VeridentiDocs
ChangelogFor BusinessContact
Docs Admin guide Data residency

Data residency

Pin your organization's encrypted vault data to a specific region — and control it at the org, group, or user level.

How it works

Every vault's ciphertext is stored in exactly one region's storage. Routing is fail-closed — if a region isn't available, writes are refused rather than stored in the wrong place. Data is never silently moved across borders. Everything stored is zero-knowledge ciphertext; Veridenti never sees vault contents.

Finding your way around

The Data Residency screen is organized into three tabs:

Where new data lands: org, group, or user defaults

A vault's region is resolved in this order — user default → group default → organization default → global:

Business plans include Global, EU, and US zones; per-country zones require Enterprise.

New vault needs a region 1 · User default Members → Region (no SSO needed) highest priority if not set ↓ 2 · Group default Data Residency → Default Region by Group if not set ↓ 3 · Organization default Data Residency → Organization Default Region if not set ↓ 4 · Global the built-in fallback fallback
A new vault's region is resolved top-down — the first level that has a region set wins. Existing data moves only via Move a Vault.

Available regions

Global, EU, and US today; per-country residency (Canada, UK, Germany, France, Australia, Singapore, India, Japan, and more) on an Enterprise contract. EU-member countries are covered at the EU level by the EU zone.

Moving data that already exists

Setting a default only affects new vaults. To relocate data that already exists, use Move a Vault Between Regions on the Migrations tab: Veridenti copies the ciphertext to the target region zero-knowledge (never decrypted), flips the region pointer only after every item has copied, then purges the source. It is fail-safe — a mid-copy failure leaves the vault intact on the source — and every move is audited.

Compliance reporting

The Residency Compliance table (on the Migrations tab) records every migration — source, destination, item count, and whether the source purge completed or left anything to remediate — read from the tamper-evident audit log. You can re-run a purge from the same table if a former source needs re-cleaning.

Residency vs. sovereignty

Storing data in a country (residency) is different from being immune to foreign law (sovereignty). For strict sovereign regimes (e.g., France SecNumCloud, some German public-sector requirements), Veridenti can target a sovereign provider — and because Veridenti is zero-knowledge, even a legal request in another jurisdiction yields only ciphertext no one can decrypt. That last property is often the strongest control of all.

Availability & disaster recovery

Region-pinning affects durability and availability. See the Continuity & disaster recovery guide for how pinned data rides out an outage — offline-first access, platform redundancy, and in-jurisdiction DR replicas — and use the Continuity & DR tab for live per-region status, replica health, RPO/RTO targets, and Break-Glass.

What if…

Last updated August 26, 2026 · Docs v1.3
Enter to open · Esc to close
Veridenti