Skip to content
// FLEET
us-west-1GB300 · liquid
eu-central-1B300 · liquid
apac-sg-1GB200 · NVL72
me-uae-1VR200 · Rubin
// TRUST

Security you can audit.

One identity model, one audit log, one set of controls across every service. Compliance is enforced at the data-adapter boundary — not hidden in the UI.

Live status →

// FRAMEWORKS

SOC 2 Type II

Independently audited security, availability, and confidentiality controls.

ISO 27001

Certified information-security management system.

HIPAA-ready

BAA-eligible configurations for protected health information.

GDPR

DPA, SCCs for transfers, and data-subject request handling.

PCI DSS

Card data handled by Stripe (PCI Level 1); Segal never stores PANs.

Audit logging

Every privileged mutation recorded — who, what, when, before/after.

// DATA RESIDENCY

Every resource carries its region. Choose where data lives; filter by residency in the console. Region certifications:

RegionLocationTierCertifications
us-west-1Reno, United StatesTier IVSOC 2 Type II · ISO 27001 · HIPAA
us-east-1Ashburn, United StatesTier IVSOC 2 Type II · ISO 27001 · HIPAA · PCI DSS
eu-central-1Frankfurt, GermanyTier IVSOC 2 Type II · ISO 27001 · GDPR · EN 50600
apac-sg-1Singapore, SingaporeTier IIISOC 2 Type II · ISO 27001 · MTCS Tier 3
me-uae-1Abu Dhabi, United Arab EmiratesTier IVISO 27001 · ISO 22301
ap-ph-1Manila, PhilippinesTier IIIISO 27001
// EXPORT CONTROL

GPU compute and certain network control surfaces are subject to U.S. export controls (EAR; some items ITAR-adjacent). Access to export-controlled regions and VPN exit nodes is gated on eligibility screening, enforced server-side at the adapter boundary.

We do not provide access to denied parties or embargoed destinations. Blocked actions return a clear, typed restriction — not a silent failure.

// SUBPROCESSORS

Representative list — the maintained register is available on request.

StripePayments + PCIGlobal
NeonManaged PostgresMulti-region
ResendTransactional emailGlobal
// GET STARTED

Build on a platform you can audit.

Region-pinned data, scoped access, and a single audited control plane across every service.