The standard managed path does not guarantee in-country processing
Permanent sources and outputs live in customer R2, while managed encoding temporarily processes media outside the customer account. Regulated deployments must review Cloudflare jurisdiction support and desktop or customer-cloud encoding under Enterprise.
Boundaries to review
Separate permanent storage, temporary processing, and AI transfer
R2 Location Hint is a performance hint, not a residency guarantee. Match the required guarantee to Cloudflare contract features and the NULX processing model.
Permanent storage location
Keep sources and outputs in customer R2, then verify required residency through Cloudflare's supported jurisdictions.
Processing location
Managed encoding runs on NULX infrastructure. Customer-PC and customer-cloud encoding are reviewed under Enterprise.
Auditable access
Review the connected R2 bucket, allowed prefixes, and Groq audio transfer before granting access.
Regulatory reviews
What this means for EU and public-sector reviews
We do not claim there is no cross-border transfer. The compliance page separates permanent R2 storage, NULX managed processing, and Groq transfer paths.
Read the compliance overviewNext step
Review the setup before you grant anything
The setup guide shows the exact IAM policy and bucket layout. Questions about a regulated rollout? Talk to us.