Choose where your data lives
A vulnerability report is a map of how to attack you. You should know which jurisdiction holds it.
Mondoo runs multi-tenant in a shared EU or US region, single-tenant in an instance we operate for you, or self-managed in your own environment.
Get an assessmentFour ways to run Mondoo
| EU region | US region | Single-tenant | Self-managed | |
|---|---|---|---|---|
| Where your data is stored | European Union, in Frankfurt | United States | A single region of your choice, dedicated to you | Your own private cloud instance |
| Who operates it | Mondoo GmbH, Berlin | Mondoo Inc. | Mondoo GmbH, or Mondoo Inc. | You |
| Tenancy | Shared, with logical separation and separate encryption keys for every customer | Shared, with logical separation and separate encryption keys for every customer | Single tenant, with its own database | Single tenant |
| Best for | Organizations in the EU and UK, and anyone in scope for NIS2 or DORA | Organizations in North America or Latin America | Regulated workloads that cannot share a tenant | Teams with the capacity to operate the platform, and hard sovereignty requirements |
EU region
| Where your data is stored | European Union, in Frankfurt |
|---|---|
| Who operates it | Mondoo GmbH, Berlin |
| Tenancy | Shared, with logical separation and separate encryption keys for every customer |
| Best for | Organizations in the EU and UK, and anyone in scope for NIS2 or DORA |
US region
| Where your data is stored | United States |
|---|---|
| Who operates it | Mondoo Inc. |
| Tenancy | Shared, with logical separation and separate encryption keys for every customer |
| Best for | Organizations in North America or Latin America |
Single-tenant
| Where your data is stored | A single region of your choice, dedicated to you |
|---|---|
| Who operates it | Mondoo GmbH, or Mondoo Inc. |
| Tenancy | Single tenant, with its own database |
| Best for | Regulated workloads that cannot share a tenant |
Self-managed
| Where your data is stored | Your own private cloud instance |
|---|---|
| Who operates it | You |
| Tenancy | Single tenant |
| Best for | Teams with the capacity to operate the platform, and hard sovereignty requirements |
Every option runs the same platform. The difference is who holds the data and where.
What choosing a region actually means
A region is where Mondoo stores and processes your data. Region sits at the top of the structure: each organization belongs to exactly one region, each space to one organization, each asset to one space.
The EU region runs on Google Cloud in Frankfurt, operated by Mondoo GmbH in Berlin. Backups are taken daily, encrypted, and held in Germany. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, and every customer has separate encryption keys.
New accounts start in the US region. If you need the EU region, it has to be enabled before you create assets. Worth knowing at signup rather than after.
The two regions are separate. Data is stored and processed independently, and assets cannot be moved between them. Treat the choice as permanent.
One account can hold organizations in both regions. If you operate in both markets you do not need two accounts, and each organization keeps its own data where you put it.
If you have no regulatory driver, choosing the region closest to you is still worth doing for response times.
Residency and sovereignty are not the same thing
These two terms get used interchangeably and they should not be.
Data residency is about geography. Where does the data physically sit?
Data sovereignty is about jurisdiction. Which government's laws can compel access to it?
You can have the first without the second, and that gap is where most vendor answers quietly stop.
Here is ours.
Each region is operated by the Mondoo entity in that jurisdiction. The EU region runs in Frankfurt, operated by Mondoo GmbH, a German company based in Berlin. The US region is operated by Mondoo Inc. Your data, and your backups, stay in the region you choose. For the great majority of organizations, including those in scope for NIS2, DORA and GDPR, that is the answer to the question being asked.
The infrastructure underneath is Google Cloud. Google is a US company, and US law reaches US companies. If your threat model or your regulator treats that as material, an EU region does not resolve it, and no vendor running on a US hyperscaler can tell you otherwise.
For organizations where that is decisive, self-managed is the honest answer. You run the platform in infrastructure you own, under your own contracts, with your own keys. We never hold the data, so there is nothing on our side for anyone to compel.
It's important to review and make an informed choice around your data residency and sovereignty. We're here to help you.
Self-managed, in more detail
Mondoo is a comprehensive CTEM solution. It is a rich platform with real operational overhead, and the managed options exist because they are the better choice for many customers.
Self-managed and operated often makes sense in one of the following scenarios:
- A regulator or internal policy requires that no third party can access the data, not merely that it stays in a jurisdiction
- You are already running comparable platforms and have the in-house team and expertise
- Your environment cannot reach an external service at all
In that model you deploy Mondoo into your own cloud account on Google Cloud, AWS or Azure. You control the network, the keys, the backups and the retention. Mondoo supplies the software and the support.
If you are weighing this against single-tenant, the practical difference is operational responsibility. Single-tenant gives you a dedicated instance and we run it. Self-managed gives you full control and you run it.
Compliance and certifications
- SOC 2 Type II
- ISO 27001
- CIS SecureSuite
- GDPR
A data processing agreement is available for all deployment models. Our security overview and completed security questionnaires are available on request.
Common questions
In the region your organization belongs to. The EU region stores and processes data in the European Union, on Google Cloud in Frankfurt, with encrypted backups held in Germany. The US region stores and processes data in the United States.
Yes. UK data protection law recognizes the EEA as providing adequate protection, so sending data to our EU region needs no additional transfer mechanism.
No. Personal data moves freely within the EU and EEA, so an EU region deployment puts you in the same position wherever in the Union you operate. There is no cross-border transfer to account for.
You choose at organization level. New accounts start in the US region, and the EU region must be enabled before you create assets in it. Because the regions are separate and assets cannot move between them, treat the choice as permanent. One account can hold organizations in both regions.
In the EU and US regions and in single-tenant deployments, the Mondoo teams that operate and support the platform hold the access needed to run it. That access is governed by role-based controls and is logged. In a self-managed deployment, Mondoo holds no access at all, because the platform runs entirely in your environment. We can provide details of our access controls and audit practices on request.
Mondoo uses third-party foundation models for some automated analysis, such as generating remediation guidance. Only the data required for that analysis is sent, your data is not used to train those models, and the providers involved are covered by our data processing agreement. A full list of our subprocessors is available on request.
Yes, for every deployment model. Contact us and we will send it.
Not sure which option fits? An assessment is the fastest way to find out. We will look at your environment, your regulatory scope and your team's capacity, and tell you which deployment model we would actually recommend.