Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Data residency

dataPolicy:
residency:
allowed:
- EU
processing:
allowedProviders:
- azure-openai
- ollama
forbiddenProviders:
- public-cloud-us
  • Before each model invocation and each message to a remote agent the runtime determines provider and region.
  • If the region is not allowed or cannot be determined, the operation is denied (fail closed) and policy.denied is emitted.
  • forbiddenProviders takes precedence over allowedProviders.

Normative text: Data residency and processing.