Part 1 of a series on data residency, by Kisa Brostrom, CTO at BoodleBox
Every RFP asks it: "Is my data stored in the United States?" Every vendor answers yes. Almost nobody asks the follow-up question that actually matters.
There are two very different promises hiding behind that one yes.
There's a huge difference between saying our infrastructure is based in the United States and saying we can guarantee that your data will never be stored, processed, or touched outside the United States.
US-based means a provider's infrastructure normally runs domestically.
US-bound is a contractual commitment that a specific workload cannot leave a defined geography, full stop. Most vendors are selling you the first one. Most institutions think they bought the second.
And "your data" is a lot bigger than the database you asked about. It touches the application layer, storage, logging, document processors, embeddings, model providers, moderation services, and every subprocessor underneath. A "yes" to residency rarely means all of that.
Here's the part that gets left out of the sales conversation entirely: providers want the opposite of a locked-down region. They want global endpoints and access to a wider pool of infrastructure for reliability, latency, and capacity. When one region hits a wall, failing over somewhere else with room to spare is how uptime gets protected.
The moment you contractually say the workload cannot leave the United States, you've intentionally made the pool smaller and that can create a conflict.
"You can't ask for maximum reliability and a hard geography lock in the same sentence."
You can't ask for maximum reliability and a hard geography lock in the same sentence. Those two requirements pull against each other. And that tension already shows up on the invoice:
A geography guarantee has a price. Anthropic prices US-only inference at 1.1x the cost of global inference. OpenAI applies a 10% uplift to regional processing.
Constrain the supply available to serve you, and the cost of serving you goes up. Every "US-only, no exceptions" clause is a line item — most procurement teams just haven't seen where it lives yet.
"The question to actually ask your vendor: not 'is my data in the US,' but 'is this workload contractually bound to the US, and what's the premium for that guarantee?'"
Kisa Brostrom | Chief Technology Officer, BoodleBox
Kisa Brostrom leads AI systems architecture, data strategy, and platform governance at BoodleBox. With over a decade of experience in data engineering, applied machine learning, and distributed systems design, she has spent her career building scalable, privacy-aligned AI infrastructure in startup and growth-stage environments — the kind of environments where the gap between what technology can do and what people actually use it for is most visible.
At BoodleBox, Kisa has led the development of a privacy-first AI platform serving 100,000+ learners across 1,300+ institutions, including a sustainability-focused token-reduction architecture that makes equitable access to AI practical at institutional scale. She works daily at the intersection of what AI can do and what it should do for the people trying to learn with it.
The perspective in this piece is drawn from her work on AI security, compliance, and data governance at BoodleBox.
Every organization's data residency requirements are different. See our full security posture, then let's talk through yours.
Book a free consultation and demo →
Want to see Kisa walk through this exact distinction? It starts around 2:30 in the recording below.
Learn more about the ins and outs of the BoodleBox workspace from our team of experts.
Schedule a meetingLooking for more information?