Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Ivanti Neurons for ITSM Work in China? Data Residency, ICP & Cross-Border Rules

Ivanti Neurons for ITSM is the system of record for your China IT estate. Its cloud SaaS is hosted offshore on Microsoft Azure with no mainland-China region, so your China IT staff's and requesters' personal information and your CMDB sit abroad — a PIPL cross-border and data-residency matter; but it is also self-hostable on-premises, so it can run in-country. A compliance-first look at residency, ICP and the IT-estate record.

Does Ivanti Neurons for ITSM work in China?

Whether you can run Ivanti Neurons for ITSM in China is a data-residency and licensing question, not a speed one. The platform is the system of record for your China IT estate — the personal information of your IT staff and ticket requesters, plus the CMDB, asset inventory and tickets that map how your China operation is built and run.

Ivanti's cloud SaaS is hosted offshore on Microsoft Azure with no mainland-China region, so running the China estate there puts that personal information and that security-sensitive record abroad — a PIPL cross-border transfer (Articles 38–40, with Article 13/23 notice and separate consent), and for a CIIO or high-volume handler an in-country-storage duty under CSL Article 39 (formerly Article 37). But Ivanti Neurons for ITSM is also available on-premise, which you install and run yourself — so you can deploy it in-country, keep the employee PII and the CMDB in the mainland, and the compliant path stays open.

This is a risk picture, not a verdict — your obligations turn on your role, data volumes and what your tickets hold. Our China team can map your Ivanti ITSM exposure with you →

What Ivanti Neurons for ITSM's own documentation says about China

FactPrimary source
In Ivanti's own words, Neurons for ITSM has an on-premise deployment you install and run yourself: its On-Premise help opens, "If you are an on-premise customers looking for information about installing, configuring, system requirements, ops console, performance tuning, and web services, you are in the right place." That self-hostable model is the residency lever — it lets you run the platform on China-resident infrastructure inside the mainland. Ivanti Docs — Neurons for ITSM On-Premises (2025), retrieved 2026-10-11
Ivanti's own subprocessor list shows the Neurons for ITSM cloud SaaS is hosted on Microsoft Azure in Australia, Canada, Germany, the United Kingdom and the United States (the wider Neurons platform adds Japan) — none in mainland China. On the cloud SaaS, your China staff's and requesters' personal information and your CMDB are held offshore. Ivanti — Subprocessors, retrieved 2026-10-11
Holding your China staff's and requesters' personal information offshore is a cross-border transfer under PIPL (Articles 38–40), on top of the Article 13/23 notice and separate consent. The duty lands on you, the handler — not on Ivanti. China's Personal Information Protection Law (PIPL), Articles 13, 23 and 38–40
For a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires personal information generated in China to be stored in the mainland; and a public, China-facing self-service or ticket portal is an internet information service that needs an ICP filing bound to mainland hosting. China's Cybersecurity Law, Article 39 (formerly Article 37); ICP filing requirement

Sources verified by the 21YunBox compliance team on 2026-10-11.

For an enterprise running Ivanti Neurons for ITSM for a mainland-China operation, the question that matters is not whether the service desk paints quickly from Shanghai. It is where the platform is hosted and where the data it holds comes to rest — because an ITSM platform is the system of record for your entire China IT estate. It carries the personal information of your China IT staff and of every requester who files a ticket, and it carries the CMDB, asset inventory, service maps and incident and change tickets that describe, in concentrated form, how your China operation is built and run. Ivanti Neurons for ITSM is offered two ways — a cloud SaaS hosted offshore on Microsoft Azure with no mainland-China region, and an on-premise deployment you install and run yourself — and that deployment choice is the whole story: an on-premise, China-resident instance can keep that data in the mainland, while the offshore cloud cannot. Four prongs decide it — the personal information’s residency and cross-border exposure; the CMDB-and-ticket security-governance exposure a speed test never sees; automated triage or AI that makes decisions about people; and an ICP filing for any China-facing self-service portal.

Ivanti's own Neurons for ITSM On-Premises online help on docs.ivanti.com, whose Overview page opens by welcoming on-premise customers looking for information about installing, configuring and setting system requirements — confirming Neurons for ITSM has an on-premise deployment you install and run yourself on infrastructure you control, including inside mainland China.
“If you are an on-premise customers looking for information about installing, configuring, system requirements, ops console, performance tuning, and web services, you are in the right place.” — Ivanti's own Neurons for ITSM On-Premise help confirms an on-premise deployment you install and run yourself, so the platform can live on China-resident infrastructure inside the mainland. Source: Ivanti Docs — Neurons for ITSM On-Premises (2025)

Ivanti Neurons for ITSM in China at a glance

What decides it In Ivanti's own terms — and China's law
What it holds Two things China's law cares about. The personal information of your China IT staff and of every requester who files a ticket — names, work email, phone, org, sometimes device and location. And your CMDB and tickets — hostnames, network topology, asset inventory and service maps, plus incident and change records that routinely carry internal system detail, configuration and sometimes embedded secrets. Together, a concentrated map of how your China operation is built and run.
Offshore cloud, or on-premise Ivanti Neurons for ITSM is offered as a cloud SaaS and as an on-premise deployment you install and run yourself. Ivanti's own subprocessor list shows the cloud is hosted on Microsoft Azure in Australia, Canada, Germany, the UK and the US (the wider Neurons platform adds Japan) — none in mainland China. The on-premise option is the residency lever: run it on China-resident infrastructure and the data can stay in the mainland. An offshore cloud instance cannot.
Personal-information residency & cross-border Run the China estate on the offshore cloud and your staff's and requesters' personal information rests abroad — a cross-border transfer (数据出境) under PIPL Articles 38–40, on top of the Article 13/23 notice and separate consent. For a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires China-collected personal information to be stored in the mainland.
The CMDB & tickets — the distinctive second half The half a reachability check never sees. Your whole China IT estate's configuration, topology and operational secrets sitting offshore is both a cross-border data issue and, for sensitive operations, may implicate “important data” (重要数据) handling and data-security duties. Treat the classification as a risk to confirm with counsel, not a settled label — but the concentration of security-sensitive detail is real.
Automated handling, and the ICP door Ivanti's auto-triage and AI workflows that profile or decide about individuals bring in PIPL Article 24 on automated decision-making (notice and an opt-out). And any public, China-facing self-service or ticket portal is an internet information service, so it carries an ICP filing duty bound to mainland hosting.
Reachability is not the axis Whether the service desk loads quickly from the mainland is operational, not the compliance question. What decides it is where the platform is hosted and where the people-data and the IT-estate record live. 21YunBox helps you keep that data in-country, secure the consents, file the ICP for any portal, and deliver compliantly — the 21YunBox Optimizer — in front of the Ivanti instance you already run.

What it actually holds — your people’s data and your IT-estate record

Ivanti Neurons for ITSM is not a public-facing marketing site; it is the internal system of record for how IT serves your China operation, and it holds two kinds of data Chinese law cares about. The first is personal information: the directory of your China IT staff and the identity of every requester who opens a ticket — names, work email, phone number, organizational unit, and often the device and location attached to an incident. For a mainland workforce, all of that is personal information under China’s Personal Information Protection Law.

The second is the half a speed test never sees — and it is the one that makes an ITSM platform different from an ordinary business app. Your CMDB is a structured inventory of the hosts, network topology, services and assets that make up your China estate; your incident and change tickets routinely carry internal system detail, configuration and, in practice, embedded credentials and secrets. Taken together they are a concentrated, security-sensitive map of exactly how your China operation is built and run. Whether that record lives in the mainland or offshore is decided entirely by how you deploy Ivanti — the offshore cloud or an on-premise instance you place where you choose.

The doors: residency, the IT-estate record, automated handling, and ICP

Put the China estate on the offshore cloud and the first door opens. The staff and requester personal information in that instance rests abroad, which makes it a cross-border transfer (数据出境). The duty lands on you, the handler, not on Ivanti: PIPL Articles 13 and 23 require notice and a basis to collect the data, and Articles 38–40 require a transfer mechanism to send it offshore — a CAC security assessment, the CAC standard contract, or certification. And for a critical information infrastructure operator or a high-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, its substance unchanged) requires personal information generated in China to be stored in the mainland, which an offshore cloud cannot satisfy.

The CMDB-and-ticket record opens a second, quieter door. Beyond the personal information, the concentration of configuration, topology and operational secrets for your China estate is a data-security exposure in its own right, and for sensitive operations it may fall within “important data” (重要数据) handling with heightened data-security duties. This is a risk to map and settle with counsel rather than a classification to assert — but a reachability check will never surface it.

Two more doors follow from how you run the platform. Where Ivanti’s auto-triage, predictive or agentic workflows profile people or make decisions about them, PIPL Article 24 on automated decision-making attaches — transparency, fairness, and an opt-out from decisions made solely by automation. And the moment you expose a public, China-facing self-service or ticket portal, that portal is an internet information service and carries an ICP filing (备案) duty bound to a mainland hosting resource — which an on-premise, China-resident deployment can provide and an offshore one cannot.

Why a reachability check misses this

A probe from inside China can watch the Ivanti login screen paint and conclude “it works.” That answer is beside the point. The compliance exposure is not on the screen — it is in the data at rest and how it moves: the staff and requester personal information, and the CMDB, topology, asset inventory and ticket secrets that describe your China estate, all sitting on an offshore cloud. A page-load test measures none of that. It cannot see which region the tenant lives in, whether separate consent was taken, whether a transfer mechanism is in place, or that your most security-sensitive operational record is concentrated abroad. That is the competitor-proof second half of the question — and it is exactly why making an offshore ITSM merely reachable from the mainland is not the answer. Keeping the people-data and the IT-estate record in-country, with consent and an ICP-filed portal, is.

The lawful path — map, localize, deliver

There is a compliant way to run Ivanti Neurons for ITSM for a mainland-China operation, and because the platform is self-hostable its middle step is unusually clean — one that sits in front of the Ivanti instance you already run, with no rebuild and no migration.

First, map: our China compliance team inventories what your ITSM holds — the staff and requester personal information, the CMDB and asset data, the content of incident and change tickets, and any China-facing self-service portal — establishes where Ivanti is deployed today (often the offshore cloud), the ICP status of any portal domain, and the consent and residency basis each flow relies on. We build the technical picture; the legal conclusions are settled with counsel.

Then localize: this is where Ivanti’s on-premise option pays off directly. We help you run Neurons for ITSM on a China-resident path so the employee personal information and the CMDB and ticket record stay in the mainland, obtain the Article 13/23 notice and separate consent, honor the Article 24 opt-out for automated handling, and protect the security-sensitive IT-estate record. Localize means keeping the data on an in-country path — never a route that ships it offshore anyway.

Then deliver: any public, China-facing portal is an internet information service, so it carries an ICP filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of the Ivanti instance you already run, so it runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and never move personal information across the border by stealth. 21YunBox is a compliance overlay and partner to the ITSM platform you already run, not a competitor to it.

None of this is a verdict that Ivanti Neurons for ITSM is “blocked” or “illegal” in China; it is self-hostable software, and much of the exposure dissolves the moment you choose an in-country deployment. It is a risk-and-residency map, and which duties bite your case turns on your entity, your role under Chinese law, your data volumes, and what your tickets actually hold — worth settling the specifics with counsel before your China IT operation depends on it.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Ivanti Neurons for ITSM store Chinese employees' data in China?
In its cloud SaaS, no. Ivanti's own subprocessor list shows the ITSM cloud is hosted on Microsoft Azure in Australia, Canada, Germany, the UK and the US — no mainland-China region — so the staff and requester personal information in a China instance would rest offshore, a PIPL cross-border transfer. Because Neurons for ITSM is also available on-premise, you can instead deploy it on China-resident infrastructure and keep that data in the mainland.
Is it against the law to use Ivanti Neurons for ITSM in China?
Not inherently. The issues are the cross-border transfer of personal information (which PIPL permits with notice, separate consent and a transfer mechanism), any in-country-storage duty if you are a CIIO or high-volume handler, an ICP filing for a public self-service portal, and PIPL Article 24 where auto-triage or AI makes decisions about people. The CMDB and tickets add a data-security exposure, since your China IT estate's configuration and secrets would sit offshore. Whether each duty bites turns on your role and volumes — treat it as a risk to settle with counsel, not a blanket prohibition.
Can 21YunBox help make our Ivanti ITSM stack compliant in China?
Yes. Our China compliance team maps what your ITSM holds — employee PII, the CMDB and asset data, ticket content, and any China-facing portal — and where it is hosted, helps you keep that data in-country (including a self-hosted, China-resident Ivanti deployment), secures the Article 13/23 consent and the Article 24 opt-out, files the ICP for any public portal, and stands up compliant in-country delivery in front of the Ivanti instance you already run. Get in touch to work through your specific case.

ARTICLES RELATED TO IVANTI NEURONS FOR ITSM

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.