundary do.

Managed cloud: pinned to a region

In a managed deployment, your tenant is pinned to one residency region:

  • EU. Storage and processing in the European Union. Model inference respects EU residency too, confirmed at the infrastructure level, so using frontier models through the platform does not move regulated data out of region.
  • UK. UK residency for UK-regulated organizations.
  • Saudi Arabia. In-Kingdom storage and processing for Saudi data sovereignty requirements, often paired with on-premises components. Document intelligence, including Arabic, runs in-Kingdom in containers.

Backups and disaster recovery replicas stay inside the same jurisdiction as the tenant they protect, encrypted, so resilience never becomes the reason data left the region.

On premises: the data never leaves your environment

Deployed on your own hardware or as a managed appliance inside your data center, the platform runs where your documents already are. Nothing is stored outside your environment, and we are not the data processor, because there is no data exchange to process. Air-gapped operation is supported for the most sensitive environments.

In your tenant: your cloud, your boundary

Deployed inside your own cloud tenancy, data stays within the boundary your organization already governs, under your own residency commitments with your cloud provider.

Which answer is yours

The residency decision is one of the first decisions in an engagement, alongside deployment model and tenancy. We confirm it during discovery, before provisioning, together with hosting, network policy, and language requirements for document processing.

Get the security pack

Evidence for your review

Get the security pack

For security reviewers and vendor risk teams. The pack contains the four ISO certificates with their full scope statements, the architecture diagrams, and the data processing agreement. The Statement of Applicability is included in the pack; it is not published on the site.

Submitted details are used to respond to this request.