Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does CyberArk Work in China? Privileged-Access Data Residency, PIPL & In-Country PAM

CyberArk's Identity Security Platform SaaS — Privilege Cloud, Secrets Manager and CyberArk Identity — is hosted across AWS regions in the Americas, EMEA and APAC, and its own documentation shows none in mainland China, so the privileged credentials, secrets, vault contents and session recordings it holds for your China systems rest offshore. For mainland China that makes their collection a cross-border transfer under PIPL, with an elevated edge where privileged-access data governs critical systems and may count as important data. A compliance-first look at the residency, cross-border and in-country-storage questions, and the lawful path — CyberArk's own self-hosted PAM Vault on China-resident infrastructure.

Does CyberArk work in China?

CyberArk is reachable from mainland China — so the honest answer is that reachability is not the problem. What decides the China question is data residency and cross-border transfer, and the data at issue is the most sensitive you hold.

CyberArk's Identity Security Platform SaaS — Privilege Cloud, Secrets Manager and CyberArk Identity, now delivered under the Idira brand after CyberArk's acquisition by Palo Alto Networks — is hosted in a fixed set of AWS regions, and its own documentation shows none in mainland China; the nearest are Singapore, Tokyo, Mumbai, Sydney and Jakarta. So the privileged credentials, secrets, vault contents and privileged-session recordings it holds for your China systems rest offshore, which makes their collection a cross-border transfer (数据出境) under PIPL (Articles 38–40). Because that data is your control plane, where it secures critical systems it may be "important data" — raising China's data-export security assessment — and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) requires in-country storage no offshore region can meet.

21YunBox maps your exposure, localizes the China estate onto CyberArk's own self-hosted Vault on China-resident infrastructure, and delivers your China-facing surfaces in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel. Get a compliance assessment →

What CyberArk's own documentation says about China

FactPrimary source
CyberArk's own documentation lists the AWS regions its Identity Security Platform runs in — and none is in mainland China. CyberArk's platform docs (now branded "Idira Docs") state: "This topic lists the supported AWS regions for each Idira service in ISPSS," and that each service is "deployed in the closest supported region." The regions enumerated span the Americas, EMEA and APAC — the nearest to the mainland being Singapore, Tokyo, Mumbai, Sydney and Jakarta — with no mainland-China region, so Privilege Cloud, Secrets Manager and the vault contents they hold for your China systems rest offshore. CyberArk (Idira) Docs — "Validate supported AWS regions for ISPSS" (docs.cyberark.com), retrieved 2026-10-09
CyberArk operates in-country regions for data-sovereignty markets — but none in mainland China. Its regional-availability list includes dedicated regions in the UAE (me-central-1) and India (Mumbai, ap-south-1), added so regulated customers could keep identity data onshore. In-country residency is therefore a real option for the product in some jurisdictions — there is simply no mainland-China region to select, so a China tenant still resolves to a data center outside the country. CyberArk (Idira) Docs — "Validate supported AWS regions for ISPSS" (docs.cyberark.com), retrieved 2026-10-09
Moving China privileged-access data to an offshore CyberArk region is a PIPL cross-border transfer. Holding credentials, secrets, vault contents and privileged-session recordings collected from identifiable people and systems in mainland China in an AWS region outside the country triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The duty sits with the handler (you), not with CyberArk as processor. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09
Privileged-access data can carry heavier duties than ordinary SaaS data. Because privileged credentials and session recordings are the control plane for the systems they secure, where your CyberArk deployment protects critical information infrastructure that data may qualify as "important data," and its transfer may require China's data-export security assessment (数据出境安全评估) before anything leaves. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires China-generated personal information to be stored in China — a duty an offshore region cannot meet. Cybersecurity Law of the PRC, Article 39 (formerly Article 37); Measures for the Security Assessment of Data Exports (数据出境安全评估办法), CAC (cac.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a company running privileged access management across its China systems, the first question about CyberArk is usually whether the consoles load from the mainland. They are reachable on the wire — but that is not where the China decision is settled. CyberArk concentrates the most sensitive data in your estate in one place: the privileged credentials and secrets in its vault, and the recordings and audit trail of every privileged session. What decides whether you can use it in China is where that data comes to rest, and whether moving it there was lawful — a data-residency and cross-border question, not a performance one.

And CyberArk answers the first half in its own documentation. Its Identity Security Platform Shared Services — the SaaS layer behind Privilege Cloud, Secrets Manager and CyberArk Identity, now delivered under the Idira brand following CyberArk’s acquisition by Palo Alto Networks, though the documentation still lives at docs.cyberark.com — is hosted in a fixed set of AWS regions, and none of them is in mainland China. So the keys to your China systems sit offshore, and a different body of law decides whether that was allowed.

CyberArk's platform documentation page 'Validate supported AWS regions for ISPSS' (branded 'Idira Docs'), listing the supported AWS regions for the Identity Security Platform Shared Services across the Americas, EMEA and APAC — the APAC entries being Sydney, Mumbai, Jakarta, Tokyo and Singapore — with no mainland-China region
CyberArk's own platform documentation (now “Idira Docs”) sets out where its Identity Security Platform Shared Services — Privilege Cloud among them — runs: “This topic lists the supported AWS regions for each Idira service in ISPSS,” and “When a region is chosen for a service, that service is deployed in the closest supported region.” The regions it enumerates span the Americas, EMEA and APAC — the nearest to the mainland being Singapore, Tokyo, Mumbai, Sydney and Jakarta — with none in mainland China, so the privileged credentials and session recordings it holds for your China systems rest offshore. Source: CyberArk (Idira) Docs — Validate supported AWS regions for ISPSS

CyberArk in China at a glance

What decides it In CyberArk's own terms — and China's law
What it is CyberArk's Identity Security Platform is a privileged access management (PAM) and identity-security suite. Across Privilege Cloud, Secrets Manager and CyberArk Identity it holds the most sensitive operational data you have: privileged credentials and secrets, the contents of the vault, and the recordings and audit trail of privileged sessions on your China systems.
Is it reachable from the mainland? Reachability is not where the China decision sits. Even where the consoles load from the mainland, what matters is where the privileged-access data they manage comes to rest, and whether it was lawful to move it there. This page publishes no China latency figure — speed is not the axis.
Where does the data live? Offshore. CyberArk's own documentation enumerates the AWS regions its SaaS runs in — across the Americas, EMEA and APAC — with the nearest being Singapore, Tokyo, Mumbai, Sydney and Jakarta. There is no mainland-China region; a service is “deployed in the closest supported region,” and the closest supported region is still outside the country.
Moving China privileged-access data into it Credentials, secrets, vault contents and session recordings tied to identifiable people and systems are personal information. Holding them in an offshore region is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Where that data governs critical systems it may also be “important data,” raising a data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet.
The lawful path Keep the China estate's privileged-access data in-country: deploy CyberArk's own self-hosted Privileged Access Manager — the Vault you run on infrastructure you control — on China-resident infrastructure, with consented in-country processing and storage, and keep CyberArk's SaaS for your other regions. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

The crown-jewels data sits in an offshore region

CyberArk’s whole purpose is to concentrate the most dangerous data in one hardened place: the privileged credentials and secrets that unlock your systems, the vault that stores them, and the recordings and audit trail of what administrators did in each privileged session. For your China systems, that is the control plane itself — the single store an attacker, or a regulator, would care about most.

Its own documentation sets out where that store lives. The Identity Security Platform Shared Services (ISPSS) — the SaaS behind Privilege Cloud, Secrets Manager and CyberArk Identity — runs in a fixed list of AWS regions across the Americas, EMEA and APAC, and CyberArk states that each service is “deployed in the closest supported region.” The nearest regions to the mainland are Singapore, Tokyo, Mumbai, Sydney and Jakarta — every one of them offshore. There is no mainland-China region on the list, so a tenant provisioned for your China estate still resolves to a data center outside the country. Vault contents and session recordings follow the region you are placed in; placing them closer does not place them inside China.

Offshore privileged-access data is a cross-border transfer — and the stakes are higher here

The gate is the same one every offshore service meets, but the data makes it sharper. The privileged credentials, secrets, vault contents and privileged-session recordings CyberArk holds for identifiable administrators and systems in China are personal information, and keeping them in an AWS region outside the mainland is a cross-border transfer (数据出境) of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, not CyberArk the processor: Articles 38–40 require notice, a separate consent distinct from any general use agreement, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Two things raise the stakes above an ordinary SaaS transfer. First, what this data is: privileged credentials and session recordings are the control plane for the systems they secure, so where your CyberArk deployment protects critical information infrastructure, the data it holds can itself rise to “important data,” and a transfer of important data may require China’s data-export security assessment (数据出境安全评估) before anything leaves. Second, residency: for a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China — an in-country storage duty that an offshore CyberArk region cannot satisfy. Which of these bite your specific deployment is a risk to confirm with counsel against what you actually vault, record and secure.

A nearer AWS region is still not a China region

The instinct is to pick the closest region and call residency handled — Singapore or Tokyo for an Asian footprint. But proximity is not residency. None of CyberArk’s APAC regions is in mainland China, so moving your tenant from, say, Frankfurt to Singapore relocates the cross-border transfer; it does not end it.

It is worth being precise about what CyberArk does and does not offer, because the pattern is instructive. CyberArk has stood up in-country regions specifically for data-sovereignty markets — its list includes the UAE (me-central-1) and India (Mumbai, ap-south-1), regions added so regulated customers could keep identity data onshore. In-country residency is therefore a real option for the product in some jurisdictions; CyberArk simply has no mainland-China region to select. Keeping China’s privileged-access data in the country is consequently a different deployment model, not a different region toggle: CyberArk’s own self-hosted Privileged Access Manager — the Vault you run on infrastructure you control — stood up on China-resident infrastructure for the China estate. That is a legal design decision before it is a technical one.

None of this makes CyberArk “blocked” or “illegal” in China — it is reachable and widely used. It is a risk-and-residency map: which obligations bite turns on your entity, the systems you secure, the data you vault and record, and who your administrators are — and it is worth settling with counsel before your privileged-access data depends on it.

The lawful path — map, localize, deliver

There is a lawful shape to running privileged access management for a China estate, and it starts with the data, not the network.

First, map. Our China team works through the PIPL exposure attached to what CyberArk holds for your China systems — which credentials, secrets, vault entries and session recordings were collected or generated in the mainland and must stay there, what (if anything) may lawfully leave, whether the systems you secure make that data “important data” or bring a critical-information-infrastructure duty into play, and what your notice and separate-consent flow has to cover. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.

Then localize. For the China estate we stand up and integrate CyberArk’s own self-hosted Privileged Access Manager — the Vault you run on your own infrastructure — on China-resident infrastructure, with consented in-country processing and storage, so the privileged-access data stops leaving the country by default. You keep CyberArk’s SaaS for the regions where it already serves you; what changes is that the mainland’s crown-jewels data stays in the mainland.

Then deliver. Any China-facing console, portal or administrative surface that has to be reachable from inside the mainland is itself a service delivered in China, so it carries an ICP filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is privileged access management that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or any network restriction; we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is CyberArk available in mainland China?
CyberArk's consoles and SaaS endpoints are reachable from the mainland, so availability is not the obstacle — and this page publishes no China latency figure, because speed is not the axis. The real question is data residency: CyberArk's Identity Security Platform runs only in AWS regions outside mainland China (the nearest are Singapore, Tokyo, Mumbai, Sydney and Jakarta), so the privileged credentials, secrets and session recordings it holds for your China systems rest offshore. Treat the specifics as a risk to confirm with counsel.
Is sending our China privileged-access data to CyberArk's cloud a cross-border transfer?
If your tenant is in any CyberArk region — all of which are outside the mainland — then the credentials, secrets, vault contents and privileged-session recordings it holds for your China systems are stored offshore, a cross-border transfer (数据出境) under PIPL: notice, a separate consent, and one transfer mechanism. Because this data is the control plane for the systems it secures, where it protects critical information infrastructure it may be "important data" (raising a data-export security assessment), and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty no offshore region meets. Confirm your exact obligations with counsel.
Can we just pick CyberArk's Singapore or Tokyo region to keep data in China?
No — none of CyberArk's regions is in mainland China, so a nearer region does not satisfy a China residency duty; moving a tenant from Frankfurt to Singapore relocates the cross-border transfer, it does not end it. Keeping the China estate's privileged-access data in-country means a different deployment model: CyberArk's own self-hosted Privileged Access Manager — the Vault you run on infrastructure you control — stood up on China-resident infrastructure. 21YunBox maps what must stay, localizes it onto that in-country deployment, and delivers your China-facing surfaces on ICP-filed infrastructure — it is not a route around China's data-export rules.

ARTICLES RELATED TO CYBERARK

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.