Where is my Reality Twin data stored?
Regions, sub-processors, model inference routing, encryption — everything about where your data lives.
Reality Twin is built for European teams that care about data residency. This article covers exactly where your data lives, how it moves, and how to pin it to a specific region.
Default region
Application data (knowledge sources, conversations, workspace metadata, embeddings) is stored in the European Union — Ireland. Reality Twin is a Swiss company operating under Swiss law, so the operator is Swiss while the storage is EU; both the GDPR and the Swiss FADP apply, and a DPA is available.
Encryption
- In transit — TLS 1.3, HSTS enforced.
- At rest — AES-256, keys managed by the cloud provider's KMS.
- Backups — encrypted with a separate key.
- Optional customer-managed keys (CMEK) on Enterprise.
Model inference routing
Foundation-model inference happens with EU-hosted providers by default. US routing is opt-in per workspace and disabled unless you explicitly enable it. Enterprise plans can pin inference to Switzerland-hosted models.
Sub-processors
The current sub-processor list is on /dpa. We notify DPA signatories in advance of any new sub-processor via email; you have the right to object.
Isolation
- Every workspace is logically isolated at the row-level in the database.
- Row-level security policies enforce workspace boundaries at query time.
- Enterprise plans can request physical isolation on dedicated infrastructure.
Backups and recovery
- Point-in-time recovery for the last 14 days.
- Daily snapshots kept for 30 days.
- Restoration RTO 4 hours, RPO 15 minutes.
Frequently asked questions
Is my data ever used to train shared models?
No. Your data stays in your workspace and is never used for cross-customer training.
Where is inference physically performed?
In the EU by default. Providers used are listed on /dpa.
Can I request a security review?
Yes — email hello@realitytwin.io for the full security package.
- GDPR and Swiss FADP alignmentHow Reality Twin handles your — and your visitors' — data rights under EU GDPR and Swiss FADP, with a working data-subject request workflow.
- Sign a DPA (Data Processing Addendum) with Reality TwinGet a countersigned DPA in two business days — standard clauses, plain-language sub-processor list, SCC-backed transfers.
- Report a security vulnerability (responsible disclosure)How to report a security issue to Reality Twin, our response timelines, and how researchers get credit.
Did this article solve your problem?
If not, email us — a human on the founding team replies, usually within a business day.