Guide

MCP Gateway With EU Data Residency: Where Gatana Keeps Your Data

An MCP gateway holds three kinds of sensitive data: stored credentials, the content of tool calls, and the audit trail. This guide shows where Gatana Cloud processes each kind. It also shows which sub-processors touch the data, what crosses the EU border, and how to keep all of the data inside your own network.

· Erik Jonsson Thorén, Founder, Gatana

Short answer: Gatana Cloud stores customer data at rest in the European Union. Live data is on bare-metal servers in Germany. Encrypted backups are in France. Encryption keys are in Google Cloud KMS in an EU region. Traffic in transit passes the edge of Cloudflare. Other data stays in the EU unless an owner enables the optional AI assistant. Enterprise customers can self-host.

Three kinds of data

An MCP gateway stands between agents and every system that they use. Three kinds of data pass through it or stay in it:

  1. Credentials. API keys and OAuth tokens for the connected services. The gateway stores them so that agents can act without the keys reaching a laptop. This is the most sensitive data in the system.
  2. Tool call content. The arguments that an agent sends and the results that a service returns. They pass through the gateway on every call. The audit metadata stays behind. Artifacts and persistent storage stay behind too, where a team uses them.
  3. The audit trail. Who asked, which agent acted, which server and tool, when, and with what outcome.

Account data, such as names and email addresses, surrounds these. The conversations of the in-app AI assistant exist only where an organization turns the assistant on.

Where Gatana Cloud processes each kind

The table is the sub-processor list from Section 5.2 of our Data Processing Agreement, with the kind of data that each party touches.

Data Where it is processed Operated by
Live database: credentials, configuration, audit log, artifacts, assistant transcripts Germany, bare-metal Kubernetes cluster Hetzner
Encrypted database backups France OVHcloud
Keys that wrap the encryption key of each organization, and the key operation audit log EU region Google Cloud KMS
Transactional email: addresses and message content EU region Amazon Web Services (SES)
Traffic in transit: DNS, TLS termination, reverse proxy, bot protection Global edge network Cloudflare
AI assistant conversations, only where an organization owner has enabled the assistant United States, zero data retention OpenRouter

Customer personal data at rest is stored in the European Union. The DPA commits us to notify the registered contact before we add or replace a sub-processor. The contact has time to object.

How stored data is protected

Residency says where the bytes are. It does not say who can read them. The Security page describes the controls. The short form:

  • One key for each organization. Each tenant has its own AES-256-GCM data encryption key. A key held in Google Cloud KMS wraps it. The plaintext key exists only in application memory for the duration of an operation. It is never written to disk. Access to the database alone does not reveal customer data.
  • Key use is logged outside our control. Google Cloud Audit Logs record every encrypt and decrypt operation. Google holds these logs. We cannot change them. We treat an unexplained decrypt as a critical security incident.
  • Least privilege for people. Only personnel with a documented business need can access production systems. Multi-factor authentication protects that access. We review it each quarter. Emergency access follows a separate path. We log it and review it after every use.

What crosses the EU border

Two flows involve parties outside the EU.

Cloudflare, always. Cloudflare provides DNS, TLS termination and bot protection in front of Gatana. Requests pass its global edge network before they reach our cluster in Germany. Cloudflare sees IP addresses, request metadata and traffic in transit. The Standard Contractual Clauses cover this transfer, as Section 6.3 of the DPA sets out.

OpenRouter, only if you turn the assistant on. The in-app AI assistant is disabled by default. It processes nothing until an organization owner enables it in the dashboard. That step is the documented instruction of the controller. Conversations then go to OpenRouter, which routes each request to a model provider. We use OpenRouter under its zero data retention terms. Requests go only to endpoints whose providers commit not to store prompts or outputs and not to train on them. OpenRouter keeps technical metadata such as token counts for billing. Gatana stores the transcripts themselves in Germany. An organization can instead point the assistant at its own model endpoint. OpenRouter is then not used for that organization.

The services you connect are yours. When an agent calls GitHub, Slack or an internal API through the gateway, the data goes where that service is. Those providers are not sub-processors of Gatana. Your own agreements with them apply. Gatana stores the credential, the configuration and the audit record to make the call possible. That data is processed under the DPA on the infrastructure above.

Accendo Consulting GmbH in Zürich, Switzerland, operates Gatana. Switzerland has an adequacy decision from the European Commission. The Data Processing Agreement is published in full. It is part of the Terms of Service. It includes the EU Standard Contractual Clauses and the UK Addendum. It commits Gatana to notify affected customers of a security incident without undue delay and within 72 hours. It commits Gatana to assist with data subject requests, and to delete or return customer data at the end of the contract. A SOC 2 examination that covers the Security and Confidentiality criteria is in progress. The report will be available under NDA when it is issued.

How to keep all data in your own network

Two options exist for organizations whose rules do not permit a hosted gateway.

Self-host the full stack. Enterprise customers run Gatana on their own Kubernetes cluster with the official Helm chart:

helm install gatana oci://ghcr.io/gatana-ai/charts/gatana --namespace gatana -f values.yaml

Gatana the company never sees the configuration or the data. Credentials, tool calls and audit records stay inside the network. MCP servers that reach internal systems need no exposure to the internet. Two trade-offs apply. You schedule the upgrades. You provision the compute, the database and the networking.

Reach private servers from Gatana Cloud over Tailscale. Some teams accept that Gatana Cloud holds credentials and audit logs, but will not expose internal MCP servers. They connect those servers through Tailscale. The gateway reaches the server over the private network. Nothing is published to the internet.

Questions to ask any MCP gateway vendor

The same questions, in the order that a data protection officer asks them:

  • Where is customer data stored at rest, by country? Who operates the servers?
  • Which sub-processors touch the data, for what, and where? Is the list published? Do you give notice before changes?
  • What leaves the region in transit, and under which transfer mechanism?
  • Are credentials encrypted with a key for each customer? Where is that key held? Who can use it?
  • Which AI features send data to a model provider? Are they on by default? What does the provider keep?
  • Can the full product run in our own environment? What do we give up if it does?
  • Where is the audit trail stored? Can we stream it to our own systems?

Our answers are above. If one is missing or unclear, write to [email protected]. We will add it to this page.

FAQ

Questions, answered.

Where is Gatana Cloud hosted?

Gatana Cloud runs on bare-metal Kubernetes servers in Germany, operated by Hetzner. Encrypted database backups are stored in France with OVHcloud. The keys that wrap the encryption key of each tenant are in Google Cloud KMS in an EU region. The company behind Gatana is Accendo Consulting GmbH in Zürich, Switzerland.

Is Gatana GDPR compliant?

Gatana processes customer personal data as a processor under a published Data Processing Agreement. The DPA includes the EU Standard Contractual Clauses and the UK Addendum. It names every sub-processor with its location. It commits Gatana to breach notification within 72 hours. Data at rest stays in the European Union. The DPA is part of the Terms of Service.

Does any data leave the EU?

Two flows do. Cloudflare terminates TLS at its global edge. Thus traffic in transit passes the network of Cloudflare. If an organization owner enables the optional AI assistant, its conversations go to OpenRouter in the United States under zero data retention terms. All other data stays in the EU. This includes credentials, audit logs and backups.

Can I keep tool calls inside my own network?

Yes. Enterprise customers install Gatana on their own Kubernetes cluster with the official Helm chart. Gatana the company then never sees configuration or data. Gatana Cloud customers can reach private MCP servers over Tailscale. The servers stay closed to the internet.

Who can read the credentials stored in Gatana?

Each organization has its own AES-256-GCM key. A key in Google Cloud KMS wraps it. The plaintext key exists only in application memory during an operation. It is never written to disk. Google logs every wrap and unwrap outside the control of Gatana. Access to the database alone reveals nothing.

Is Gatana SOC 2 certified?

A SOC 2 examination is in progress. It covers the Security and Confidentiality trust services criteria. The report will be available to customers under NDA when it is issued. Until then, the Security page and the Data Processing Agreement describe the controls in force.

All guides