Does HashiCorp Vault Work in China? Data Residency, Localization & PIPL Cross-Border
HashiCorp Vault concentrates your API keys, tokens, certificates and encryption keys — the keys to everything. Self-managed Vault runs on mainland-China infrastructure (the lawful lever); HCP Vault, the managed service, offers no mainland-China region, so those secrets rest offshore — a PIPL cross-border transfer. A compliance-first look at where your secrets are allowed to rest.
Does HashiCorp Vault work in China?
Whether HashiCorp Vault works in China is a data-residency question about where your secrets and keys are allowed to rest — not whether it connects — and self-hosted Vault is the lawful lever.
Vault is a secrets manager that gathers your API keys, tokens, TLS certificates, database credentials and encryption keys into one place — the keys to everything, the most concentrated store of sensitive material most organizations keep. Self-managed Vault is a binary you run yourself, including on mainland-China infrastructure, so the secrets stay on mainland soil; it is never "blocked." HCP Vault, the managed service on HashiCorp Cloud Platform, runs only on offshore AWS and Azure regions with no mainland-China region to select, so those secrets come to rest abroad — a cross-border transfer PIPL governs (Articles 38–40) wherever the keys protect or unlock China personal information, and for a critical-information-infrastructure operator or high-volume handler, a breach of the in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). The exposure is the offshore managed deployment, not the software.
This is a risk map, not a ruling — your obligations turn on your entity, your data volumes and whose personal information your secrets protect. Our China team can map your HashiCorp Vault exposure with you →
What HashiCorp Vault's own documentation says about China
| Fact | Primary source |
|---|---|
| HCP Vault, the managed service, has no mainland-China region. HashiCorp Cloud Platform runs on the global AWS and Azure partitions: its own supported-environments documentation states "HCP services support AWS in these regions:" and lists Oregon, Virginia, Ohio, Canada Central, Ireland, London, Frankfurt, Tokyo, Singapore and Sydney (plus a parallel set of Azure regions) — none in mainland China, and no China data-residency option. Secrets held in HCP Vault therefore come to rest offshore. | HashiCorp — HCP supported AWS environments, retrieved 2026-10-10 |
| Self-managed Vault is a binary you run on your own infrastructure — the in-country lever. HashiCorp's install documentation offers Vault as a package or precompiled binary you "install the binary manually" and operate yourself, so you can run the cluster on mainland-China infrastructure and keep the secrets on mainland soil. (HashiCorp relicensed Vault from the MPL to the Business Source License in August 2023, prompting the Linux Foundation OpenBao fork, and HashiCorp was acquired by IBM in a deal that closed February 2025 — neither changes where your secrets rest.) | HashiCorp — Install Vault, retrieved 2026-10-10 |
| China secrets held in an offshore HCP Vault are a cross-border transfer under PIPL. Where the keys, certificates and credentials Vault holds protect or contain the personal information of people in China and the service sits offshore, the handler — you, the operator, not HashiCorp or IBM — must give notice, obtain separate consent and satisfy one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. PIPL Articles 38–40 govern that transfer, and the security-assessment measures set when the assessment is mandatory. | Personal Information Protection Law of the PRC, Articles 28 and 38–40 |
| CIIOs and high-volume handlers owe an in-country storage duty an offshore secrets service cannot meet. Personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). The 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. Because self-managed Vault runs identically in-country, self-hosting on mainland infrastructure meets this duty without a migration. | PIPL Article 40; PRC Cybersecurity Law Article 39 (formerly Article 37) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a team serving mainland China, the question about HashiCorp Vault was never whether it installs or whether a developer can reach it. It installs and runs anywhere you put it. Vault is a secrets-management system: it holds the API keys, tokens, TLS certificates, database credentials and encryption keys that unlock the rest of your stack — gathered into one place, the single most concentrated store of sensitive material most organizations keep. So the real question is a residency one: where are those secrets and keys allowed to come to rest? The answer splits by how you run it. Self-managed Vault — the binary you download and operate yourself — is residency-flexible: run the cluster on mainland-China infrastructure and the secrets stay on mainland soil, the lawful lever. HCP Vault, the managed service on HashiCorp Cloud Platform, runs only on offshore AWS and Azure regions with no mainland-China region to select, so the keys to everything come to rest abroad.
HashiCorp Vault in China at a glance
| What decides it | In HashiCorp Vault's own terms — and China's law |
|---|---|
| Where the secrets physically rest | Vault has no region of its own; your deployment does. Self-managed Vault is a binary you run on your own infrastructure, including mainland-China soil, so you keep the secrets in-country. HCP Vault, the managed service on HashiCorp Cloud Platform, runs only where HCP runs: its own docs say "HCP services support AWS in these regions:" and list Oregon, Virginia, Ireland, Frankfurt, Tokyo, Singapore and Sydney, plus a comparable set of Azure regions — none in mainland China. |
| What it holds, and why residency bites | Vault concentrates the keys to everything: API keys, tokens, TLS certificates, database and cloud credentials, and the encryption keys that protect data elsewhere. Where those keys encrypt or unlock the personal information of people in China — including Article 28 sensitive data such as financial, government-ID or health fields — and where KV secrets, PKI certificate subjects or Vault's audit logs carry names, emails or other identifiers, personal information is in scope directly, not just by reference. |
| Your mainland secrets in the store | Secrets, certificates and keys generated or used in China and held in an offshore HCP Vault are a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is you, the operator — not HashiCorp, and not IBM, which now owns it. |
| In-country storage duty | A critical information infrastructure operator or high-volume handler owes an in-country storage duty an offshore secrets service cannot meet — mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. |
| Is it reachable? | Treat reachability as the delivery half, not the question — the software runs fine in-country. The lawful lever is to run Vault in-country (self-hosted on mainland infrastructure, or a licensed sovereign option), and any China-facing surface in front of it — the admin UI, the API edge, a reporting portal — needs an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33). |
Where the secrets actually rest
Vault does not have a region; your deployment does. The engine is the same code whether it runs in Frankfurt, Singapore or Shanghai, so the residency question is entirely about the host you put it on — and here the two deployment shapes part company.
Self-managed Vault is distributed as software you run yourself. HashiCorp’s own install documentation offers it as a package or a precompiled binary you “install the binary manually,” which you then operate on your own servers — a cluster you can stand up on mainland-China infrastructure as readily as anywhere else. Run it there and the secrets never leave the mainland. (For the record, HashiCorp moved Vault’s license from the MPL to the Business Source License in August 2023 — prompting the OpenBao fork, now a Linux Foundation project — and HashiCorp itself was acquired by IBM in a deal that closed in February 2025; none of that changes where your secrets come to rest, which is still set by where you deploy.)
HCP Vault is the other shape: the fully managed service HashiCorp runs for you on HashiCorp Cloud Platform. HCP in turn runs on the global AWS and Azure partitions, and HashiCorp’s own documentation enumerates exactly which regions — “HCP services support AWS in these regions,” then Oregon, Virginia, Ohio, Canada Central, Ireland, London, Frankfurt, Tokyo, Singapore and Sydney, with a parallel set of Azure regions. There is no mainland-China region on that list, and no China data-residency option to toggle. Point your organization’s secrets engine at HCP and the most concentrated store of sensitive material you hold comes to rest abroad; under the Personal Information Protection Law, moving the China personal information those secrets protect or contain out of the country is a cross-border transfer, and the handler responsible is you.
What it holds is the keys to everything — and often personal information
Vault earns this scrutiny because of what it stores. Most tools touch one slice of your data; Vault holds the credentials to all of them — the database passwords, cloud access keys, signing certificates and encryption keys that, taken together, are the keys to your entire estate. Concentrating that material offshore is already a trade-secret and security concern. It becomes a data-protection one the moment those secrets meet China personal information: the encryption keys that protect your China customer records, the credentials a mainland service uses to read them, the certificates that identify your China systems and, directly, any names, emails or tokens written into a KV secret or captured in an audit-log entry. Each of those is personal information under PIPL once it describes an identifiable person, and some is Article 28 sensitive personal information — financial, government-ID, biometric or health data — which carries a higher bar of specific purpose, strict necessity and separate consent.
That is why residency is not merely good practice here. For a critical information infrastructure operator, and for a handler whose volumes cross the regulators’ thresholds, personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore secrets service structurally cannot satisfy that duty — the material is, by definition, in the wrong country. And where an export is permitted at all, crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment before any of it lawfully leaves.
Running it on HCP Vault doesn’t meet the residency duty — and what does
The honest summary is narrow and important: nothing about HashiCorp Vault is “blocked,” and you do not need to leave it. The exposure is not the software; it is a managed deployment that parks the mainland’s most sensitive secrets outside the mainland. Fix the deployment and the exposure closes.
The lawful lever is to run the same Vault in-country. Self-hosted on mainland infrastructure — or, where you want a managed experience, on a licensed in-country or sovereign-cloud equivalent — Vault behaves exactly as it does abroad: the same KV and PKI engines, the same policies, the same automation, so the secrets China requires to stay in-country do, with no rewrite and no second secrets store. Pointing a mainland Vault agent back at the offshore HCP endpoint is not localization and does not meet the storage duty; standing up a lawful in-country Vault is. Where a subset of secrets may lawfully cross the border, you keep that transfer minimized, consented and backed by a transfer mechanism, while any China-facing surface in front of Vault earns its own ICP filing.
This is a risk map, not a verdict. Whether you owe in-country storage, a transfer mechanism, a separate consent, an ICP filing, or some combination turns on your entity, your data volumes, how much of what your secrets protect is personal or sensitive, and who your users are — and it is worth settling with counsel before you decide where a single mainland key lives.
The lawful path — map, localize, deliver
You do not have to drop HashiCorp Vault to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a tool you already run, a partner that sits alongside your stack, not a competitor to it. There are three moves, and they fit together.
Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your actual entity, your data volumes, and whose personal information your secrets protect and your audit logs record — so the exposure is written down before anything is moved.
Localize. Because the risk is where the secrets rest, we run Vault in-country — self-hosted on mainland infrastructure, or on a licensed in-country or sovereign-cloud option — so the keys and credentials China requires to stay on mainland soil do. Localize means a lawful in-country deployment of the same Vault, never a tunnel back to an offshore endpoint; only the minimized, lawfully transferable subset ever crosses.
Deliver. For any China-facing surface in front of Vault — the admin UI, the API edge, the reporting portal your mainland users and operators hit — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.
The goal is plain: your HashiCorp Vault deployment runs legally and compliantly for your users in China.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization
- China’s data-export security assessment measures
