← Trust center

Data residency

An honest posture, not a marketing flyer. Where data is stored and where it is processed are separate questions, so this page answers them separately: the database, LLM inference, application hosting and third-party services. The per-organization view is returned by the /api/v1/compliance/data-residency endpoint.

Database

Verified 2026-09-23

eu-central-1 (Frankfurt, Germany)

Transformics production data is hosted in a Supabase/Postgres environment in eu-central-1 (Frankfurt).

LLM inference

Implemented, live verification pending

AWS Bedrock EU inference profiles, source eu-west-1

Production LLM inference uses Anthropic Claude through EU Bedrock inference routing.

Application hosting

Not published

Region not yet published

The hosting region of the application tier (web front end and API servers) has not been published yet. It is separate from the database and LLM inference regions.

Third-party services

Not all EU-only

Listed per sub-processor

Other services, such as payments and email delivery, are listed individually with their own processing locations. Not all of them are EU-only.

Database (every organization)

Transformics production data is hosted in a Supabase/Postgres environment in eu-central-1 (Frankfurt). Every organization, on every plan, uses this one shared multi-tenant production database, isolated per organization by row-level security. There is no separate US database and no US default tier.

The compliance API reports this state as residency_status: "default_shared". The database region says nothing about where LLM inference runs or where the application is hosted; those are covered below.

LLM inference, EU routing by default

Production LLM inference uses Anthropic Claude through EU Bedrock inference routing. Every LLM call, for every organization and plan, is sent to Anthropic Claude on AWS Bedrock through an EU cross-region inference profile called from eu-west-1 (Ireland). AWS routes these requests only to Regions in EU member states: Frankfurt, Stockholm, Milan, Spain, Ireland and Paris.

  • There is no direct Anthropic API path and no US or global fallback. If the EU route is unavailable, the AI feature returns an error instead of sending the request elsewhere.
  • Before a request leaves Transformics, the names the platform knows about, your own sensitive terms and detected contact details are replaced with placeholders, and the request carries no organization, user or profile identifier. Administrators can also switch off AI reading of uploaded documents and of survey free text.
  • The llm_calls audit table records the model and the routing region of every call and keeps only a sha256 hash of the prompt.
  • How Amazon Bedrock and Anthropic handle prompts and completions (retention, abuse monitoring, access by the model provider) is governed by their terms and is under legal review; this page makes no claim about it.

Status: enforced in the application and covered by automated tests; verification against the live production AWS account is still pending. This section covers where LLM inference runs only. It is separate from the database region.

Pilots, EU LLM routing by default

Pilot organizations use the same production database in eu-central-1 (Frankfurt) and the same EU LLM routing (AWS Bedrock, source eu-west-1) as every other organization. The compliance API reports some pilot organizations as residency_status: "pilot_eu_routing"; the label is historical and does not change where data is stored.

Per-organization region election

The organization record can store a region election (supabase_region), and the compliance API reports it as residency_status: "elected". Today the election is recorded metadata only.

There is no dedicated per-region database project, so an election does not move data: the organization's data stays in the production database in eu-central-1 (Frankfurt). Separate regional projects would require customer-specific enterprise configuration.

Application hosting

The web front end and API servers are a separate component from the database and LLM inference. Their hosting region has not been published yet and is not implied by the database or LLM region. It will be listed here once confirmed.

Third-party services

Payments, email delivery and other supporting services are run by the sub-processors listed on /legal/subprocessors, each with its own processing location. Not all of them are EU-only, and this page does not claim that they are.

What we don't currently support

  • Physical project-level separation per region. Roadmap item. The per-organization region election is metadata only today; dedicated regional database projects are operational work that would be scoped for Enterprise customers on request.
  • Turkey-region (TR) data residency. The database is in Frankfurt (eu-central-1) and LLM inference uses EU Bedrock routing; neither has a Turkey-region option. AWS Bedrock does not currently offer the Claude model families in an Istanbul region. The KVKK regulatory track is supported in assessment content (sovereign-AI readiness module + KVKK summary in the CISO pack).
  • A published application-hosting region. See Application hosting above.
  • IP-block-list collaborator gating. Best-effort logging today (Accept-Language + IP-derived country); strict jurisdiction enforcement is a roadmap item.

External-collaborator region pinning

When an org has recorded a region election, the admin must tick a cross-region acknowledgement before any external collaborator can be invited. At acceptance time, the inviting org's recorded region is stamped immutably on the invitation row (region_at_accept) and an audit-log row is written with actioncollab.cross_region_accept.

Backups (point-in-time-recovery)

Database backups follow a 30-day point-in-time-recovery window. After a DSAR erasure request completes, the in-place PII anonymization propagates to backups within that window. Backup-residual data is not separately accessible and is purged on the PITR rolling window. Survey free text, evidence files and the sensitive-terms list stay encrypted with the organization's key; backups keep that encrypted data and the wrapped key for the same window.

Data-residency FAQ

Where is customer data stored?

Transformics production data is hosted in a Supabase/Postgres environment in eu-central-1 (Frankfurt). All organizations share this one multi-tenant production database, isolated per organization by row-level security. There is no separate US database tier.

Where does LLM inference run?

For every organization and plan, LLM inference runs on Anthropic Claude through AWS Bedrock using EU cross-region inference profiles, called from eu-west-1 (Ireland). AWS routes these requests only to Regions in EU member states (Frankfurt, Stockholm, Milan, Spain, Ireland, Paris). There is no direct Anthropic API path and no US or global fallback: if the EU route is unavailable, the AI feature returns an error instead. This routing is enforced in the application and covered by automated tests; verification against the live production AWS account is still pending. It is separate from where the database is hosted.

Is all processing in the EU?

Not every component. The production database is in Frankfurt (eu-central-1) and LLM inference is routed only to AWS EU Regions. The hosting region of the application tier has not been published yet, and some third-party services, such as payment processing, are not EU-only. Each sub-processor and its location is listed on /legal/subprocessors.

What does a per-organization region election do?

The organization record can store a region election, and the compliance API reports it. Today the election is metadata only: there is no separate per-region database project, so it does not move data. Every organization's data stays in the production database in eu-central-1 (Frankfurt).

Can customers require Turkey/TR regional hosting today?

No. The production database is in Frankfurt (eu-central-1) and LLM inference uses EU Bedrock routing; neither has a Turkey-region option. AWS Bedrock does not currently offer the Claude model families in an Istanbul region. The KVKK regulatory track is supported for assessment content; see /compliance for the KVKK posture.

Need a region we don't list?

Customer-specific enterprise configuration may be required. Email compliance for a residency assessment.

compliance@transformics.ai