Trust & security
Data residency
Today: every Monroe workspace runs in AWS US-East, fully isolated per workspace. Compute, stored state, database records, encryption keys, and run history all live there. Below is what we can sequence for regulated buyers, and where each option stands.
| Option | Status |
|---|---|
| AWS US-East, per-workspace isolation | Live today |
| EU residency (Ireland / Frankfurt) | Enterprise roadmap |
| Region-locked "no-egress" deployment | Enterprise roadmap |
| AP-Southeast (Singapore, Sydney) | 2027 roadmap |
| Dedicated, fully-isolated infrastructure | 2027 roadmap |
The architecture ports cleanly across AWS regions, with no third-party router to relocate, so if a region or isolation tier gates your purchase, email enterprise@getmonroe.com and we will sequence it against your timeline.
GDPR posture today
- Data subject deletion request → workspace deletion with a 30-day retention window, then permanent wipe (your stored data and secrets)
- DPA + SCC available on request
Cross-region data flow
Customer data stays in the US-East region. The only out-of-stack calls are:
- Stripe payment processing (US/EU, Stripe-side)
- Identity provider (US)
- Model inference stays in-region, inside AWS, in the US
Dedicated isolation
Current Enterprise workspaces already run fully isolated from one another on AWS. A small number of regulated customers (banks, defense contractors) want Monroe in dedicated, single-tenant infrastructure; that is on the 2027 roadmap. Email enterprise@getmonroe.com to discuss requirements.
Next → security overview.