Data Residency & Multi-Region Support
Overview
The Agent Passport platform supports data residency workflows by allowing tenant data to be pinned to specific geographic regions. Compliance still depends on the customer's full control environment, policy configuration, and operational process.
Supported Regions
Currently Available
- US (United States): Default region, fully operational
- EU (European Union): Available for enterprise pilots
- CA (Canada): Available for enterprise pilots
Additional Regions
- AP (Asia Pacific): Available by enterprise agreement
- AU (Australia): Available by enterprise agreement
- BR (Brazil): Available by enterprise agreement
Private Instances
- Custom Regions: Available for enterprise customers with specific residency requirements
- Private Deployments: Available by enterprise agreement for privacy-sensitive or isolated environments
Data Residency Model
What Data is Region-Pinned
- Passport Data: Passport metadata and configurations for the selected region
- Organization Data: Tenant information and settings for region-pinned organizations
- Decision Events: Policy evaluation records for the selected region
- Attestations: User and organization attestations for region-pinned tenants
- Verifiable Attestation: Verifiable attestation records associated with region-pinned tenants
What Data is Global
- Agent Routing: Agent ID to region mapping (for performance)
- Public Keys: Registry public keys (for verification)
- Rate Limiting: Global rate limit counters (for DDoS protection)
Technical Implementation
Database Isolation
Each region has its own:
- D1 Database: SQLite database for tenant data
- KV Store: Key-value store for caching and routing
- R2 Bucket: Object storage for backups and large files
Cross-Region Operations
- Verification: Can verify agents across regions
- Audit: Cross-region audit queries supported
- Webhooks: Can trigger webhooks across regions
Compliance & Security
Data Protection
- Encryption: All data encrypted at rest and in transit
- Access Control: Region-specific access controls
- Verifiable Attestation: Comprehensive Verifiable Attestation per region
Regulatory Compliance
- GDPR: EU region supports GDPR evidence and residency workflows
- CCPA: US region supports CCPA evidence workflows
- PIPEDA: CA region supports Canadian privacy evidence workflows
Enterprise Features
Private Instances
- Dedicated Infrastructure: Private deployment topology by enterprise agreement
- Custom Domains: Your own domain for API endpoints
- Custom Branding: White-label passport verification
- SLA Terms: contract-backed SLA terms for enterprise deployments
Migration Support
- Data Export: Export all tenant data in standard formats
- Region Migration: Move tenants between regions
- Backup & Restore: Full backup and restore capabilities
Getting Started
For Developers
- Choose Region: Select appropriate region during tenant creation
- Configure Bindings: Set up region-specific environment variables
- Test Verification: Verify agents work across regions
For Enterprise
- Contact Sales: Reach out for private instance setup
- Compliance Review: Review data residency requirements
- Custom Configuration: Set up region-specific configurations
API Reference
Region Selection
# Create tenant in EU region
POST /api/tenants
{
"name": "Acme Corp",
"region": "EU",
"compliance_level": "enterprise"
}
Region Information
# Get available regions
GET /api/regions
# Get region details
GET /api/regions/EU
Support
For questions about data residency or multi-region support:
- Documentation: aport.io/docs
- Support: [email protected]
- Enterprise: [email protected]