Key facts
| GCC regions | me-central-1 (UAE) default GCC region; sa-central-1 (Riyadh) on Enterprise |
| Pinning | Region selected per workspace; data stays in the pinned region |
| Deployment tiers | Cloud, VPC, on-prem and air-gapped for stricter requirements |
| Key custody | BYOK via cloud KMS or HSM; customer-controlled revocation |
| Subprocessors | Published list with change notification and locations |
| Audit | Per-request logs and audit export with region attribution |
| Contractual frame | Terms at /legal/terms and service commitments at /legal/sla |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified) |
TL;DR
- Pinning is a configuration decision — verify it, do not assume it.
- Failover and support access are the usual sources of accidental export.
- Choose the lightest deployment tier that satisfies the strictest regime.
- Collect evidence: region maps, config exports and subprocessor locations.
- Align UAE, Saudi and sector rules separately — they are not identical.
How it works, step by step
- List the data classes and the GCC regimes that apply to each workload.
- Select the GCC region per workspace and export the configuration as evidence.
- Decide the permitted failover behaviour and test it before go-live.
- Confirm where logs, backups and vector stores live, not just inference.
- Review the subprocessor list and where each provider processes data.
- Choose key custody — provider, BYOK or HSM — and document revocation authority.
- Rehearse an incident and a deletion request so the evidence trail is complete.
Try it yourself
Open the AI data residency checklist →
What "keeping data in the GCC" actually requires
Residency is not a single setting. Six stores need a location decision:
- Inference: where prompts and completions are processed.
- Prompt and response logs: often the largest uncontrolled copy.
- Embeddings and vector indexes: derived data that mirrors your documents.
- Backups and disaster recovery: a common accidental export path.
- Support access: engineers viewing data from outside the jurisdiction.
- Metadata and billing records: may contain identifiers even when content does not.
Map each store, then pin the region and verify with a configuration export rather than assuming the default.
UAE, Saudi and the wider GCC
The regimes differ and evolve. The UAE has federal PDPL plus free-zone regimes such as DIFC and ADGM; Saudi Arabia applies PDPL with sector guidance from SDAIA and financial rules from SAMA; Qatar, Bahrain, Kuwait and Oman each add their own expectations. A practical approach is to define the strictest applicable regime per workload, then satisfy it rather than designing to an average. Plugsky's GCC default is the UAE region, with a Riyadh region available on Enterprise and on-prem or air-gapped deployment when data must not leave a specific national boundary at all.
Residency architecture that holds under pressure
- Failover: make permitted failover regions explicit; if none are permitted, capacity-plan inside the jurisdiction instead of relying on automatic rerouting.
- Keys: hold encryption keys in a KMS or HSM you control so revocation is yours.
- Logs: keep request logs in-region and export only the fields your monitoring needs.
- Support: agree who can access data, from where, under what approval, and how it is logged.
- Deletion: cover primary storage, backups and vector indexes, with evidence.
What to put in the vendor file
Collect evidence that a reviewer can follow: a store-by-store residency map, a workspace configuration export showing the pinned region, the subprocessor list with locations, sample audit events, and the retention and deletion schedule. Confirm the contractual positions in the terms and SLA — /legal/terms and /legal/sla — and record that SOC 2 Type II and ISO 27001 are readiness in progress rather than completed. If your regulator requires a physical boundary, ask for the on-prem or air-gapped option rather than negotiating a clause that the architecture cannot enforce.
Honest comparison
| Residency approach | Plugsky | Global API provider | Self-hosted in-country |
|---|---|---|---|
| GCC region | UAE default; Riyadh on Enterprise | Varies; often nearest foreign region | Your data centre |
| Failover control | Pinned region plus explicit behaviour | Provider routing decides | You design it |
| Deployment tiers | Cloud, VPC, on-prem, air-gapped | Provider cloud only | All of it is yours |
| Key custody | BYOK or HSM with revocation | Usually provider-managed | You operate the HSM |
| Evidence | Config exports, logs, subprocessor list | Varies | Your own tooling |
| Ops burden | Managed | Managed | High |
Frequently asked questions
Does Plugsky have a GCC region?
Yes. me-central-1 (UAE) is the default GCC region, with sa-central-1 (Riyadh) available on Enterprise. Region pinning keeps data in the selected region, and on-prem or air-gapped options exist for stricter boundaries.
Is pinning enough for Saudi PDPL?
Not by itself. You also need to control failover, logs, backups, support access and key custody, and to evidence the configuration. Review the specific PDPL and sector requirements with counsel.
What about data in embeddings?
Embeddings are derived data and belong in the same residency and deletion scope as source documents. Keep the vector store in-region and test deletion across the collection and its backups.
Can support staff access our data from outside the GCC?
Support access should be contractually and operationally constrained, and logged. For strict requirements, on-prem or air-gapped deployment removes external access paths entirely.
How do we prove residency to an auditor?
Provide a store-by-store map, a workspace configuration export showing the pinned region, subprocessor locations, sample audit events and the retention schedule. Evidence beats assurance language.
What happens during a region incident?
Failover behaviour should be explicit and tested. If cross-border failover is not permitted, plan capacity within the jurisdiction rather than relying on automatic rerouting.
Does Plugsky keep data in the UAE by default?
The UAE region is the GCC default, but verify the setting in your own workspace and export the configuration for your file. Do not assume a default equals a commitment.
What certifications support GCC diligence?
Plugsky documents UAE PDPL and DIFC DPL alignment plus SOC 2 Type II and ISO 27001 readiness in progress. Treat certifications as pending and validate controls directly with the enterprise team.