Data Sovereignty and the Cross-Border Transfer Nobody Audits
.jpg)
Data sovereignty is the requirement that data stays subject to the laws of a jurisdiction you chose. Most programs enforce it on storage and never audit inspection, which means a legacy cloud proxy decrypting employee traffic in a point of presence two countries away is an unreviewed cross-border transfer sitting in the middle of the architecture. dope.security removes that transfer instead of documenting it, because inspection runs on the device and the plaintext never enters a vendor data center at all.
Your storage map is finished. Your inspection map does not exist.
Every sovereignty program starts the same way. Someone builds a register of systems, tags each one with a hosting region, chases the SaaS vendors for data processing agreements, and lists the subprocessor countries. That is real work and it produces a real map. The map is also missing the one system that touches every byte of web traffic the company generates.
If you send traffic through a cloud proxy, that proxy terminates TLS. It holds the plaintext. It inspects it, logs metadata about it, and re-encrypts it on the way out. That happens inside a data center owned by your security vendor, in whatever city their routing picked, under whatever law applies there. Nobody put it on the register, because it does not look like storage. It is transit. It still meets every practical definition of a transfer, and it is worth reading how the major platforms differ on this before you accept it as unavoidable: our breakdown of how Zscaler and Netskope route and decrypt traffic is the shortest way to see the pattern.
The awkward part is that this is not a gap in anyone's compliance work. It is a gap in the model. Sovereignty frameworks were written when the risky thing was a database in the wrong region. The riskiest thing in a 2026 estate is a decryption point that follows your employees around the planet and reports to a vendor.
What sovereignty actually asks of a security control
Strip out the acronyms and a sovereignty requirement asks three questions of any system in the path. Where does this system see my data in the clear. Which government can compel access to it there. Can I prove the answer without taking a vendor's word for it.
A cloud proxy answers badly on all three. It sees everything in the clear by design, since that is what break and inspect means. The jurisdiction is whichever PoP the anycast route or the client config picked this morning, which can change without a change ticket on your side. And proving it means trusting a vendor status page and a subprocessor list, because you have no visibility into which node handled which session.
An on-device architecture answers differently, and it is not a marketing difference. When the TLS session terminates in an agent on the laptop, the plaintext exists on hardware you own, in the country the employee is standing in, governed by the law that already applies to that employee's device. There is no third jurisdiction to disclose because no third party ever held it. We walk through the mechanics of that split in on-device versus cloud proxy SSL inspection.
The detour is a jurisdiction problem before it is a latency problem
Security teams already know the performance cost of backhauling. Every request leaves the device, travels to the vendor's nearest node, gets inspected, goes to the destination, and comes back the same way. The measured penalty runs roughly 40 to 80 milliseconds when a user sits near a PoP and 150 to 400 milliseconds when they do not.
What gets missed is that the milliseconds and the jurisdictions are the same fact. Latency is the distance to the decryption point. Distance to the decryption point is, in most of the world, a border crossing. A team in Singapore whose traffic inspects in Tokyo is not just paying 90 milliseconds. It is exporting plaintext to Japan on every request, all day, with no record of it anywhere in the sovereignty register.
Want the number for your own network? The Fly-Direct Speed Test measures your real round-trip latency in the browser, then shows what a legacy proxy detour adds to it, app by app. See how on-device inspection with dope.SWG removes the detour, or book a 20-minute demo.
Takeaway: the detour you measure in milliseconds is the same detour your privacy counsel should be measuring in jurisdictions.
How the major SSE platforms handle the question
Every vendor below is a capable product with real customers. The point is not that they are bad at security. The point is that a cloud-proxy design cannot avoid putting your plaintext in someone else's building, and each vendor's own documentation says where.
Zscaler (ZIA)
Zscaler forwards all traffic to a ZEN or Service Edge node before it reaches the internet, which is the architecture, not a configuration choice. Latency compounds as inspection modules stack, and Gartner has cited a 10 to 20 percent throughput drop. For restricted geographies Zscaler sells China Premium and Plus uplifts, so the jurisdictional answer in that region is a separately licensed one.
Netskope
Netskope runs its own NewEdge proxy cloud and publishes an SLA of under 10 milliseconds for non-decrypted traffic and 50 milliseconds once decryption is on, a documented five-fold penalty for the act of inspecting. Netskope also sells China Premium and Elite SKUs. The feature set is genuinely strong. The plaintext still lands in NewEdge.
Forcepoint ONE
Forcepoint backhauls through roughly 300 AWS points of presence, which means your inspection jurisdiction is effectively AWS region selection made by someone else's routing. Forcepoint's own knowledge base confirms that its China offices are blocked, so for teams operating there the sovereignty conversation ends before it starts.
Palo Alto Prisma Access
Prisma Access runs on Google Cloud and AWS infrastructure, and its Explicit Proxy mode makes decryption mandatory. Mainland China coverage is partner-operated and requires an ICP filing, which adds a second commercial entity to the list of parties that can see your traffic.
Cloudflare One and Gateway
Cloudflare's uniform anycast design is fast and gives no regional isolation, which is exactly the trade-off it sounds like: you do not choose the node. The November 18 2025 outage, triggered by a single oversized config file, produced global 5xx errors for around five hours and is the clearest illustration of what one control plane spanning every jurisdiction means in practice. Mainland access runs through a JD Cloud partnership plus an ICP filing.
Broadcom and Symantec Cloud SWG
Broadcom's own knowledge base documents specific China hostname formats (KB 208150) alongside latency and timeout guidance (KB 174576, KB 169051). The lineage runs Blue Coat to ProxySG to WSS to Cloud SWG across four owners, and the architecture has stayed a cloud proxy the whole way.
dope.security
dope.security inspects on the device. There is no PoP, no backhaul, and no vendor-side plaintext, so there is no inspection jurisdiction to disclose. It works in mainland China with no paid geographic uplift. The console is one console, built from scratch rather than assembled from acquisitions, which matters here because a sovereignty audit is only as good as your ability to answer questions from a single source.
Where on-device inspection stops and honesty starts
An on-device model is not a claim that nothing ever leaves the endpoint. Two things are worth stating plainly, because a sovereignty reviewer will ask.
- Web inspection: legacy proxies decrypt in a vendor data center; dope.security decrypts in the agent on the endpoint, so the plaintext of a session never crosses a border for the purpose of inspection.
- DLP classification: legacy platforms typically send content to a vendor-operated inspection tier and retain it for tuning; Dopamine DLP classifies file uploads and AI prompts through zero-retention APIs, so content is not stored or used for model training, and the design is covered by US Patent 12,464,023.
- Data at rest: legacy CASB deployments proxy your SaaS traffic to see files; CASB Neural inspects OneDrive and Google Drive through APIs and reports what is externally shared, without inserting a proxy hop into user traffic.
- Policy distribution: legacy agents poll a cloud for policy on a 30 to 60 minute cycle; dope.console pushes policy in seconds, and the agent keeps cached policy in fallback mode so enforcement does not depend on a reachable control plane.
That is the honest version. The claim is not zero data movement. The claim is that the one movement sovereignty programs most consistently fail to document, bulk plaintext of employee web traffic landing in a foreign vendor PoP, does not happen at all. If you are building the privacy argument rather than the performance one, our note on privacy and data residency in an on-device model covers the reviewer questions in more detail.
China is where this stops being theoretical
Most sovereignty debates stay abstract until someone opens an office in a restricted geography. Then the architecture answers for you. Several major platforms sell China connectivity as a paid uplift or route it through a local partner with an ICP filing, which means the jurisdiction question has a price and a third party attached to it. Others simply do not work there, and their own documentation says so.
An agent that inspects locally and sends traffic direct does not need a special regional design, because it never needed the detour in the first place. That is the same property that makes the performance story work, and it is why teams with distributed footprints tend to arrive at the same place from two different directions. Greylock Partners, a firm with a device-first and heavily mobile team, moved off Cisco Umbrella in 27 days from first proposal to signed contract, in part because DNS-layer filtering missed HTTPS traffic and the SWG component still backhauled through Cisco data centers.
What to do with this before your next audit
You do not need a new framework. You need three lines added to the one you have.
- Add the inspection point to the register. For every control that terminates TLS, record the city, the operating entity, and whether you or the vendor chooses it.
- Ask each vendor to name the jurisdiction in writing per region, including any partner-operated coverage and any geography sold as an uplift.
- Test whether removing the detour is even hard. If inspection can run on the endpoint, the transfer disappears rather than getting documented, and the latency number improves as a side effect.
If you are early in comparing options, the shortlist logic in our guide to Zscaler alternatives maps cleanly onto sovereignty criteria, because architecture is the variable in both cases.
Sovereignty programs have spent a decade getting very good at answering where data sits. The unanswered question is where it gets opened, and for most companies running a cloud proxy the answer is a building they have never visited, in a country they never selected, chosen by a routing decision they cannot see. Move inspection to the device and the question stops needing an answer.
Ready to take the detour out of your architecture? See how Fly Direct works or book a 20-minute demo.
Frequently Asked Questions
Is SSL inspection in a cloud proxy a cross-border data transfer?
In practice it functions like one. The proxy terminates TLS and holds your plaintext in whichever data center handled the session, so if that data center sits in another country, employee data has crossed a border and become subject to that country's law. Most sovereignty registers only track storage, so the transfer usually goes undocumented. dope.security avoids the question by decrypting on the endpoint instead.
What is the difference between data sovereignty, data residency, and data localization?
Residency is where data physically sits. Localization is a legal requirement that it sit in a specific country. Sovereignty is the broader question of which government's law governs it, which is why an inspection point matters even though it stores nothing long term. A cloud proxy can satisfy a residency clause for storage and still hand plaintext to a different jurisdiction in transit.
Does choosing a regional PoP solve the problem?
It narrows it without closing it. You are still trusting the vendor's routing to keep sessions inside the region you picked, and anycast designs explicitly do not guarantee regional isolation. You also still have a third party holding plaintext, which is the part a reviewer cares about. Removing the decryption hop is a cleaner answer than choosing a better location for it.
Do I need a separate SKU for China with dope.security?
No. dope.security works in mainland China without a paid geographic uplift, because there is no point of presence to reach. Several cloud-proxy vendors sell China connectivity as a premium tier or route it through a local partner with an ICP filing, which adds both cost and another entity to your disclosure list.
Does on-device DLP send my data anywhere?
Dopamine DLP classifies file uploads and AI prompts using zero-retention APIs, so content is not stored by the provider and is not used for model training. That is a narrower and more auditable data flow than routing all web traffic through a vendor inspection tier, and it is the flow you should document rather than the one you should assume. The architecture is covered by US Patent 12,464,023.
How does this change my answer to a customer security questionnaire?
It shortens it. Instead of naming a vendor, a set of PoP regions, and a subprocessor chain for web inspection, you state that TLS inspection happens on the managed endpoint and no third party receives session plaintext. That is one sentence you can prove from your own deployment rather than several you have to source from a vendor.


.jpg)
.jpg)
.jpeg)

