Data Residency & Trust
Last updated: October 2026
1. How to read this page
This page exists to be quoted in a security review. Three rules govern everything below, and the third matters most.
- Section 5 lists what is held in your region.
- Sections 6 and 7 list what is not.
- The lists are closed. If a category of data is not named in section 5, it is not held in your region. We do not ask you to infer coverage from silence, and you should not accept a residency claim from any vendor — us included — that leaves you to.
We publish it this way because "available in the EU" is not a scope statement, and the gap between a region and a boundary is where security reviews go wrong.
2. Where your data lives today
Cevoriq operates 2 regions: US East (Virginia) (us-east-1), EU Central (Frankfurt) (eu-central-1). Each organization's records and files are stored in the single region chosen when that organization was created, and are not stored in any other. We say it this way rather than naming one country because, with more than one region open, a single-boundary claim would be true for some customers and false for others — and a security review needs to know which applies to them.
Storage is not the whole processing chain. Three providers process customer data outside that boundary and are named, with what each receives, in Section 5 of our Privacy Policy: identity and sign-in (Clerk), email delivery (Resend), and any AI provider your organization uses — which for Contract Intelligence receives the full contents of uploaded contract documents. Section 7 below sets out the complete list.
Which AI provider that is depends on you, and the difference matters. By default, AI features run on Cevoriq’s own provider account, so contract text reaches a third party we chose and we are the ones with a contract governing it. If instead you supply your own AI credentials — your Azure OpenAI deployment, your OpenAI, Anthropic or Google key, or your own AI gateway — that text goes to your provider under your agreement, and does not reach an AI provider of ours at all. On a Dedicated instance with your own credentials, contract content therefore stays inside a boundary you control end to end.
We state both cases because only one of them is true for any given customer, and which one is a setting rather than a property of the product. Nothing here is automatic: bringing your own provider is configured in Settings, and until it is, the default above applies.
3. Our region strategy: regions, not countries
Like other enterprise platforms (ServiceNow, Salesforce, Atlassian), Cevoriq offers regions, not per-country infrastructure. A region is a full data plane — its own database and file storage — and countries map onto regions: a German organization is served by an EU region, a UK organization by a UK or EU region. Most data-protection regimes (including UK and EU GDPR) do not require in-country storage; they require lawful handling, which a region plus the appropriate contractual mechanisms (adequacy, Standard Contractual Clauses, a Data Processing Agreement) satisfies.
New regions open on committed customer demand, not on a calendar. We deliberately do not publish dates: a region becomes available when a customer contract requires it and the full regional stack has been provisioned and verified. Until then it is listed below as planned — visible direction, no false promise.
4. Region availability
A region is offered only when we have recorded the decision to offer it as a reviewed change in our repository — not a setting anyone can switch on — and our automated checks fail if an offered region has no production database registered in our backup configuration. Each region is served by its own deployment, and an organization can be created in a region only where that region's database and file storage are both configured. Nothing sets an availability flag by hand, so a region we have not built cannot be offered to you by construction rather than by policy. This table is rendered from that reviewed configuration and reads the same on every Cevoriq deployment.
| Region | Identifier | Status |
|---|---|---|
| 🇺🇸 US East (Virginia) | us-east-1 | Available |
| 🇪🇺 EU Central (Frankfurt) | eu-central-1 | Available |
| 🇺🇸 US West (Oregon) | us-west-2 | Planned — opens on committed demand |
| 🇪🇺 EU West (Ireland) | eu-west-1 | Planned — opens on committed demand |
| 🇬🇧 UK (London) | eu-west-2 | Planned — opens on committed demand |
| 🇸🇬 Asia Pacific (Singapore) | ap-southeast-1 | Planned — opens on committed demand |
| 🇯🇵 Japan (Tokyo) | ap-northeast-1 | Planned — opens on committed demand |
| 🇮🇳 India (Mumbai) | ap-south-1 | Planned — opens on committed demand |
| 🇦🇺 Australia (Sydney) | ap-southeast-2 | Planned — opens on committed demand |
| 🇧🇷 Brazil (São Paulo) | sa-east-1 | Planned — opens on committed demand |
5. What is held in your region
Everything your organization creates in the product. This list is closed: see section 1, rule 3.
| Class | Includes | Where it lives |
|---|---|---|
| Operational records | Assets and asset lifecycle, incidents, dispatches, service definitions and SLA records, work items | Your region |
| Commercial records | Contracts, customers, vendors, orders, purchase orders, quotes and sourcing records, engagements, the unit ledger | Your region |
| Logistics records | Shipments, returns, RMAs, warehouse and stock records | Your region |
| Field Service records | Work orders and their tasks, checklists and checklist answers, and the labour, travel and parts recorded on a job; technicians, their skills, absences and assignments, including crews; bookings on the scheduling board and handovers between assignees; vehicles, their assignments and odometer readings; maintenance plans and visits; escalation rules and the escalations they raise; proof of service; partner-portal accounts and sign-in sessions; messages queued for a subcontractor's own system; and the push-notification subscriptions of technicians' phones | Your region |
| Documents & files | Contract documents, purchase-order attachments and every uploaded file | Your region (storage location recorded on every file at write time, so where a file lives is a fact in your data rather than an inference from configuration) |
| Your configuration | Compliance settings, your own AI provider credentials, integration settings and credentials, Field Service settings, holiday overrides | Your region |
| Derived data | Embeddings and extractions computed from the above | Your region |
| Activity and AI records | The audit trail of changes made in your organization, AI decisions and the reasoning recorded with them, conversations with the operational assistant, and saved reports | Your region |
How we can state this as a closed list. Every data model in the platform is classified as either global or regional in a single file, and a build-time check refuses an unclassified one rather than defaulting it to either side. Section 6 enumerates the global side completely, so everything not on that list is in your region by construction. We describe the mechanism because it is what lets this page close its lists honestly rather than aspirationally.
6. What is global by design
A small, enumerated set of records is held once, globally, rather than in any region. This list is complete. Apart from platform-published documents, the global records have no field designed to hold a contract, an asset record or a document, and the same build-time check refuses any reference from a global record into regional data. Platform-published documents are the exception: that store holds files, and what keeps your contracts out of it is a recorded declaration made by a Cevoriq platform administrator at upload, not a structural barrier. A few administrative notes written by Cevoriq staff (for example, the reason a document was withdrawn) are also held globally; the people writing them are told at the field not to enter customer information there.
| Category | What it is | Where it lives |
|---|---|---|
| Identity | Your people's names, email addresses and sign-in records (via Clerk, our identity provider) | Global |
| Memberships | Which person belongs to which organization, and in what role | Global |
| Platform registry | Organization name and region assignment, module entitlements, subscription facts | Global |
| Reference data | The master catalogue and jurisdiction holiday calendars — shared, owned by nobody | Global |
| Cross-organization links | The registry of links between organizations, their agreed metric scopes, and the approvals for them. A link spans regions by definition, so it cannot live inside one | Global |
| Consolidated reporting metrics | Pre-aggregated, whitelisted numbers only (counts and totals) — computed live, never stored; structurally unable to carry a person, serial number, or address | Global (in transit only; nothing retained) |
| Platform-published documents | Material Cevoriq publishes to organizations (e.g. group master agreements), declared non-resident at upload | Global, by declaration |
| Cevoriq's own billing lines | The aggregated figures Cevoriq invoices against | Global |
Access changes across regions
Because identity is global and your data is regional, a change to who may do what is made once and then has to reach the region your people are signed in from. Role changes, suspensions and access removals take effect immediately in the region where they are made. Sessions already signed in from another Cevoriq region keep their existing access for up to 1 minute before the change reaches them.
We state the number rather than describing it as instant, because it is not instant and a security review deserves the real figure. Actions that destroy data, move money, or change permissions are never served from a cached decision — those are always checked against the authoritative record at the moment they are taken.
7. Processing performed outside your region
Nothing here is an exception granted to us. Each is a deliberate architectural decision, stated so you can price the risk yourself.
| Function | What leaves your region | Retained where |
|---|---|---|
| Application compute | All request processing. Your data is stored in your region and processed in the United States. This applies to every region we offer today, including EU Central (Frankfurt): each region has its own deployment, and the compute behind every one of them currently runs in the United States | Not retained; processed in transit |
| Authentication | Sign-in is performed by Clerk in the United States. Choosing a region does not move it, and no setting available to you changes it today | Clerk's infrastructure, United States |
| Email delivery | Message content and recipient addresses for notifications you have configured | Delivery metadata retained by Resend outside your region |
| AI processing | Content you submit to AI features, including the full contents of uploaded contract documents for Contract Intelligence | Per your configured provider's terms |
| Server request logs | Standard request metadata collected by our hosting provider | Outside your region |
| Cached content | Transient caches held by our hosting and delivery layer | Outside your region |
| Database backups | Encrypted snapshots of your regional database. Where the snapshot is taken and kept depends on your region. For EU (Frankfurt), the backup is produced by compute inside the region and stored in an EU-jurisdiction bucket — it does not leave. For US (N. Virginia), the snapshot is encrypted and held in our CI provider’s storage in the United States, which is the same jurisdiction as the database | Encrypted; in-region for EU, United States for US |
| Support access | Cevoriq personnel may access your data to provide support, from outside your region | Not retained |
If you connect Cevoriq to a service-management system that serves users in more than one region, that integration necessarily moves data across regions. That is your instruction to us as your processor, and it is recorded as an explicit acknowledgement.
8. Storage residency vs. processing residency
Selecting a region governs where your data is stored at rest. Application compute may run outside your region — the same posture as most major SaaS platforms, whose support and operations are global. This is the first row of section 7 and the most consequential entry on this page. If your organization requires strict processing residency (data never leaving the region even transiently), raise it with us during contracting: it is a materially different commitment and we will tell you honestly whether we can meet it, rather than let a region label imply it.
9. Residency is not sovereignty
We offer residency. We do not claim sovereignty, and the distinction is not pedantry. Residency means data is stored in a stated location. Sovereignty means it is beyond the reach of another jurisdiction's legal process. Cevoriq is a United States company, and so are several of its providers, so storing data in a European region would not place it beyond US legal process. Any vendor telling you otherwise while operating under US ownership is describing residency and calling it sovereignty.
If your organization requires a signed Data Processing Agreement or specific transfer safeguards, ask us at legal@cevoriq.com. If your requirement is genuine sovereignty rather than residency, say so early: it is not a commitment we make today.
10. Bringing your own identity provider
Planned, and not available today. Federation needs a plan upgrade with our identity provider that we have not made, so no organization is using it at present. Like regions and customer-managed keys, it opens on committed demand; ask during contracting.
Once available, your organization federates its own directory (Microsoft Entra ID, Okta and other SAML or OIDC providers) for sign-in, configured by your own IT administrator. That gives you the credential check, your own multi-factor and conditional-access policies, and automatic provisioning and deprovisioning, so that disabling a person in your directory revokes their Cevoriq sessions.
It does not move authentication into your region, because our identity provider still brokers the exchange and holds the session. That is the honest limit of what federation buys you on our shared platform, and we would rather state it than let the feature imply more.
11. Encryption
- In transit: all traffic is encrypted with TLS.
- At rest: our database and file-storage providers encrypt all data at rest; integration credentials are additionally encrypted at the application layer before storage.
- Customer-managed keys (BYOK): planned as a paid option for organizations that need to hold their own encryption keys — the ability to revoke a key and render data unreadable to the platform. Like regions, this opens on committed demand; ask during contracting.
12. Retention and deletion
Deleting an organization is deliberately not instantaneous, and not a single click. It is a sequence with a pause in the middle, so that a deletion made in error — or disputed internally — can still be undone.
- You request deletion. The organization is locked immediately: members can no longer sign in or reach any data. Nothing is destroyed, and the request can be cancelled.
- A 90-day pause. Your data stays intact and inaccessible throughout. You may cancel at any point in this window and resume where you left off.
- Permanent deletion. After 90 days a member of our team performs the deletion deliberately — outside the evaluation exception below, we do not destroy customer data on an automatic timer. Your records, the documents you uploaded, and the database rows behind them are removed.
- Backups age out. Encrypted snapshots are not edited after the fact, because a backup that can be rewritten is not a reliable one. Deleted data therefore persists in them until the snapshot expires: at most 30 days for daily snapshots and 12 months for monthly ones. If we ever restore from a snapshot, deletions you requested in the meantime are re-applied as part of the restore.
The one exception: evaluation organizations. An organization set up as an evaluation, with a deletion window agreed for it, is deleted automatically. Once its evaluation period has ended and the agreed number of days has passed, it is permanently deleted without a member of our team acting and without the 90-day pause in step 2. A legal hold still stops it. This applies only to organizations designated as evaluations; no other organization is deleted this way.
Records we are required to keep. Some business records — the transaction ledger, contracts, invoices, and the audit trail — are retained for up to seven years to meet accounting and legal obligations, in the archive tier rather than in backups. This is a narrower set than “everything”: it does not mean we keep a copy of your whole database for seven years.
Legal holds override all of the above. Where a hold is in force, deletion stops — including automated expiry — and does not resume until the hold is lifted. Individual erasure requests are handled through the erasure workflow in Settings, subject to the same holds.
In build, and not yet available: the 90-day pause is currently enforced by process rather than by the product refusing early deletion; permanent deletion currently removes your account records and organization data, with removal of uploaded documents and regional database rows being extended to complete the sequence above; and snapshot expiry windows are being applied to storage. This paragraph will be removed when each is in place. We describe them here rather than omitting them because you are entitled to know the policy we are building to, and to hold us to it.
13. What we do not offer at all
Stated so it is not mistaken for something merely absent from the lists above.
- Relocating an organization between regions. Region is chosen once.
- In-country infrastructure. We offer regions, not countries — see section 3.
- A choice of where your directory records live. Designed, not yet built; all directory records are held in the United States today.
- Customer-managed encryption keys — planned, not available.
- Automated retention-schedule deletion. The retention period shown in Settings does not yet drive automatic deletion, and we will not present it as though it does. This is separate from the organization-deletion sequence in section 12, which is a response to a request you make rather than a schedule running on its own, and from the evaluation exception described there, which runs on the deletion window agreed for that evaluation rather than on a retention period.
14. Questions
Security reviews and residency questionnaires are welcome: privacy@cevoriq.com. Ask us to demonstrate isolation — that an organization in one region has no rows in another — and we will show you the result rather than describe it. If a claim on this page and the product ever disagree, the product is the truth and we would like to know.