Skip to main content
Data residency

The standard managed path does not guarantee in-country processing

Permanent sources and outputs live in customer R2, while managed encoding temporarily processes media outside the customer account. Regulated deployments must review Cloudflare jurisdiction support and desktop or customer-cloud encoding under Enterprise.

Boundaries to review

Separate permanent storage, temporary processing, and AI transfer

R2 Location Hint is a performance hint, not a residency guarantee. Match the required guarantee to Cloudflare contract features and the NULX processing model.

Permanent storage location

Keep sources and outputs in customer R2, then verify required residency through Cloudflare's supported jurisdictions.

Processing location

Managed encoding runs on NULX infrastructure. Customer-PC and customer-cloud encoding are reviewed under Enterprise.

Auditable access

Review the connected R2 bucket, allowed prefixes, and Groq audio transfer before granting access.

Regulatory reviews

What this means for EU and public-sector reviews

We do not claim there is no cross-border transfer. The compliance page separates permanent R2 storage, NULX managed processing, and Groq transfer paths.

Read the compliance overview

Next step

Review the setup before you grant anything

The setup guide shows the exact IAM policy and bucket layout. Questions about a regulated rollout? Talk to us.