One region, and you can't choose it
If a contract requires customer data to stay inside a particular jurisdiction, we can’t meet it today. That’s the whole answer, and it’s at the top so you don’t have to read the rest.
Component by component
Where each thing sits
| Component | Where it lives | Leaves the region? |
|---|---|---|
| The database | Managed Postgres, one region. Workspaces, assistants, conversations, contacts, knowledge. | No |
| Compute | The API and background workers, one region. Processed in memory only. | No |
| Uploaded files | Object storage on a provider whose network is global by design. | Yes |
| The web surfaces | This site and the dashboard, from an edge network. No conversation content stored there. | Yes, HTML only |
| Model providers | The retrieved passages and the visitor's message, on every answered message. | Yes, every message |
The last row decides most reviews, and it’s inherent to the product rather than a setting. What each provider receives is on subprocessors.
Worth knowing
What's true, and what's available instead
Answering is a transfer
Answering sends content to a model provider, which is a cross-border transfer whatever else is true. There's no option to run inference in a region you nominate.
Not training data
Your content isn't used to train models — by us, or by the providers under the terms we hold with them.
A DPA and a published list
A signed data processing agreement and a subprocessor list that changes when the product does.
Deletion on request
Workspace data can be deleted from the primary database and object storage.
Residency requirements are worth telling us about even if you decide against us — security@integrable.cloud. Demand is what gets a region built.