Built on certified infrastructure

Your data is encrypted, split into shards, and distributed across 12 independently audited storage providers in 223 locations. No single provider holds a readable copy.

Trust Center · Last updated 8 October 2026

12
Independently audited storage providers
223
Storage locations across our providers
0
Providers holding a readable copy of your data
Every object
Covered by a signed audit record

Compliance

ironshard
GDPRDPA available
EU data residencyPinned to your jurisdictions
See the docs →
infrastructure providers

Every provider we use is independently audited, most with both SOC 2 Type II and ISO 27001.

See all providers →

Product & data securityBuilt into the storage layer

Encryption

Data is encrypted at rest and in transit.

Key management

Data encryption keys are encrypted and protected by a Key Management Service (KMS).

Erasure-coded shards

Each object is split into encrypted fragments. One fragment alone is meaningless, but the object is recoverable.

Per-agent access control

Each agent gets its own identity and a policy that limits what it can reach.

Signed audit log

Every read and write is recorded, signed, and exportable as structured JSON.

Isolated branches

Agents work on copy-on-write branches; production stays untouched.

Multi-cloud by design

IronShard spreads encrypted shards across 12 independent storage providers and 223 locations, from European specialists to global hyperscalers. Each provider is independently audited, and no single one ever holds a readable copy.

European providers

OVHcloud

France

30 locations

  • SOC 2 Type II
  • ISO 27001
Compliance page ↗

Exoscale

Switzerland

8 locations

  • SOC 2 Type II
  • ISO 27001
Compliance page ↗

Hetzner

Germany

3 locations

  • ISO 27001
  • BSI C5
Compliance page ↗

ScanNet

Denmark

1 location

  • ISAE 3402
Compliance page ↗

Global providers

Microsoft Azure

US

47 locations

  • SOC 2 Type II
  • ISO 27001
Compliance page ↗

Google Cloud

US

43 locations

  • SOC 2 Type II
  • ISO 27001
Compliance page ↗

Amazon Web Services

US

34 locations

  • SOC 2 Type II
  • ISO 27001
Compliance page ↗

Akamai (Linode)

US

20 locations

  • ISO 27001
Compliance page ↗

IBM Cloud

US

13 locations

  • SOC 2 Type II
  • ISO 27001
Compliance page ↗

Tigris

US

11 locations

  • SOC 2 Type II
Compliance page ↗

DigitalOcean

US

9 locations

  • SOC 2 Type II
  • ISO 27001 data centers
Compliance page ↗

Cloudflare

US

4 locations

  • SOC 2 Type II
  • ISO 27001
Compliance page ↗

Certifications belong to each provider; links go to their own compliance pages.

Common questionsAbout security and compliance

Is IronShard GDPR-compliant?
IronShard is engineered to meet GDPR's requirements at the storage layer: encryption everywhere, jurisdiction pinning, scoped access, and a full access record. Compliance is a property of your processing, not of any single vendor; IronShard's role is to make sure the storage-side controls and evidence are already in place.
How does IronShard support EU AI Act obligations?
Through automatic lineage and audit. Every dataset state, training run, and inference read is recorded and signed, so the questions the Act asks (which data did this model use, who accessed it, and can the result be reproduced) are answerable from the log.
Can healthcare and finance teams run AI agents on IronShard?
Yes. Agents work on isolated branches of real data with per-agent scoping, and every access is logged immutably. IronShard is engineered to meet the storage requirements of HIPAA, GLBA, and PCI-DSS; the Enterprise page covers how these deployments are structured. Enterprise
Where does my data physically live?
Where you pin it. Data is fragmented and distributed across the providers and regions you choose, and it stays within those boundaries. No single provider holds a complete file.
Why does data lineage matter for compliance?
Without versioning and lineage, you cannot prove which datasets trained which model, reproduce a result, or explain an output. IronShard captures dataset state and access history automatically, so lineage is a record you export rather than a document you assemble.