Skip to main content

Boardroom Answers · Revenue & Global · Global Enterprise Delivery

You pitch India-first, but where does my data actually live? If the answer is not India, why should a GCC governed by DPDP touch you?

The question a GCC Head / VP of Global Delivery asks.

The short answer

Tokyo today, and our code physically prevents claiming otherwise. Mumbai and Frankfurt cells are built and config-activated — provisioned on request for Enterprise, with org migration between cells already implemented.

The full executive answer

The straight answer: today, production data lives in AWS Tokyo — ap-northeast-1 — and I will not pretend otherwise, because our own code forbids it. The architecture is multi-region by organisation pinning: every customer org lives in exactly one region cell, cross-region queries are impossible by construction, and an India cell — AWS Mumbai, ap-south-1 — plus an EU cell in Frankfurt are fully coded, activating on configuration alone with zero code change. There is even a guard function that makes it architecturally impossible for marketing to claim residency in a region until that region’s infrastructure is genuinely live, and another that prevents an org ever being recorded as pinned to a non-live region. Honesty about residency is a compile-time property of this product.

On the legal question: DPDP as it stands does not mandate blanket data localisation — it restricts transfers only to government-blacklisted jurisdictions, and Japan is not one. So a GCC can adopt us today lawfully, with our DPA, PII redaction before any model call, and the Compliance Evidence Vault, which explicitly covers India DPDP alongside the EU AI Act. Where a customer’s internal policy or sectoral regulator — say RBI-adjacent entities — demands Indian residency, the honest path is: the Mumbai cell is provisioned on request as part of an Enterprise engagement, and an org-migration path between cells is already built.

What I will not do is what this market is full of — vendors who say "yes, resident in India" and mean a CDN edge. Ask your next three vendors to show you the code that stops their own marketing from overclaiming residency. That artifact is my differentiation on this question.

Grounded in: Data-residency-by-design (region-cell architecture per jurisdiction); DPDP transfer-restriction analysis rather than localisation folklore.

Want this answered live, on your data?