LightYear
/Docs
DocsSecurityCompliance and Data Residency

Compliance and Data Residency

Understand LightYear's compliance certifications and how to configure data residency for regulated workloads.

intermediate
6 min read
LightYear Team
Updated April 24, 2026
compliancegdprdata-residencysecurity
Ready to get started?

Compliance Certifications

CertificationStatus
SOC 2 Type II✅ Certified
ISO 27001✅ Certified
GDPR✅ Compliant
HIPAA✅ BAA available
PCI DSS✅ Level 1

Request compliance documentation at [email protected].

Data Residency

Choosing a Region

All data (servers, block storage, object storage) remains within the selected region. LightYear does not replicate data across regions without explicit configuration.

RegionJurisdiction
Hong Kong (HKG)Hong Kong SAR
Singapore (SGP)Republic of Singapore
Los Angeles (LAX)United States
Frankfurt (FRA)European Union

GDPR Considerations

For EU data subjects, deploy in Frankfurt (FRA) to keep data within the EU. Use a Data Processing Agreement (DPA) — available on request.

Encryption

Data at Rest

All block storage and object storage is encrypted at rest using AES-256.

Data in Transit

All API calls and control plane traffic use TLS 1.2+. Server-to-server traffic on private networks is not encrypted by default — use WireGuard or IPsec for sensitive workloads.

Audit Logging

All API calls and control panel actions are logged and retained for 90 days. Access logs via:

  1. Account → Audit Log in the control panel
  2. API: GET /v1/audit-logs

HIPAA Workloads

For HIPAA-covered workloads:

  1. Sign a Business Associate Agreement (BAA) with LightYear.
  2. Deploy in a dedicated tenancy environment (contact sales).
  3. Enable encryption for all storage volumes.
  4. Restrict access via firewall rules and VPN.

Was this article helpful?

Your cookie choices for this website

This site uses cookies and related technologies, as described in our privacy policy, for purposes that may include site operation, analytics, and enhanced user experience. You may choose to consent to our use of these technologies, or manage your own preferences. Cookie policy