Skip to content
Trust Center
Where data lives

Data residency & data flow

An explicit, scannable statement of where your data is stored, where it is processed, the entity that controls it, and the basis for every cross-border hop. No implicit answers.

Last updated 27 June 2026

Where your data lives

Permafrost is operated by DuneCodeForge Ltd, incorporated in the United Arab Emirates, which is the data controller. The Service runs on managed infrastructure; the table below states each layer, its location, and the legal basis that covers any cross-border transfer.

Data residency by layer: location and transfer basis
LayerLocationTransfer basis
Controller entityDuneCodeForge Ltd — United Arab EmiratesData controller under the UAE PDPL (Federal Decree-Law 45/2021)
Data at rest (database)Neon-managed PostgreSQL — United States region (confirm)PDPL Art. 22/23 adequacy or SCCs; GDPR/UK SCCs + DPF where certified
Compute (request processing)Vercel serverless/edge — United States primary region (confirm)SCCs + DPF where certified
Source tenant dataStays in your Microsoft tenant's configured regionRead-only access authorized by your admin's consent; you control the tenant

Region values marked “confirm” are pending verification against the live deployment and will be stated exactly once confirmed. We do not name a region we have not verified.

The data-flow path

Reading and analyzing a connected tenant follows one path, end to end:

  1. You grant read-only consent. By default Permafrost reads from your Microsoft tenant under its own multi-tenant application, authorized by that consent — no per-tenant secret is held. (Pro and above can opt into a dedicated app registration you own, whose secret is held encrypted in our secrets vault.)
  2. Data is processed in the compute region to compute CIEM analysis (UPR scores, findings, recommended roles).
  3. Results and the supporting inventory state are stored in the database region, logically isolated by customer ID at every query boundary.
  4. Nothing is sent to advertising networks or used to train models, and no customer's data is aggregated with another's.

That last point is consistent with our security posture: analysis is decision-support for a human reviewer, never an input to a shared model or a cross-customer dataset.

EU / UK data residency

A dedicated EU or UK data-residency option (data at rest and compute kept in-region) is on our roadmap. We have not committed a date yet. If your procurement requires in-region residency, contact us so we can discuss your requirement and where it sits against the roadmap.