Data Residency Is Two Claims, and Most Vendors Answer Only the Easy One
Everything below about our own deployment is measured, including the part where our own live page has said something we cannot support.
The question a regulator actually asks
Not "where is your company", and not "where is your server". The question is where does the personal data physically rest, and who can reach it there.
Those decompose into two claims that sound like one:
Claim one: our infrastructure runs in jurisdiction X. Easy to make, easy to verify, and usually true.
Claim two: your customers' data is stored in jurisdiction X. Harder, because storage is usually somewhere else.
A vendor that answers the first when you asked the second has not lied to you. It has answered a different question, and you will not notice until an auditor asks it precisely.
Why the two come apart
Application servers and object storage are different systems with different geography.
The server is a machine in a datacentre and its location is a fact. Object storage is a service that places and replicates objects according to its own policy, across whatever regions that policy covers, unless you have pinned it to a jurisdiction.
Most storage providers support a jurisdiction-restricted mode. It is a configuration choice, it is not the default, and a team that has not deliberately made that choice does not have it. The uploads, the images, the recordings, the things a regulator actually cares about, are in the second system.
Our own page has said otherwise
Until 2026-08-06, one of our live pages advertised an EU data residency option and stated that a German regulator's residency requirement was satisfied by a Solidus EU region.
There is no EU region. There is no residency option. There is no product to select. That copy was wrong, it was ours, and it has since been corrected on the live page, and the claim is gone in both languages. We are leaving the paragraph here rather than deleting it, because a vendor that quietly removes a false claim and a vendor that never made one are not the same thing, and only one of them tells you.
We are writing that here rather than waiting to be asked, because a buyer who discovers it during due diligence learns two things, and the second one is about us.
How to ask any vendor, including us
"Where does the object storage put my uploads, and is the bucket jurisdiction-restricted?" Not "is your infrastructure in the EU". The second question has an easy yes that does not answer the first.
"Show me the endpoint." A jurisdiction-restricted bucket has a distinguishable one. This is one of the few compliance claims a buyer can verify without trusting a document.
"What is your replication policy?" Storage that replicates for durability across regions is doing exactly what you want operationally and exactly what you do not want jurisdictionally, and the tension is real rather than a gotcha.
Where this leaves a decision today
If jurisdiction-pinned storage is a hard requirement, we do not meet it today and you should not run a pilot on the assumption that we do. The fix is a configuration change rather than an architecture change, which makes it a scheduling question, and we have not scheduled it.
If your requirement is that infrastructure sits in the EU, that is true of the server and is the easier half of what you probably meant.