Research Safety Company
News

Regional availability

Where Neuraphic services run, where we are expanding, and how data residency works.


Where a service runs determines which laws apply to the data it processes, which customers can use it under what terms, and how much latency every request experiences. This page is the current, honest account of where Neuraphic operates.

Current regions

United States. Our primary production region. All application servers, databases, and customer account data are hosted in the United States. This is where every customer is served today.

Global edge. Static content and request routing are handled from edge locations worldwide for low-latency delivery. Customer data is not stored at the edge.

Other regions

There are none, and there is no date. Everything runs in one region in the United States. A European region has been designed and is not deployed; the work exists in our infrastructure code and is switched off, and the account policy currently refuses every region but the one we operate.

We are not publishing a target date. A date on this page would be a commitment, and this site does not carry commitments about things that do not exist. When a second region is serving traffic, this page will say so on the day it does.

Data residency

There is one region, so there is nothing to select and nothing to replicate. Customer content is not copied outside it. Backups for disaster recovery are stored within the same jurisdictional region as the primary data.

Two narrow exceptions. Aggregated, non-identifying operational telemetry may be processed outside the region to keep the service running. And an encrypted backup is written nightly to storage outside our cloud provider, deliberately: a copy that only exists inside the account it is meant to survive is not a backup. That copy is encrypted to a key we hold offline.

Compliance by region

European Union. Personal data is processed in alignment with the GDPR. Standard contractual clauses are included in the Data Processing Addendum for any transfers that remain necessary.

California. Californian residents are covered under the CCPA regardless of which region they are served from. We honor access, correction, and deletion requests within the timeframes defined by the law. Requests can be sent to privacy@neuraphic.com.

Other jurisdictions. Customers with specific regulatory requirements should contact enterprise@neuraphic.com.

Service availability

Where a service runs is one half of availability. The other half is what happens when it stops.

There is no service level agreement, because there are no service contracts. Nothing here is generally available and nobody is paying for uptime, so any number published on this page would be a commitment made to nobody, enforceable by nobody, against a service that has not been asked to carry load. When there is a contract, the target, the measurement window, the exclusions and the credit schedule will be in it, and this page will say so.

What is true today, and can be checked rather than promised:

Identity is the tier everything else depends on. Sign-in, two-factor, passkey ceremonies and session management are operated to the strictest internal target we hold ourselves to, for a plain reason: somebody who cannot sign in cannot recover from any other incident. It runs on a self-managed database cluster across three availability zones, with automatic failover.

The failover has been tested by breaking it on purpose. The primary was killed mid-write, over the application's own connection, while writes were in flight. 323 writes were acknowledged and 323 survived. Writes resumed in about a second; full redundancy took longer to rebuild, and the difference between those two numbers is the honest one.

Incidents are published in full, including the parts that are still wrong on the day of publication. The clearest example is the five days when every alarm fired correctly and none of them could reach a human. That is the standard this page is held to, not an uptime figure.

Changes

When a new region becomes available, when an existing region changes status, or when our data residency or service availability commitments change, we notify customers by email and publish the change here and on the Trust Center.

We would rather tell you what we are building than pretend a region exists because it sounds better in a pitch.