Home/Sovereignty
Residency · Jurisdiction · Compliance
“In the region” is not the same as “in the country”.
Every hyperscaler will sell you a Singapore or Jakarta region and call it local. Your board, your regulator and your customers are asking a narrower question — and it deserves a specific answer.
Residency
There is no second region to leak into.
The usual failure is not malice, it is a default. A durability feature replicates a bucket to a neighbouring country, a logging agent ships traces to a vendor's US endpoint, a support tool caches a transcript abroad — and the residency claim quietly stops being true.
We operate one region. Cross-border replication is not disabled by policy; it does not exist as a capability. That is a weaker product in every dimension except the one that brought you here.

| Data class | Where it lives |
|---|---|
| Model weights | TH-BKK-1 only |
| Prompts and completions | TH-BKK-1 only · in memory · zero retention by default |
| Embeddings and indexes | TH-BKK-1 only |
| Object and block storage | TH-BKK-1 only · single region by design |
| Backups and snapshots | Thailand only · second Thai site on request |
| Platform telemetry | TH-BKK-1 only · no third-party analytics |
| Support tooling | Hosted in Thailand · operated by Thai staff |
| Billing records | Thailand · held by the contracting Thai entity |
Side by side
The questions a risk committee actually asks.
| Question | TAC | Hyperscaler, regional |
|---|---|---|
| Where is the compute? | Bangkok | Singapore or Jakarta, sold as “local” |
| Which law governs the contract? | Thai law, Thai courts | Usually Singapore, Ireland or Delaware |
| Who can be served notice? | A Thai company, at a Thai address | A foreign parent, via a local reseller |
| Foreign disclosure exposure? | None — no foreign parent | Subject to the operator’s home jurisdiction |
| Round trip from Bangkok | 2–6 ms | 60–90 ms regional, 180 ms+ US |
| Can you inspect the facility? | Yes, on a term contract | Effectively never |
| Support in Thai? | Engineers, not a script | Tier 1 outsourced, escalation in English |
| Billing currency | THB or USD | USD, FX risk on you |
Hyperscalers are better than us at almost everything else — breadth of service, global reach, ecosystem, tooling. This table is deliberately narrow. If residency and jurisdiction are not on your list, buy from them.
PDPA · B.E. 2562 (2019)
The compliance position, in plain terms.
We are a processor, you are the controller
The data protection agreement says so explicitly, with processing purposes, categories and retention written out rather than incorporated by reference to a web page that can change.
No cross-border transfer to disclose
Sections 28 and 29 of the PDPA govern transfers out of Thailand. There is nothing to declare under them, because there is no transfer — a shorter conversation than an adequacy assessment.
Sub-processors are listed and few
The full list is in the contract and changes require notice with a right to object. We do not route your data through an analytics vendor, a foreign logging service or a third-party model API.
Breach notification in hours
24-hour notification to you, with the facts you need for your own 72-hour obligation to the PDPC. Not “without undue delay”.
Data subject requests are answerable
Access, correction, erasure and portability can be executed against a defined set of stores in one country — the only reason they are answerable inside the statutory window.
Exit leaves you with something
Weights, fine-tunes, indexes and logs exported in open formats, then a NIST 800-88 purge with certificate. Written into the contract before you sign.
Sector rules sit on top of the PDPA — BOT notifications for financial institutions, OIC for insurers, and the relevant healthcare rules for patient data. We map controls to whichever applies to you during scoping. None of this is legal advice; bring your own counsel.
Assurance
Certification status, without the marketing tense.
Plenty of vendors write “aligned with” and “designed to meet” and hope you read it as certified. Here is the actual state.
| Control | Status | Note |
|---|---|---|
| Facility ISO/IEC 27001 | In place | Held by the facility operator |
| Facility ISO 22301 | In place | Business continuity |
| PDPA processor agreement | In place | Executed per customer |
| TAC ISO/IEC 27001 | In progress | Audit scheduled; scope covers the control plane |
| SOC 2 Type II | In progress | Observation window opens after ISO |
| Penetration test | Annual | Independent; report available under NDA |
| Customer audit right | Contractual | Annual, on term contracts |
Sovereign tier
Some institutions cannot have an egress path at all.
For those cases the deployment sits in a dedicated cage or a rack you own, with no route to the internet, updates delivered under change control, and staff vetted to your standard. Model weights are loaded physically and the control plane is source-available so your team can read what it does.
It is slower to change, more expensive to run and harder to support. It is also the only configuration some regulators will accept, so it exists.
See the Sovereign tierTalk to us
Send us your security questionnaire.
We will complete it before the first meeting rather than after the fourth. If there is a control we do not have, it will say so on the form.
Direct line sales@thaiaicloud.co.th · Replies in one business day, Thai or English.