Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does MuleSoft Work in China? Data Residency, Cross-Border Integration Data & PIPL

MuleSoft's Anypoint Platform runs no mainland-China control plane and no CloudHub region in the country — its own documentation places CloudHub 2.0 only in North America, South America, the European Union and Asia-Pacific, and hosts the control plane in the US or the EU. So the personal information your integrations move, and the control-plane metadata the platform keeps, cross the border under PIPL. The lawful path is to run the Mule runtime in-country — self-hosted Runtime Fabric or on-premises — so China integration data stays in China. A compliance-first look at the data-residency, cross-border and ICP questions.

Does MuleSoft work in China?

MuleSoft's Anypoint control plane is reachable from the mainland, so connectivity is not where the China decision is settled. What settles it is data residency: MuleSoft runs no mainland-China control plane and no CloudHub region, so the data your integrations move — and the metadata the platform keeps — rest offshore.

MuleSoft's own CloudHub 2.0 Architecture doc places the managed runtime only in “North America, South America, the European Union, and Asia-Pacific,” and hosts the control plane in the US or the EU. An integration layer exists to move personal information between systems, so routing those flows through an offshore runtime is a cross-border transfer (数据出境) under PIPL — notice, a separate consent and a transfer mechanism (Articles 38–40) — and it may trigger China's data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires that data to be stored in China, which no offshore CloudHub region can satisfy.

The lawful path is to run the Mule runtime in-country — self-hosted Runtime Fabric or on-premises — so China integration data stays resident, sending out only what may lawfully leave, while delivering the China-facing apps on ICP-filed infrastructure. 21YunBox maps, localizes and delivers, and never uses or suggests circumvention. Treat the specifics as a risk to confirm with counsel.

What MuleSoft's own documentation says about China

FactPrimary source
MuleSoft runs no mainland-China region — CloudHub 2.0 deploys only to North America, South America, the EU and Asia-Pacific. MuleSoft's CloudHub 2.0 Architecture documentation states: “CloudHub 2.0 provides the ability to deploy apps in different regions of the world: North America, South America, the European Union, and Asia-Pacific,” and its published runtime regions (US, Canada, Brazil, Ireland, Germany, the UK, Singapore, Australia, Japan, India) include no location inside mainland China. MuleSoft, “CloudHub 2.0 Architecture” (docs.mulesoft.com), retrieved 2026-10-09
The Anypoint control plane is hosted in the US or the EU — offshore from China. MuleSoft states: “For the US Cloud and MuleSoft Government Cloud control planes, MuleSoft hosts the management console and platform services in the United States,” and “For the EU Cloud control plane, MuleSoft hosts these services in Europe.” The control-plane metadata it keeps about your integrations therefore rests outside the mainland. MuleSoft, “CloudHub 2.0 Architecture” (docs.mulesoft.com), retrieved 2026-10-09
MuleSoft supports a self-managed runtime you can run on infrastructure inside China. Its Anypoint Runtime Fabric documentation states: “You can use Runtime Fabric with managed Kubernetes services like EKS, AKS, GKE, and OKE, or with self-managed distributions like Red Hat OpenShift and Rancher,” and it also supports standalone on-premises Mule runtimes — so the runtime executing your China flows can be kept in-country. MuleSoft, “Anypoint Runtime Fabric Overview” (docs.mulesoft.com), retrieved 2026-10-09
Moving China personal information through an offshore runtime is a PIPL cross-border transfer, with a residency duty for CIIOs. Routing personal information collected in mainland China to an offshore CloudHub runtime triggers PIPL Articles 38–40 (notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification), and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) requires that data to be stored in China. Personal Information Protection Law of the PRC, Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

Whether MuleSoft “works” in mainland China is a data-residency question long before it is a connectivity one. MuleSoft’s Anypoint Platform is an integration and API-management layer — its whole job is to move data between your systems — so the decision does not turn on whether you can reach the control plane from Shanghai. It turns on where the data your integrations carry, and the metadata the platform keeps about them, come to rest. MuleSoft answers that in its own documentation: there is no mainland-China control plane and no CloudHub region in the country, so both the runtime executing your flows and the management plane behind them sit offshore.

MuleSoft's own CloudHub 2.0 Architecture documentation, 'Shared Global Regions' section, stating that CloudHub 2.0 deploys apps in North America, South America, the European Union and Asia-Pacific, and that MuleSoft hosts the management console and platform services in the United States for the US Cloud control plane — naming no mainland-China region
MuleSoft's own CloudHub 2.0 Architecture doc, under “Shared Global Regions”: “CloudHub 2.0 provides the ability to deploy apps in different regions of the world: North America, South America, the European Union, and Asia-Pacific,” and “For the US Cloud and MuleSoft Government Cloud control planes, MuleSoft hosts the management console and platform services in the United States.” No mainland-China region appears — so the runtime and the control-plane metadata both rest offshore. Source: docs.mulesoft.com — CloudHub 2.0 Architecture

MuleSoft in China at a glance

What decides it In MuleSoft's own terms — and China's law
What it is MuleSoft's Anypoint Platform is an integration and API-management platform (iPaaS). It splits into a control plane — the MuleSoft-managed environment where you design, deploy and manage integrations — and a runtime plane that executes them, either on CloudHub (MuleSoft-managed) or on infrastructure you manage yourself. Because integrations move records between systems, the data flowing through the runtime, plus the control-plane metadata, are the China surface.
Where it runs MuleSoft offers control-plane “clouds” in the US (default), the EU, Canada, the UK, Japan, Australia and India, plus a US Government cloud — none in mainland China. CloudHub 2.0 deploys apps only across “North America, South America, the European Union, and Asia-Pacific,” and MuleSoft hosts the management console and platform services in the US (or Europe for the EU Cloud). No mainland region is offered.
Your China data crossing the border When the runtime executing your flows sits in an offshore CloudHub region, the personal information your integrations carry out of China is a cross-border transfer under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. A data-export security assessment may apply above thresholds.
Residency for CIIOs For a critical information infrastructure operator, personal information generated in China must be stored in China (Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40) — a duty an offshore CloudHub region cannot meet. Switching a flow to a different offshore cloud relocates the transfer; it does not end it.
The lawful path Run the Mule runtime in-country — self-hosted Runtime Fabric or on-premises inside the mainland — so the China integration data stays resident, send out only what may lawfully leave, keep the Anypoint control plane for your other regions, and deliver the China-facing apps in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

No mainland region — the control plane and the runtime both sit offshore

MuleSoft’s Anypoint Platform is built from two planes, and China’s law reaches both. The control plane — where you design, deploy and manage your integrations — is what MuleSoft calls a cloud, and it is offered in the US (the default), the EU, Canada, the UK, Japan, Australia and India, plus a US Government cloud. Not one is in mainland China. The runtime plane, where your integrations actually execute, runs either on CloudHub (MuleSoft-managed) or on infrastructure you stand up yourself.

For the managed option, MuleSoft is explicit in its CloudHub 2.0 Architecture documentation: “CloudHub 2.0 provides the ability to deploy apps in different regions of the world: North America, South America, the European Union, and Asia-Pacific,” and “For the US Cloud and MuleSoft Government Cloud control planes, MuleSoft hosts the management console and platform services in the United States,” with the EU Cloud hosted in Europe. Its published runtime regions span the US, Canada, Brazil, Ireland, Germany, the UK, Singapore, Australia, Japan and India — none inside the mainland. So “we already run MuleSoft” does not carry into China on its own terms: the platform places both the runtime and its own management data outside the country.

An integration layer is where China data leaves by default

This is the part most teams underestimate. An integration platform exists to move records between systems — a CRM, an ERP, a database, a payment or messaging service — and much of what passes through it is personal information: names, contact details, order and account records, device and user identifiers. When the runtime executing those flows sits in an offshore CloudHub region, the personal information your integrations carry out of China becomes a cross-border transfer the moment it leaves, and the control-plane metadata MuleSoft retains — payloads surfaced in logs, queued messages, monitoring data — is itself held offshore.

Under China’s Personal Information Protection Law that transfer lands on you, the personal-information handler, not on MuleSoft the processor: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the regulated thresholds, or where the data is “important data,” China’s data-export security assessment (数据出境安全评估) may have to clear before anything leaves. And if you are a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China — a duty an offshore CloudHub region cannot satisfy no matter how it is tuned. A data-integration layer is precisely the place where China personal information gets moved out of the country by default; which of these obligations bite your specific flows is a risk to confirm with counsel against what you actually move and store.

The self-hosted runtime is the opening — if the data is kept in-country

There is a lawful way to keep the integration data in China, and MuleSoft’s own architecture leaves room for it. Alongside the managed CloudHub runtime, MuleSoft documents a self-managed runtime plane: “You can use Runtime Fabric with managed Kubernetes services like EKS, AKS, GKE, and OKE, or with self-managed distributions like Red Hat OpenShift and Rancher,” and it also supports standalone on-premises Mule runtimes. Run the Mule runtime on infrastructure inside the mainland and the data your China flows carry can stay in China by default, with only what may lawfully leave flowing out to the rest of your estate — while the Anypoint control plane keeps serving the other markets where it already does.

That split — what must stay in China, what may cross the border — is the heart of the work, and it is a legal question before it is a technical one. It is also not a setting the platform decides for you: pointing a flow at a “different region” only relocates the transfer among offshore clouds; it does not end it. Keeping China integration data in-country means standing up an in-country runtime and designing the flows around it. This is a risk map, not a verdict — whether you owe a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination turns on your entity, your data volumes and who your users are, and it is worth settling with counsel before your integrations depend on it.

The lawful path — map, localize, deliver

There is a compliant way to run MuleSoft for a China-facing business, and it has a shape. First, map: our China compliance team works through your PIPL exposure flow by flow — which integrations carry personal information out of China, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty applies, and what your notice and consent have to cover. We build the technical picture; the legal conclusions are settled with your counsel.

Then localize: we stand up and integrate an in-country Mule runtime — self-hosted Runtime Fabric or on-premises inside the mainland — so the China integration data stays resident in the country, keeping only the data that may lawfully leave flowing out, and leaving your Anypoint control plane exactly where it already runs for every other market.

Then deliver: the public-facing apps and APIs that expose these integrations to users in the mainland are an internet service in China, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. What we never do, and what no one lawfully can, is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth. The result is a MuleSoft estate that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is MuleSoft available in mainland China?
MuleSoft's Anypoint control plane and CloudHub endpoints are reachable from the mainland, so availability is not the obstacle — the question is data residency. MuleSoft runs no mainland-China control plane and no CloudHub region; its own docs place the managed runtime only in North America, South America, the EU and Asia-Pacific, and host the control plane in the US or the EU. So the data your integrations move, and the metadata the platform keeps, rest offshore. Cross-border connectivity to an offshore runtime can also be inconsistent, but that is an operational matter, not the decision. Treat the specifics as a risk to confirm with counsel.
Is running China data through MuleSoft a cross-border transfer?
If your Mule runtime executes on an offshore CloudHub region — anywhere outside the mainland — then the personal information your integrations carry out of China is transferred offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and above the regulated thresholds it may require China's data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. Confirm your exact obligations with counsel.
Can I just pick a MuleSoft region closer to China to keep data in-country?
No — MuleSoft offers no mainland-China control plane or CloudHub region, so no managed region keeps the data in China; moving a flow from one offshore cloud to another merely relocates the cross-border transfer. Keeping China integration data in-country means running the Mule runtime on infrastructure inside the mainland — self-hosted Runtime Fabric or on-premises — and designing the flows so only what may lawfully leave does. 21YunBox maps that split, localizes the China data onto an in-country runtime, and delivers the China-facing apps on ICP-filed infrastructure — it is never a route around China's data-export rules.

ARTICLES RELATED TO MULESOFT

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.