Skip to main content
CONNEX Cloud OS strictly enforces physical database isolation by statutory jurisdiction coupled with sovereign key management to eliminate cross-border compliance risks.

Republic of Korea Jurisdiction (PIPA)

All user credentials, profiles, VFS documents, and session histories for Korean residents are permanently isolated within dedicated Firestore databases in Seoul (asia-northeast3), strictly blocking unauthorized cross-border transfers.

United States & Global Jurisdiction (CCPA/GDPR)

Data for US and international users resides exclusively within dedicated Firestore databases in Iowa (us-central1), fully adhering to SOC 2 Type II and CCPA requirements.

Sovereign Key Control & Cryptographic Boundary

In addition to physical multi-region database boundaries, enterprise tenants can maintain complete custody over their data through Customer-Managed Encryption Keys (CMEK) and the Instant Cryptographic Kill Switch:
  • Customer-Managed Key Custody: Enterprise clients host their Key Encryption Keys (KEKs) directly within their own cloud accounts (GCP Cloud KMS or AWS KMS).
  • Instant Access Revocation (Kill Switch): By disabling the key within their own KMS console, all data reads across CONNEX VFS and Agentic RCAG pipelines immediately fail closed with HTTP 423 Locked (KeyAccessRevokedError).
  • Zero Cross-Jurisdictional Contamination: Cryptographic keys and encrypted payloads never transit outside their designated regulatory perimeter.
Users select their statutory country of residence upon registration. Once set, the jurisdictional binding is strictly permanent to prevent cross-border data leakage.