Does CueCrux offer data residency options?

Explainer

Does CueCrux offer data residency options?

Choose where your data lives to meet regulatory requirements

Data residency is a critical concern for organisations operating under data protection regulations that restrict where personal or sensitive data can be stored and processed. CueCrux provides configurable data residency options to help you meet these requirements.

The challenge that data residency addresses is straightforward but has complex implications. Many regulations, including GDPR, various national data protection laws, and industry-specific frameworks, restrict the geographic transfer of certain types of data. If your organisation is subject to GDPR and you store documents containing personal data of EU residents, those documents may need to remain within the EU. If you are subject to data sovereignty requirements in a specific country, your data may need to stay within that country's borders.

CueCrux operates infrastructure in multiple geographic regions. When you configure data residency for your organisation, you specify which region or regions your data should be stored in. This setting applies to everything: uploaded documents, generated embeddings, search indexes, answers, receipts, audit logs, and user account data. All processing also occurs within the specified region. When you run a search, the computation happens in the region where your data resides, and the results do not leave that region's infrastructure.

The available regions include the European Union, the United States, the United Kingdom, Asia-Pacific, and additional regions that are being added based on customer demand. For enterprise customers with specific geographic requirements, CueCrux can discuss dedicated infrastructure in particular countries.

Configuring data residency is an organisational-level setting. Once set, it applies to all workspaces within the organisation. This ensures consistency. You do not need to worry about individual team members inadvertently storing data in the wrong region. The organisational policy enforces the residency requirement uniformly.

For multinational organisations, CueCrux supports multi-region configurations. You can create workspaces that are pinned to specific regions. For example, your EU team's workspace stores all data in the EU region, while your US team's workspace stores data in the US region. Cross-region search is available but operates under strict controls. Queries can be sent across regions, but the results are assembled within the requesting workspace's region, and full document content does not cross regional boundaries. Only receipts and answer summaries flow between regions, with the underlying evidence remaining in its home region.

Data residency interacts with several other CueCrux features. For Domain Watches, the monitored content is fetched and stored within your specified region. For proof links, the answer and its receipts are served from infrastructure in the appropriate region. For audit logs, all logging occurs within the region. For SSO, the authentication flow can be configured to use identity provider endpoints within the region.

The technical implementation of data residency goes beyond simply choosing a data centre location. CueCrux uses region-specific encryption keys managed by the region's key management service. This means that even at the encryption layer, your data is sovereign to the specified region. Network routing is configured to prevent data from traversing outside the region during processing. Regular audits verify that data residency commitments are being maintained.

For organisations that need formal assurance of data residency compliance, CueCrux provides data processing agreements that specify the applicable region, the types of data covered, the processing activities performed, and the technical and organisational measures in place to maintain residency. These agreements can be tailored to reference specific regulations and can be reviewed by your legal team before deployment.

Data residency also affects how CueCrux handles its own operations. Backup and disaster recovery copies of your data remain within the specified region. Infrastructure maintenance and support activities are conducted by personnel with appropriate clearances for the region. System logs that might incidentally contain customer data are retained within the region.

It is worth noting that data residency applies to your private data, meaning your uploaded documents, your search queries, your answers, and your audit logs. CueCrux's public knowledge base, which contains information from publicly available sources, is a shared resource that is not region-specific. However, when public knowledge is used to answer your queries, the answer assembly and receipt generation occur within your specified region.

Data residency is available on enterprise plans and is configured during the initial deployment setup. Changing the data residency region after deployment is possible but involves a data migration process, so it is best to set the correct region from the start.