Data Residency
Ayrıca şöyle anılır data localization, data sovereignty
Data residency is where an organization's data actually, physically sits, which country, which data center, under which jurisdiction's laws, as distinct from where the company processing it is headquartered or where its customers are located. A buyer asking about data residency wants to know, concretely: if a regulator in my country demands to know where my customers' identity data lives, what do I tell them.
It matters for identity verification specifically because the data involved, government ID scans, biometric face data, dates of birth, is exactly the category most residency and localization laws are written to protect. A vendor that can't answer "which country is this stored in" is a vendor a regulated buyer in a data-localization jurisdiction usually cannot legally use.
Where the requirement comes from
Multiple, independent, non-harmonized legal regimes drive this, not one global rule: the EU's GDPR restricts moving personal data outside the EU/EEA unless an adequacy decision or an approved transfer mechanism applies; Türkiye's KVKK (Law No. 6698) imposes a comparable cross-border-transfer restriction, directly relevant given Solidus's own primary go-to-market geography; China's PIPL and Russia's Federal Law No. 242-FZ go further, in some cases requiring the initial recording of certain personal data to happen inside the country before any transfer elsewhere. None of these regimes coordinate with each other, and none of them are something a vendor gets to interpret its own way: an actual legal opinion reviewed per jurisdiction is what a real compliance answer requires, not a vendor's own assurance.
Solidus's honest position
Solidus's entire testnet infrastructure runs on a single server, hosted by Hetzner in Germany. There is no second region, no in-Türkiye deployment, no US-only or EU-only option, and no contractual commitment to store a given customer's data in a specific jurisdiction. A buyer who needs a data-residency guarantee, which, for several of Solidus's own named KYC-vertical targets in Türkiye, a strict reading of KVKK's cross-border rules could require, cannot get one from Solidus today. This isn't a subtle gap to qualify around; it's a straightforward "not built yet," and it belongs on the list of real questions a serious enterprise buyer should ask before any pilot, not something to discover during a security review.
See also
GDPR and GDPR Article 17 cover the EU data-protection regime data residency sits alongside. Vendor Lock-In is the related dependency-on-one-operator question this entry's caveat also names. SOC 2 is the closest thing to an independent audit of how data is protected, distinct from where it's stored, and, like data residency, not something Solidus holds today.
Nereden geliyor
Bunu başkası belirtti. Solidus bir araya getiriyor.
Data residency requirements come from national and regional data-protection and sovereignty law, not from Solidus or any single vendor: the EU's GDPR restricts transfers of personal data outside the EU/EEA absent an adequacy decision or an approved safeguard (GDPR Chapter V), Russia's Federal Law No. 242-FZ requires personal data on Russian citizens to be initially recorded on servers located in Russia, and China's PIPL imposes its own localization requirements on certain categories of processors. Türkiye's KVKK (Law No. 6698) similarly restricts cross-border transfer of personal data absent an adequacy finding or an explicit consent/contractual safeguard. Solidus wrote none of this law and offers no regional-deployment product against any of it today.
Bunu nasıl doğrularsınız
Solidus bunu inşa etmedi. Girdi kavramı açıklıyor.
None to offer in Solidus's favor. There is no regional-deployment product, no data residency page, and no signed data-processing agreement specifying storage location to point to. Stated directly rather than implied as "coming soon."