Envelope

Data Residency & Hosting

Where your data lives today, and where it's going — including regional hosting and private cloud options for teams with strict data sovereignty requirements.

Current hosting

Envelope currently runs on managed infrastructure in the United States (us-east-1). This includes:

  • API server and security proxy
  • PostgreSQL database (team definitions, credentials vault, run events, billing records)
  • Frontend static assets via CDN

Transactional emails are delivered via Resend (US-East). Analytics are processed by Plausible (EU), which collects no personal data.

A full list of sub-processors and data transfer mechanisms is available in the Data Processing Agreement.

Region selection

We are building support for customer-selectable hosting regions. This will allow organisations to pin their data — team definitions, credentials, and run events — to a specific geographic region.

Planned regions:

  • United States (us-east-1) — current default
  • European Union (eu-west) — roadmap
  • Additional regions based on demand

Region selection is particularly relevant for organisations subject to GDPR, UK GDPR, or sector-specific data localisation requirements (financial services, healthcare, legal). If your organisation has a hard data residency requirement today, contact us — we can discuss options on a case-by-case basis.

Note: Region selection affects where your data is stored and processed. The Envelope schema itself — the open standard — is not affected by region selection. Your team definitions remain portable across any deployment.

Private cloud / BYOC

For organisations that require Envelope to run entirely within their own cloud environment, we are developing a Bring Your Own Cloud (BYOC) deployment option. This allows you to run the full Envelope stack — API server, security proxy, and database — inside your own AWS, Azure, or GCP tenant.

With BYOC:

  • No data leaves your cloud perimeter
  • Your infrastructure team controls access, networking, and compliance
  • Encryption keys remain under your control
  • Envelope provides software updates and support; you manage the deployment

BYOC is designed for larger organisations where data sovereignty is a hard procurement requirement. It will be available as a custom enterprise arrangement. If this is a requirement for your organisation, get in touch early — we can factor your needs into our delivery timeline.

Schema & versioning

The Envelope Team Definition Schema is an open standard. Your team definitions are fully portable — they are not tied to any specific region or deployment of Envelope. Whether you use the hosted service, a regional deployment, or a private cloud instance, the same schema version applies.

Data residency changes are implemented as additive infrastructure configuration — they do not require schema version bumps and do not affect compatibility with third-party platforms (Paperclip, Relevance AI, Bedrock, etc.).

See the schema reference for versioning details.

Discuss your requirements

If you have specific data residency, compliance, or private cloud requirements, email [email protected]. We are happy to discuss your situation and provide written commitments where we can.