The territory of your data should be a choice, not an accident.
This statement is Netser’s first-party position on data sovereignty — the doctrine, the commitments, and the disclosures that make those commitments verifiable.
Five principles. Non-negotiable.
-
I.
Jurisdiction is a feature, not a friction.
The location of data — physically, legally, and operationally — is a first-class property of the system. We design for jurisdictional intent rather than collapsing it into one global pool.
-
II.
The customer holds the keys.
Encryption keys belong to the customer or to a customer-controlled escrow. Netser does not retain root key material that would let us read customer content unilaterally.
-
III.
Lawful access requires lawful process.
We respond only to validly served, jurisdictionally appropriate legal demands — never to informal requests. Where law allows, we notify customers before disclosing.
-
IV.
No undisclosed access paths.
Our systems contain no design-level backdoors, government-installed wiretap interfaces, or unaudited shadow administrators. If we ever lose this property, we will say so.
-
V.
Transparency is a recurring obligation.
We publish a transparency report on a fixed cadence. Numbers go down only because we have done the work to bring them down — not because we have stopped counting.
How we keep the doctrine honest.
Region Lock
Customer workloads land in the region the customer specifies. Cross-region replication, failover, or analytics is opt-in, contractually pinned, and logged. The default is “stay where you landed.”
Customer-Held Keys
For Sovereign and Dominion tiers, key material is generated and held in HSMs the customer controls. We can be technically incapable of reading customer content. By design.
Notice Where Permitted
If we are compelled to disclose customer data and the law permits notice, we will give notice. Where a non-disclosure order is served, we challenge it where there is reasonable ground.
Annual Transparency Report
Every January we publish counts of legal demands received, complied with, and contested — broken down by jurisdiction, by type, and by whether the customer was notified.
Calendar Year 2025 — Final.
Counts of legal demands received during the calendar year, the disposition of each, and whether affected customers were notified. Numbers are audited annually.
| Jurisdiction | Demands Received | Complied (Full / Partial) | Contested | Customer Notified |
|---|---|---|---|---|
| Hong Kong SAR | 14 | 11 / 2 | 1 | 9 |
| European Union (across MS) | 23 | 18 / 3 | 2 | 22 |
| United Kingdom | 7 | 5 / 1 | 1 | 6 |
| United States | 12 | 8 / 2 | 2 | 4 |
| Other (consolidated) | 9 | 6 / 1 | 2 | 5 |
| Backdoor / informal access requests | 0 | 0 | — | — |
* Audited by Tessera Compliance LLP. Full report and methodology available on request to [email protected].
“A piece of infrastructure that cannot tell you where your data is, who can read it, and under what process — is not infrastructure. It is a leak with a logo on it.”