Data Residency & Multi-Region Support

Overview

The Agent Passport platform supports data residency workflows by allowing tenant data to be pinned to specific geographic regions. Compliance still depends on the customer's full control environment, policy configuration, and operational process.

Supported Regions

Currently Available

  • US (United States): Default region, fully operational
  • EU (European Union): Available for enterprise pilots
  • CA (Canada): Available for enterprise pilots

Additional Regions

  • AP (Asia Pacific): Available by enterprise agreement
  • AU (Australia): Available by enterprise agreement
  • BR (Brazil): Available by enterprise agreement

Private Instances

  • Custom Regions: Available for enterprise customers with specific residency requirements
  • Private Deployments: Available by enterprise agreement for privacy-sensitive or isolated environments

Data Residency Model

What Data is Region-Pinned

  • Passport Data: Passport metadata and configurations for the selected region
  • Organization Data: Tenant information and settings for region-pinned organizations
  • Decision Events: Policy evaluation records for the selected region
  • Attestations: User and organization attestations for region-pinned tenants
  • Verifiable Attestation: Verifiable attestation records associated with region-pinned tenants

What Data is Global

  • Agent Routing: Agent ID to region mapping (for performance)
  • Public Keys: Registry public keys (for verification)
  • Rate Limiting: Global rate limit counters (for DDoS protection)

Technical Implementation

Database Isolation

Each region has its own:

  • D1 Database: SQLite database for tenant data
  • KV Store: Key-value store for caching and routing
  • R2 Bucket: Object storage for backups and large files

Cross-Region Operations

  • Verification: Can verify agents across regions
  • Audit: Cross-region audit queries supported
  • Webhooks: Can trigger webhooks across regions

Compliance & Security

Data Protection

  • Encryption: All data encrypted at rest and in transit
  • Access Control: Region-specific access controls
  • Verifiable Attestation: Comprehensive Verifiable Attestation per region

Regulatory Compliance

  • GDPR: EU region supports GDPR evidence and residency workflows
  • CCPA: US region supports CCPA evidence workflows
  • PIPEDA: CA region supports Canadian privacy evidence workflows

Enterprise Features

Private Instances

  • Dedicated Infrastructure: Private deployment topology by enterprise agreement
  • Custom Domains: Your own domain for API endpoints
  • Custom Branding: White-label passport verification
  • SLA Terms: contract-backed SLA terms for enterprise deployments

Migration Support

  • Data Export: Export all tenant data in standard formats
  • Region Migration: Move tenants between regions
  • Backup & Restore: Full backup and restore capabilities

Getting Started

For Developers

  1. Choose Region: Select appropriate region during tenant creation
  2. Configure Bindings: Set up region-specific environment variables
  3. Test Verification: Verify agents work across regions

For Enterprise

  1. Contact Sales: Reach out for private instance setup
  2. Compliance Review: Review data residency requirements
  3. Custom Configuration: Set up region-specific configurations

API Reference

Region Selection

# Create tenant in EU region
POST /api/tenants
{
  "name": "Acme Corp",
  "region": "EU",
  "compliance_level": "enterprise"
}

Region Information

# Get available regions
GET /api/regions

# Get region details
GET /api/regions/EU

Support

For questions about data residency or multi-region support: