Sovereign.
Data residency you can verify. Four sovereign regions (Canada, the United States, Europe, and Asia-Pacific), regional isolation by architecture, and every legal and security disclosure in one place.
Controls we actually run today, not aspirational language. Where something is planned but not yet in place, you'll find it noted as a roadmap item rather than described as current.
Distronode Corporation • Last Updated: September 10, 2026
On this page
Regional Isolation & Sovereignty
We build for data residency and regional isolation, and we say exactly where your data lives rather than rounding up. A Canadian workspace is stored in Montreal (Amazon Web Services, ca-central-1). A United States workspace is stored in us-east4 (Google Cloud). A European workspace is stored in Frankfurt (Amazon Web Services, eu-central-1), and an Asia-Pacific workspace in Singapore (Amazon Web Services, ap-southeast-1). All four regions are live today, and stored data stays in its region.
AI processing runs in the United States under the transfer safeguards described for each region below, unless a region has safeguards of its own. Two do. For a European workspace, the language model behind live calls runs in the European Union (europe-west4).
For a Canadian workspace, the language model runs in Montreal (northamerica-northeast1) on every voice engine except the realtime one. That engine listens and speaks with a single model that Google does not serve from Montreal, so a Canadian workspace that chooses it is processed in the United States (us-east4), and the engine picker says so. A new Canadian workspace starts on an all-Canadian engine, which runs speech recognition and speech synthesis in Montreal as well. The other engines remain available, each labelled with the region every leg runs in; on those, the two speech legs run in the United States.
Since September 2026, a telephone call on a Canadian number we issue through Telnyx is answered in Montreal in both directions. A call arriving on a number issued through Twilio, whether Canadian or United States, still reaches us in the United States. The Multi-Carrier SIP Routing card below says where each handoff happens.
Your region is assigned to your workspace during onboarding, before any data is stored. We are working toward scheduled region moves, so an established workspace can relocate as its needs change.
Region reachability, right now
Each region's public endpoint, probed from the main site when you loaded this page, and again every minute. This is reachability and round-trip time only: it does not report a region's database, its telephony, or anything behind the endpoint.
- United StatesNot checked
- CanadaNot checked
- EuropeNot checked
- Asia PacificNot checked
Sovereignty Architecture
Network Isolation
Each region's database accepts connections only from an explicit allow-list of our own servers, over TLS with certificate verification, and its plaintext ports are firewalled off. Database resources, client contacts, call transcripts, and AI vectors sit inside the Canada, United States, Europe, and Asia-Pacific regions we operate.
Managed Encryption
Database storage is encrypted at rest by the provider hosting that region, with keys the provider manages and we never hold. Telephony and messaging credentials you connect, and the secrets behind custom connectors, get a second layer through Google Cloud Key Management Service under strict access controls, and are never handed to anyone else.
Operational Logging
Audit trails stay in your own region's database. Operational telemetry and infrastructure logs go to our monitoring provider in the European Union, and application error diagnostics to our error-tracking provider in the European Union (Germany), for every region. Both are named on the sub-processor page with what they receive.
Multi-Carrier SIP Routing
We work with several telephony carriers, including Twilio, Sinch, and Telnyx, and we connect to each one from equipment in the region that serves your workspace, wherever the carrier can meet us there.
For a European workspace, outbound calls reach Twilio through its Dublin edge in Ireland and Telnyx at its Frankfurt site. Since September 2026, a Canadian workspace's outbound calls start on our Montréal equipment and are handed to Telnyx at its Montréal site. A call arriving on a Canadian number we issue through Telnyx comes the other way: Telnyx delivers it from its Canadian gateway to that same equipment.
A call arriving on a number issued through Twilio, whether Canadian or United States, still reaches us in the United States. Where a carrier has no such point of presence, calls connect through its United States infrastructure, and the data residency map says so per data type.
Security & Trust
Controls we actually run today, not aspirational language. Where something is planned but not yet in place, you'll find it noted as a roadmap item elsewhere on this page rather than described here as current.
| Control | What it means in practice |
|---|---|
| Tenant Isolation at the Database | Every tenant-scoped table is enforced with PostgreSQL Row-Level Security, not application-layer checks alone. A cross-tenant query is rejected by the database itself, even if an application bug were to attempt one. |
| Encrypted in Transit | TLS 1.2 or higher is enforced on every public endpoint. Connections attempting a weaker protocol version are rejected at the edge before they reach our infrastructure. |
| End-to-End Encrypted Calls | In-app calls and meetings are end-to-end encrypted between your device and the AI, so the media is unreadable to the servers that relay it, including ours; only your device and the assistant that answers hold the key. Calls that arrive over the telephone network are not, because the carrier delivers them unencrypted. |
| Firewall & Rate Limiting | Managed firewall rules and rate limiting sit in front of authentication endpoints specifically, to blunt credential-stuffing and brute-force attempts before they reach the application. |
| Ongoing Patch Cadence | Container base images are rebuilt and redeployed on a monthly cadence to pick up upstream security patches, independent of feature releases. |
| Managed Secrets | Credentials and API keys live in a managed secret store with scoped access per service. They are never committed to source control or shared over unencrypted channels. |
| Encrypted at Rest | Database storage is encrypted at rest by the provider hosting your region, with keys that provider manages and we never hold. Telephony and messaging credentials you store with us are encrypted again through Google Cloud KMS and are never handed to anyone else. |
| Signed DNS (DNSSEC) | distronode.com and distronode.ca are DNSSEC-signed with delegation records published at their registries, so validating resolvers can detect tampered DNS answers before a connection is ever made. |
EU GDPR Compliance Hub
Distronode supports customers subject to the European Union General Data Protection Regulation (GDPR). We honor GDPR data-subject rights and provide Data Processing Agreements with standard contractual clauses to safeguard international transfers.
Right to Erasure (Article 17)
Erasure requests are honored without undue delay and within 30 days. Deleting an account removes database records (contacts, call records, transcripts, and messages) immediately. Encrypted database backups expire on a fixed schedule within approximately eight weeks.
Right to Access & Portability (Articles 15 & 20)
Workspace owners can export their workspace data (contacts, call records and transcripts, messages, meetings, and settings) as structured JSON from the dashboard, or request a copy from our Privacy Officer at legal@distronode.com.
International Transfer Safeguards (Chapter V)
Where EU personal data is processed outside the EEA (including in Canada and the United States), we rely on European Commission-approved standard contractual clauses (SCCs) and appropriate technical and organizational safeguards, consistent with Chapter V.
Data Processing Agreements (DPA)
We provide a standard Data Processing Agreement (DPA) incorporating the EU Standard Contractual Clauses (Module Two) and the UK Addendum for transfers outside the EEA and the UK.
Canada Privacy Hub
Distronode is a Canadian company and District AI is built for the Personal Information Protection and Electronic Documents Act (PIPEDA) and aligned with Quebec's Law 25 (formerly Bill 64). There is no government certification for either law; what matters is what a vendor actually does, so this page states our practices precisely and supports your own compliance obligations.
Privacy Officer
We maintain a designated Privacy Officer to oversee compliance, manage privacy risk audits, and respond to individual access requests. Reach them at legal@distronode.com.
Mandatory Breach Logging
We keep a register of confidentiality incidents, as Law 25 requires. When an incident presents a risk of serious injury, we notify the CAI and the affected individuals promptly.
Privacy by Default
New workspaces start with privacy-protective settings. Lead enrichment and profiling features are opt-in rather than on by default.
Impact Assessments (PIA)
We assess privacy factors before releasing features that involve new uses of personal information or transfers outside Quebec, consistent with Law 25's privacy impact assessment expectations.
Sub-processors
Third parties who process customer data on our behalf as part of running the platform. We vet each one for the safeguards described elsewhere on this page, and we give at least 30 days' notice before adding or replacing one so you can review the change.
The full register (every sub-processor with purpose, data category, and region) is published at distronode.com/sovereign/subprocessors, the address our Data Processing Agreement incorporates by reference. Questions about a specific sub-processor, or how one fits your own vendor review? Contact us at legal@distronode.com.
Accessibility
Distronode is designed and built toward WCAG 2.1 Level AA. We test primary flows, including signup, checkout, and the customer dashboard, against these guidelines and address issues as we identify them. This is a stated target we are actively working toward, not a certified audit result, and we want to be as clear about that distinction here as everywhere else on this page.
Keyboard & Focus
Interactive controls are reachable by keyboard alone and carry a visible focus state, rather than relying on mouse hover to reveal what's actionable.
Screen Reader Labels
Icon-only and non-text controls carry explicit accessible names, so assistive technology announces what a control does, not just that it exists.
Color & Contrast
Text and interface colors are checked for contrast in both our light and dark themes, not just whichever one shipped first.
Ongoing Review
Accessibility is reviewed as part of building new features, not bolted on afterward, and reports from real users take priority over anything we find ourselves.
Report a Barrier If you encounter an accessibility barrier using our product, contact us at accessibility@distronode.com with what you were trying to do and where it broke down. We will prioritize a fix.
Vulnerability Disclosure
We welcome reports of security issues from independent researchers and customers. If you believe you've found a vulnerability in our platform, we want to hear about it before anyone else does.
How to report
Email security@distronode.com with enough detail for us to reproduce the issue: affected URL or endpoint, steps taken, and what you observed versus what you expected.
What we ask of you
Test only against your own account and data, avoid accessing or modifying anything that isn't yours, and give us a reasonable window to investigate and remediate before any public disclosure.
What you can expect from us
Acknowledgment within 2 business days, and ongoing updates as we investigate and work toward a resolution. We do not pursue legal action against good-faith researchers who follow this policy.
Documents
| Document | What it covers |
|---|---|
| Built for PIPEDA | How District AI implements the 10 fair information principles, in plain language. |
| PHIPA-ready | For Ontario health information custodians. We support your obligations and sign agent agreements. |
| Quebec Law 25 | Named privacy officer, incident register, consent, and where French-language service stands. |
| Data Processing Agreement | A plain-language DPA for small businesses, offered for signature. |
| Sub-processors | The real third parties that process data, with purpose, data category, and region. |
| Data residency map | Where each type of data is stored and processed. We never claim data never leaves Canada. |
| Privacy Policy | How we collect, utilize, and protect your organizational data and telemetry. |
| Terms of Service | The governing agreements, SLA targets, and mutual commitments of platform usage. |

