Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does CircleCI Work in China? Data Residency, Localization & PIPL Cross-Border

CircleCI's cloud runs offshore on AWS and GCP with no mainland-China region, so the source code it checks out, your pipeline secrets and contexts, and build logs come to rest outside the mainland — a PIPL cross-border and data-residency exposure. Self-hosted runners move job execution in-country, not the control plane; CircleCI Server can. A compliance-first look at CircleCI data residency and PIPL cross-border transfer.

Does CircleCI work in China?

Yes — a China developer can reach CircleCI and push pipelines, but that is the easy half. CircleCI is primarily a cloud service with no mainland-China region, so the source code it checks out, the pipeline secrets and contexts it stores, and the build logs and artifacts it produces all come to rest offshore — a data-residency gap, and a PIPL cross-border transfer wherever China personal information rides along.

Source code is a trade-secret asset that routinely carries embedded credentials, keys and personal information in configs, fixtures and test data; pipeline contexts and environment variables are secrets; build logs and artifacts capture both. Collected from a China team and held on CircleCI's offshore cloud, any personal information in them is a cross-border transfer under PIPL (notice, separate consent, a transfer mechanism, Articles 38–40), and for a CIIO or high-volume handler it must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). Self-hosted runners run jobs on your own machines but still "poll CircleCI for jobs," so they move execution in-country, not the control plane or the stored secrets — a partial lever. CircleCI Server, the fully self-hosted control plane, is the stronger one.

This is a risk map, not a verdict — what applies turns on your entity, your data volumes and whose personal information sits in your pipelines. Our China team can map your exposure →

What CircleCI's own documentation says about China

FactPrimary source
CircleCI's self-hosted runners move job execution in-country — but not the control plane. CircleCI's own runner documentation states that the "Container-agent polls CircleCI for jobs, spins up ephemeral pods with an injected task-agent, and executes each job within each pod." So a self-hosted runner runs jobs on your own machines, yet it reaches back to CircleCI's cloud for work. Your pipeline configuration, encrypted contexts and stored secrets stay on CircleCI's offshore control plane — which makes self-hosted runners a partial residency measure, not full in-country residency. CircleCI — Self-hosted runner concepts (circleci.com), retrieved 2026-10-10
CircleCI Server is the fully self-hosted lever — it runs the control plane in your own cluster. CircleCI's documentation describes CircleCI Server (current release 4.10) as "an on-premises CI/CD platform for enterprise customers" that "operates within your Kubernetes cluster" and is suited to organizations that must "operate within their firewall, in a private cloud, or in a data center." It "can be installed using cloud resources (GCP or AWS), locally, and in an air-gapped environment." Deployed on mainland infrastructure, it keeps the source code, secrets, contexts and build state in-country — which the cloud offering, with no mainland-China region, cannot. CircleCI — CircleCI Server 4.10 overview (circleci.com), retrieved 2026-10-10
China personal information in your pipelines, crossing to an offshore CI/CD cloud, is a cross-border transfer under PIPL. Where commits, CI logs, contexts, fixtures or artifacts carry names, emails or real customer data — common in test data and configuration — sending them to CircleCI's offshore cloud is a cross-border transfer of personal information governed by PIPL Articles 38–40: it requires notice, separate consent, and a lawful transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). The security-assessment measures set when that assessment is mandatory. PIPL Articles 38–40; CAC Measures on the Standard Contract and the Security Assessment for Outbound Data Transfers, retrieved 2026-10-10
A data-localization duty can require the code and secrets to stay in the mainland — which an offshore cloud cannot satisfy. For a critical-information-infrastructure operator or a high-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). A CI/CD cloud with no mainland-China region cannot meet an in-country storage duty; a self-hosted deployment on mainland infrastructure can. Any public China-facing surface you operate also needs an ICP filing. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); ICP filing (State Council Order No. 292), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a mainland-China audience, the deciding question about CircleCI is not whether a developer can reach it or whether a git push triggers a pipeline — both are routine. It is where the assets CircleCI handles are allowed to come to rest. A CI/CD platform holds some of your most sensitive material: the source code it checks out to build (a trade secret in itself, and routinely the credentials, keys and personal information that live in configs, fixtures and test data), the pipeline secrets and contexts it stores, and the build logs and artifacts it produces. CircleCI is primarily a cloud service, and its cloud runs offshore — on AWS and GCP, with no mainland-China region to select. So for a China team, that code, those secrets and those logs come to rest outside the country. CircleCI does offer self-hosted options — but they are not all equal, as the evidence below shows.

CircleCI's self-hosted runner documentation stating that the container-agent polls CircleCI for jobs, showing that self-hosted runners execute jobs on your own machines while the control plane and work queue remain with CircleCI's cloud
"Container-agent polls CircleCI for jobs" — so even a self-hosted runner on your own machines reaches back to CircleCI's cloud for work, which means job execution can run in-country while the control plane, pipeline contexts and stored secrets stay on CircleCI's offshore platform. Source: circleci.com/docs/guides/execution-runner/runner-concepts

CircleCI in China at a glance

What decides itIn CircleCI's own terms — and China's law
Where the code, secrets and state physically rest (the region reality)CircleCI is primarily a cloud service, hosted offshore on AWS and GCP, with no mainland-China region to select. Code checkouts, pipeline secrets and contexts, build logs and artifacts come to rest outside the mainland. In-country residency is possible only by self-hosting — and only CircleCI Server keeps the control plane in-country.
What CircleCI holds, and why it is personal informationYour source code (a trade secret, often with embedded credentials, keys and personal information in configs, fixtures and test data), pipeline secrets and contexts, build logs, artifacts and any infrastructure-as-code state. Wherever commits, logs or fixtures carry names, emails or real customer data, that is personal information under PIPL — so where it rests is a legal question, not a performance one.
Your China users' records when the platform is offshoreSend China personal information in repositories, CI logs, contexts or artifacts to CircleCI's cloud and you are making a cross-border transfer under PIPL (Articles 38–40): notice, separate consent, and one transfer mechanism — a CAC security assessment, the standard contract, or certification.
The in-country storage duty (CIIO / high-volume handler)A critical-information-infrastructure operator or high-volume handler must keep China personal information on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore CI/CD cloud structurally cannot.
Reachability is not the axis (and the China-facing surface)Whether CircleCI is reachable from China is a delivery matter, not the legal test; residency of the code, secrets and state is. The lawful levers are to run CircleCI Server in-country (self-hosted runners alone move only job execution) and to put any China-facing surface in front of it on ICP-filed delivery.

Where the data actually rests

CircleCI is, first and foremost, a cloud service. When your team connects a repository and runs a pipeline, CircleCI’s cloud checks out your source code into its build environment, reads and injects the secrets and contexts you have stored with it, and collects the logs and artifacts each job produces. That cloud runs offshore — on AWS and GCP — and it offers no mainland-China region to select. There is no data-residency control that pins a China team’s pipelines to the mainland, so on the default cloud the code, the secrets and the build state all come to rest outside the country.

CircleCI does offer self-hosted execution, but the two shapes are not equal — and the difference is the whole compliance story. Self-hosted runners let jobs run on machines you own: CircleCI’s documentation explains that the container-agent “polls CircleCI for jobs,” spins up ephemeral pods and runs each job inside one. That moves job execution in-country — but the runner still reaches back to CircleCI’s cloud for work, so your pipeline configuration, your encrypted contexts and your stored secrets stay on the offshore control plane. Runners in-country are not the same as the control plane and the stored secrets in-country.

The fuller lever is CircleCI Server, the fully self-hosted product. CircleCI describes it as “an on-premises CI/CD platform for enterprise customers” that “operates within your Kubernetes cluster” — and the Nomad control plane that schedules jobs “runs inside your Kubernetes cluster.” Run that cluster on mainland infrastructure and the control plane, the contexts and the secrets all stay in the country. That is the shape that can actually satisfy an in-country residency duty.

What it holds is personal information

A CI/CD platform is not a cache or an edge node — it handles your crown-jewel assets. The source code CircleCI checks out is a trade secret in its own right, and in practice it carries more: credentials, API keys and tokens embedded in configuration, and personal information sitting in fixtures, seed data and test datasets. The pipeline secrets and contexts CircleCI stores are, by definition, secrets. The build logs and artifacts it produces can capture both — printed environment values, test output built from real records, packaged data. Where you manage infrastructure as code, the state CircleCI touches maps your whole topology and often holds secrets in plaintext.

Two bodies of law bear on that. First, wherever commits, CI logs, contexts or fixtures carry the personal information of people in China — names, emails, identifiers, real customer records in test data — sending them to CircleCI’s offshore cloud is a cross-border transfer, and PIPL Articles 38–40 govern it: notice, separate consent, and one lawful transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The security-assessment measures set when that assessment is mandatory rather than optional.

Second, a harder duty can sit on top. A critical-information-infrastructure operator or a high-volume handler must store China personal information inside the mainland — PIPL Article 40 and the data-localization rule in Cybersecurity Law Article 39 (formerly Article 37). A CI/CD cloud with no mainland-China region cannot satisfy an in-country storage duty, because the data is, by definition, not in the country. And the source-code and trade-secret exposure runs in parallel with the PIPL analysis — it does not wait for personal information to be in scope.

Running it on a no-China-region cloud doesn’t meet the residency duty — and what does

The fix is not to make an offshore CircleCI endpoint reachable from China. Reachability was never the problem; residency of the code, the secrets and the state is. If your obligations require China personal information — or your source-code and secrets governance requires the build system itself — to stay on the mainland, the lawful lever is to run CircleCI in-country: CircleCI Server on mainland infrastructure, where the control plane, contexts and secrets all stay in the country. Self-hosted runners alone do not get you there, because they move only job execution while the control plane and stored secrets remain on CircleCI’s offshore cloud — a partial measure, honestly labelled.

Crucially, this is not a migration project in the usual sense. You are not re-platforming your application or rebuilding your pipelines; you are placing a compliant, in-country CI/CD control plane where the code and secrets must live, and putting the China-facing surfaces that sit in front of it — the dashboards and developer portals your mainland users reach — on ICP-filed, in-country delivery in front of the stack you already run. Localize means an in-country deployment, not a tunnel back to an offshore endpoint.

This page maps exposure; it is not a legal ruling. Your actual duties turn on your entity, how you classify the data in your pipelines, your transfer volumes and whether you are a critical-information-infrastructure operator — so settle those specifics with qualified China counsel before you rely on any single path.

The lawful path — map, localize, deliver

21YunBox is a compliant overlay, not a migration — and a partner to CircleCI and to your platform team, not a competitor to them.

  • Map. We read the PIPL cross-border, data-residency, data-localization (CII) and ICP obligations against your entity, your data volumes and the personal information that actually rides in your repositories, CI logs and contexts — so you know which duties bite before you move anything.
  • Localize. We run the CI/CD control plane in-country so the code, secrets and build state stay on mainland soil — CircleCI Server (or another self-managed deployment) on mainland infrastructure, or a licensed in-country / sovereign option — and keep consented, in-country storage for what must stay. Localize means an in-country deployment, not a tunnel to an offshore endpoint; self-hosted runners alone move only execution.
  • Deliver. Any China-facing surface in front of the platform — the dashboards, the developer and reporting portals your mainland users hit — runs over ICP-filed, in-country delivery (the 21YunBox Optimizer), in front of the stack you already run. No rebuild, no second codebase.

The result is a CI/CD setup that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →

Frequently Asked Questions

Does CircleCI have a data center or region in mainland China?
No. CircleCI is primarily a cloud service, and its cloud runs offshore — on AWS and GCP, with no mainland-China region to select — so the source code it checks out, your pipeline secrets and contexts, and your build logs and artifacts come to rest outside the mainland. The in-country option is to self-host: CircleCI's self-hosted runners move job execution onto your own machines, and CircleCI Server (release 4.10) runs the full control plane inside your own Kubernetes cluster. Reaching CircleCI from China is not the issue; where the code and secrets rest is.
Do CircleCI's self-hosted runners make us compliant in China?
Only partially, and it is worth being precise. Self-hosted runners run your jobs on your own machines, but CircleCI's own documentation shows the runner "polls CircleCI for jobs" — so your pipeline configuration, encrypted contexts and stored secrets remain on CircleCI's offshore cloud control plane. Runners in-country are not the same as the control plane and stored secrets in-country. For a genuine in-country deployment you run CircleCI Server on mainland infrastructure; treat the specifics as a question for counsel against your data and your entity.
Can 21YunBox help make our CircleCI setup compliant in China?
Yes. Our China team can map your PIPL cross-border and data-residency exposure — for your entity, your data volumes and the personal information that actually rides in your repos, logs and contexts — and stand up a lawful in-country path: CircleCI Server (or another self-managed deployment) on mainland infrastructure, with ICP-filed, in-country delivery in front of the surfaces your China users reach, over the stack you already run. We are a compliant overlay, not a migration. Get in touch to work through your case.

ARTICLES RELATED TO CIRCLECI

CATEGORIES

DevOps

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.