Data residency
Where data lives, how region is chosen, what crosses a border and why the decision has to be made before provisioning rather than after.
Last updated 23 July 2026 · Trust Center
1. Hosting
All environments — production and non-production — run on Microsoft Azure. Azure is a constant in the subprocessor register and applies to every deployment.
2. Choosing a region
Region is a configurable property of a deployment and is recorded on the order form. The inputs are usually your regulator’s expectations, your own data-protection commitments to your customers, and where your users are. If you have a residency constraint, raise it before provisioning.
3. What crosses a border
Three categories behave differently and a reviewer will ask about each separately.
| Category | Behaviour |
|---|---|
| Tenant records — parties, accounts, positions, movements, documents | Held in the region configured for the deployment |
| Operational telemetry | Aggregated and de-identified; does not identify you or your end users |
| Support and notification traffic | May involve a subprocessor in another region — SMS and telephony are delivered by Twilio for every deployment |
4. Transfer mechanisms
Where a transfer requires a mechanism, we implement an appropriate one, including standard contractual clauses where applicable, with any supplementary measures the circumstances require. Clause 10 of the DPA is the contractual expression of this.
5. Changing region later
Said plainly because the honest answer is more useful than the comfortable one: changing region after data exists is a migration, not a setting. It involves downtime, a cutover plan and a reconciliation, and for a regulated institution it involves telling your regulator. Choose the region at provisioning.
6. Subprocessor regions
Each entry in your completed Exhibit C records the subprocessor, its role and its region, so residency can be assessed across the whole chain rather than only at the hosting layer. Request it from legal@a8core.com.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice. Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.