Data residency & data flow
An explicit, scannable statement of where your data is stored, where it is processed, the entity that controls it, and the basis for every cross-border hop. No implicit answers.
Last updated 27 June 2026
Where your data lives
Permafrost is operated by DuneCodeForge Ltd, incorporated in the United Arab Emirates, which is the data controller. The Service runs on managed infrastructure; the table below states each layer, its location, and the legal basis that covers any cross-border transfer.
| Layer | Location | Transfer basis |
|---|---|---|
| Controller entity | DuneCodeForge Ltd — United Arab Emirates | Data controller under the UAE PDPL (Federal Decree-Law 45/2021) |
| Data at rest (database) | Neon-managed PostgreSQL — United States region (confirm) | PDPL Art. 22/23 adequacy or SCCs; GDPR/UK SCCs + DPF where certified |
| Compute (request processing) | Vercel serverless/edge — United States primary region (confirm) | SCCs + DPF where certified |
| Source tenant data | Stays in your Microsoft tenant's configured region | Read-only access authorized by your admin's consent; you control the tenant |
Region values marked “confirm” are pending verification against the live deployment and will be stated exactly once confirmed. We do not name a region we have not verified.
The data-flow path
Reading and analyzing a connected tenant follows one path, end to end:
- You grant read-only consent. By default Permafrost reads from your Microsoft tenant under its own multi-tenant application, authorized by that consent — no per-tenant secret is held. (Pro and above can opt into a dedicated app registration you own, whose secret is held encrypted in our secrets vault.)
- Data is processed in the compute region to compute CIEM analysis (UPR scores, findings, recommended roles).
- Results and the supporting inventory state are stored in the database region, logically isolated by customer ID at every query boundary.
- Nothing is sent to advertising networks or used to train models, and no customer's data is aggregated with another's.
That last point is consistent with our security posture: analysis is decision-support for a human reviewer, never an input to a shared model or a cross-customer dataset.
EU / UK data residency
A dedicated EU or UK data-residency option (data at rest and compute kept in-region) is on our roadmap. We have not committed a date yet. If your procurement requires in-region residency, contact us so we can discuss your requirement and where it sits against the roadmap.
