Data residency

Last updated: 2026-08-22 • ← Privacy

Backbuild runs on a globally distributed edge network that serves customer traffic close to the end user. Customer data at rest is stored in the United States.

Where customer data is stored

Request traffic is served from the edge location nearest the user for performance, but customer data at rest resides in the United States. Cross-region replicas used for resilience are encrypted at rest and remain within the United States.

Release artefacts

Binary release artefacts distributed through Backbuild (desktop app updates, CLI binaries, LSP updates, and white-labeled variants of the same) are stored in managed object storage in the United States. Downloads are served from the global edge, while the underlying storage remains in the United States.

Each release carries integrity metadata (a manifest that names the artefacts and their SHA-256 digests, together with a cryptographic signature), stored alongside the artefacts so that both the binary and its integrity metadata travel together. Release artefacts are signed; the signing key is held in a secured secret store and is referenced, not exposed, during signing. Clients verify each artefact's integrity and signature, and verify key continuity when signing keys are rotated.

International transfers

Because customer data is stored in the United States, personal data originating in the EEA, UK, or Switzerland is transferred to the United States. Backbuild relies on the appropriate transfer mechanism for those transfers:

A Transfer Impact Assessment methodology is followed for transfers that require one. Results are made available to customers under NDA on request.

Specific residency requirements

Customers with specific residency requirements should contact the team to discuss options. Not all arrangements are available on all subscription plans.

Contact

Residency questions and configuration help: