Every security questionnaire we fill in asks where the data is hosted. Fair question. On its own it settles less than most buyers think.

Data can sit in a London rack and still be readable by someone who is not you and not us.

The question that decides your exposure is who holds the encryption keys.

What the CLOUD Act actually does

The US CLOUD Act, passed in 2018, lets US authorities compel a US-incorporated company to produce data in its possession, custody or control, wherever in the world that data is stored. The nationality of the company is the point. The postcode of the server is not.

Three consequences buyers often miss.

UK hosting does not settle it. A US company running a London data centre is still a US company. Slough rather than Virginia does not remove the obligation.

Your contract does not settle it. A data processing agreement is an arrangement between you and your supplier. A US court order is not a party to that agreement and is not bound by it. Contractual comfort does not override a lawful demand under another country’s law.

Calling yourself the controller does not settle it. Controller and processor under UK GDPR allocates responsibility for personal data. Useful. Necessary. It does not release your processor from duties it owes under the law of its own country.

One more split that gets run together. Adequacy decisions and standard contractual clauses govern whether you may send data somewhere. The CLOUD Act governs whether someone can be compelled to produce data they already hold. Different questions. Different answers. Satisfying the first does not touch the second.

That is the gap in most “we’re hosted in the UK” answers, including some of our own older pages. Location is a transfer question. Keys are a compulsion question.

This is not a hypothetical

On 18 June 2025, Anton Carniaux, Microsoft France’s director of public and legal affairs, sat in front of a French Senate inquiry on public procurement and digital sovereignty.

He was asked, under oath, whether he could guarantee that French citizens’ data would never be transmitted to US authorities without the explicit agreement of the French government.

He said no. He added that it had never happened.

Nothing had gone wrong. No breach. No scandal. An honest answer about where a legal obligation sits, given by someone who was not free to answer otherwise.

That is the useful thing about the exchange. It was not a failure of the provider. It was a description of the structure.

If you want the quieter version of the same structure: some US legal demands arrive with a gag. The provider may be forbidden from telling you the request existed. You cannot challenge what you are not allowed to hear about. Architecture is what you have left when the letter never reaches you.

What does settle it

If a provider is compelled to produce your data, the only question that matters is what they are able to produce.

If they hold your documents in a readable form, they produce your documents. If they hold your documents encrypted with keys they have never possessed, they produce ciphertext. A demand for the keys goes to whoever actually holds them.

So do not ask a vendor whether they promise to refuse. Promises are not tested until the day they are tested, and by then you are not in the room. Ask whether they could comply if compelled, and what compliance would actually yield.

How Projectfusion is built

Better to say this plainly than let a questionnaire discover it.

Your documents are stored in UK data centres on infrastructure provided by Wasabi. Wasabi is a US company. On the reasoning above, that ought to worry you. It would, except for the second half of the architecture.

The encryption keys sit on Projectfusion’s own servers, in the UK. They are never passed to the storage provider. Encrypt and decrypt happen on our side, before anything is written to storage and after it is read back. Wasabi sees ciphertext. Always.

If Wasabi were compelled to produce what it holds, what it holds is encrypted data it has no means of reading. There is no key in that building to hand over.

We are a UK company. Any demand for the keys would have to come to us, through UK legal process, where UK law and your own advice apply.

Projectfusion is not a zero-knowledge product. We hold the keys. That is how a data room searches, watermarks, redacts and serves a view-only file without sending the original into the wild. The claim is narrower: the storage vendor cannot read the room, and a US demand served on that vendor does not produce your clients’ documents.

What we are not claiming

We are not claiming immunity from the law. We are a UK company subject to UK law. If served with a lawful UK order we would respond as any UK company would. Anyone telling you their architecture puts them beyond legal reach is selling you something that does not exist.

The claim is smaller and more useful than immunity. It closes one specific route to your clients’ documents — the route that stays open with any provider who holds both the data and the keys. Given how much of the professional services stack now sits with US-owned vendors, closing that route once is worth more than it sounds.

Which raises the related point. Exposure stacks.

If your document store, your email, your file transfer and your practice system all sit with US-incorporated vendors, you have not made one decision about jurisdiction. You have made four, and they compound.

You will not take the firm off Microsoft 365 this year. Do not pretend otherwise. The data room is one of the few remaining places where the decision is still yours, still discrete, and still made at the moment a deal or a disclosure starts. That is the decision worth making cleanly.

What to ask any vendor, including us

Questions with mechanical answers. Not questions answered by a logo.

Certifications are worth having. We hold them. A certificate tells you a process was audited on a particular date. It does not tell you who can read the files. Ask the mechanical question.

The bottom line

Hosting location is a proxy. A reasonable first question. A poor last one.

Sovereignty is who holds the keys.

If you want to walk this through with IT or compliance — the architecture, not the summary — get in touch.