Does CyberArk Work in China? Privileged-Access Data Residency, PIPL & In-Country PAM
CyberArk's Identity Security Platform SaaS — Privilege Cloud, Secrets Manager and CyberArk Identity — is hosted across AWS regions in the Americas, EMEA and APAC, and its own documentation shows none in mainland China, so the privileged credentials, secrets, vault contents and session recordings it holds for your China systems rest offshore. For mainland China that makes their collection a cross-border transfer under PIPL, with an elevated edge where privileged-access data governs critical systems and may count as important data. A compliance-first look at the residency, cross-border and in-country-storage questions, and the lawful path — CyberArk's own self-hosted PAM Vault on China-resident infrastructure.
Does CyberArk work in China?
CyberArk is reachable from mainland China — so the honest answer is that reachability is not the problem. What decides the China question is data residency and cross-border transfer, and the data at issue is the most sensitive you hold.
CyberArk's Identity Security Platform SaaS — Privilege Cloud, Secrets Manager and CyberArk Identity, now delivered under the Idira brand after CyberArk's acquisition by Palo Alto Networks — is hosted in a fixed set of AWS regions, and its own documentation shows none in mainland China; the nearest are Singapore, Tokyo, Mumbai, Sydney and Jakarta. So the privileged credentials, secrets, vault contents and privileged-session recordings it holds for your China systems rest offshore, which makes their collection a cross-border transfer (数据出境) under PIPL (Articles 38–40). Because that data is your control plane, where it secures critical systems it may be "important data" — raising China's data-export security assessment — and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) requires in-country storage no offshore region can meet.
21YunBox maps your exposure, localizes the China estate onto CyberArk's own self-hosted Vault on China-resident infrastructure, and delivers your China-facing surfaces in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel. Get a compliance assessment →
What CyberArk's own documentation says about China
| Fact | Primary source |
|---|---|
| CyberArk's own documentation lists the AWS regions its Identity Security Platform runs in — and none is in mainland China. CyberArk's platform docs (now branded "Idira Docs") state: "This topic lists the supported AWS regions for each Idira service in ISPSS," and that each service is "deployed in the closest supported region." The regions enumerated span the Americas, EMEA and APAC — the nearest to the mainland being Singapore, Tokyo, Mumbai, Sydney and Jakarta — with no mainland-China region, so Privilege Cloud, Secrets Manager and the vault contents they hold for your China systems rest offshore. | CyberArk (Idira) Docs — "Validate supported AWS regions for ISPSS" (docs.cyberark.com), retrieved 2026-10-09 |
| CyberArk operates in-country regions for data-sovereignty markets — but none in mainland China. Its regional-availability list includes dedicated regions in the UAE (me-central-1) and India (Mumbai, ap-south-1), added so regulated customers could keep identity data onshore. In-country residency is therefore a real option for the product in some jurisdictions — there is simply no mainland-China region to select, so a China tenant still resolves to a data center outside the country. | CyberArk (Idira) Docs — "Validate supported AWS regions for ISPSS" (docs.cyberark.com), retrieved 2026-10-09 |
| Moving China privileged-access data to an offshore CyberArk region is a PIPL cross-border transfer. Holding credentials, secrets, vault contents and privileged-session recordings collected from identifiable people and systems in mainland China in an AWS region outside the country triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The duty sits with the handler (you), not with CyberArk as processor. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09 |
| Privileged-access data can carry heavier duties than ordinary SaaS data. Because privileged credentials and session recordings are the control plane for the systems they secure, where your CyberArk deployment protects critical information infrastructure that data may qualify as "important data," and its transfer may require China's data-export security assessment (数据出境安全评估) before anything leaves. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires China-generated personal information to be stored in China — a duty an offshore region cannot meet. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37); Measures for the Security Assessment of Data Exports (数据出境安全评估办法), CAC (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a company running privileged access management across its China systems, the first question about CyberArk is usually whether the consoles load from the mainland. They are reachable on the wire — but that is not where the China decision is settled. CyberArk concentrates the most sensitive data in your estate in one place: the privileged credentials and secrets in its vault, and the recordings and audit trail of every privileged session. What decides whether you can use it in China is where that data comes to rest, and whether moving it there was lawful — a data-residency and cross-border question, not a performance one.
And CyberArk answers the first half in its own documentation. Its Identity Security Platform Shared Services — the SaaS layer behind Privilege Cloud, Secrets Manager and CyberArk Identity, now delivered under the Idira brand following CyberArk’s acquisition by Palo Alto Networks, though the documentation still lives at docs.cyberark.com — is hosted in a fixed set of AWS regions, and none of them is in mainland China. So the keys to your China systems sit offshore, and a different body of law decides whether that was allowed.
CyberArk in China at a glance
| What decides it | In CyberArk's own terms — and China's law |
|---|---|
| What it is | CyberArk's Identity Security Platform is a privileged access management (PAM) and identity-security suite. Across Privilege Cloud, Secrets Manager and CyberArk Identity it holds the most sensitive operational data you have: privileged credentials and secrets, the contents of the vault, and the recordings and audit trail of privileged sessions on your China systems. |
| Is it reachable from the mainland? | Reachability is not where the China decision sits. Even where the consoles load from the mainland, what matters is where the privileged-access data they manage comes to rest, and whether it was lawful to move it there. This page publishes no China latency figure — speed is not the axis. |
| Where does the data live? | Offshore. CyberArk's own documentation enumerates the AWS regions its SaaS runs in — across the Americas, EMEA and APAC — with the nearest being Singapore, Tokyo, Mumbai, Sydney and Jakarta. There is no mainland-China region; a service is “deployed in the closest supported region,” and the closest supported region is still outside the country. |
| Moving China privileged-access data into it | Credentials, secrets, vault contents and session recordings tied to identifiable people and systems are personal information. Holding them in an offshore region is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Where that data governs critical systems it may also be “important data,” raising a data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet. |
| The lawful path | Keep the China estate's privileged-access data in-country: deploy CyberArk's own self-hosted Privileged Access Manager — the Vault you run on infrastructure you control — on China-resident infrastructure, with consented in-country processing and storage, and keep CyberArk's SaaS for your other regions. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind. |
The crown-jewels data sits in an offshore region
CyberArk’s whole purpose is to concentrate the most dangerous data in one hardened place: the privileged credentials and secrets that unlock your systems, the vault that stores them, and the recordings and audit trail of what administrators did in each privileged session. For your China systems, that is the control plane itself — the single store an attacker, or a regulator, would care about most.
Its own documentation sets out where that store lives. The Identity Security Platform Shared Services (ISPSS) — the SaaS behind Privilege Cloud, Secrets Manager and CyberArk Identity — runs in a fixed list of AWS regions across the Americas, EMEA and APAC, and CyberArk states that each service is “deployed in the closest supported region.” The nearest regions to the mainland are Singapore, Tokyo, Mumbai, Sydney and Jakarta — every one of them offshore. There is no mainland-China region on the list, so a tenant provisioned for your China estate still resolves to a data center outside the country. Vault contents and session recordings follow the region you are placed in; placing them closer does not place them inside China.
Offshore privileged-access data is a cross-border transfer — and the stakes are higher here
The gate is the same one every offshore service meets, but the data makes it sharper. The privileged credentials, secrets, vault contents and privileged-session recordings CyberArk holds for identifiable administrators and systems in China are personal information, and keeping them in an AWS region outside the mainland is a cross-border transfer (数据出境) of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, not CyberArk the processor: Articles 38–40 require notice, a separate consent distinct from any general use agreement, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.
Two things raise the stakes above an ordinary SaaS transfer. First, what this data is: privileged credentials and session recordings are the control plane for the systems they secure, so where your CyberArk deployment protects critical information infrastructure, the data it holds can itself rise to “important data,” and a transfer of important data may require China’s data-export security assessment (数据出境安全评估) before anything leaves. Second, residency: for a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China — an in-country storage duty that an offshore CyberArk region cannot satisfy. Which of these bite your specific deployment is a risk to confirm with counsel against what you actually vault, record and secure.
A nearer AWS region is still not a China region
The instinct is to pick the closest region and call residency handled — Singapore or Tokyo for an Asian footprint. But proximity is not residency. None of CyberArk’s APAC regions is in mainland China, so moving your tenant from, say, Frankfurt to Singapore relocates the cross-border transfer; it does not end it.
It is worth being precise about what CyberArk does and does not offer, because the pattern is instructive. CyberArk has stood up in-country regions specifically for data-sovereignty markets — its list includes the UAE (me-central-1) and India (Mumbai, ap-south-1), regions added so regulated customers could keep identity data onshore. In-country residency is therefore a real option for the product in some jurisdictions; CyberArk simply has no mainland-China region to select. Keeping China’s privileged-access data in the country is consequently a different deployment model, not a different region toggle: CyberArk’s own self-hosted Privileged Access Manager — the Vault you run on infrastructure you control — stood up on China-resident infrastructure for the China estate. That is a legal design decision before it is a technical one.
None of this makes CyberArk “blocked” or “illegal” in China — it is reachable and widely used. It is a risk-and-residency map: which obligations bite turns on your entity, the systems you secure, the data you vault and record, and who your administrators are — and it is worth settling with counsel before your privileged-access data depends on it.
The lawful path — map, localize, deliver
There is a lawful shape to running privileged access management for a China estate, and it starts with the data, not the network.
First, map. Our China team works through the PIPL exposure attached to what CyberArk holds for your China systems — which credentials, secrets, vault entries and session recordings were collected or generated in the mainland and must stay there, what (if anything) may lawfully leave, whether the systems you secure make that data “important data” or bring a critical-information-infrastructure duty into play, and what your notice and separate-consent flow has to cover. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.
Then localize. For the China estate we stand up and integrate CyberArk’s own self-hosted Privileged Access Manager — the Vault you run on your own infrastructure — on China-resident infrastructure, with consented in-country processing and storage, so the privileged-access data stops leaving the country by default. You keep CyberArk’s SaaS for the regions where it already serves you; what changes is that the mainland’s crown-jewels data stays in the mainland.
Then deliver. Any China-facing console, portal or administrative surface that has to be reachable from inside the mainland is itself a service delivered in China, so it carries an ICP filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is privileged access management that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or any network restriction; we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
