Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Qualys Work in China? Data Residency, Localization & PIPL Cross-Border

Qualys runs no mainland-China platform — its shared platforms are in the US, EU, India, Canada, the UAE, the UK, Australia and Saudi Arabia — so your asset inventory, vulnerability map, scan results and authenticated-scan credentials come to rest offshore: a PIPL cross-border transfer and, for a CIIO or high-volume handler, a data-localization gap. A compliance-first look at Qualys's platforms and the lawful in-country path.

Does Qualys work in China?

Whether you can run Qualys for a China presence is first a data-residency question, not a reachability one.

Qualys is a vulnerability-management and policy-compliance platform: it concentrates a full asset inventory, the vulnerability map that catalogues your exploitable weaknesses, the scan results, and — for authenticated scans — the privileged credentials used to log into your hosts. By Qualys's own platform list, its shared platforms sit in the US, EU, India, Canada, the UAE, the UK, Australia and Saudi Arabia (plus a US government platform) — none in mainland China — so that data comes to rest in whichever offshore platform your account was assigned. Holding China-collected personal information there is a cross-border transfer PIPL governs (notice, separate consent, a transfer mechanism), and for a CIIO or high-volume handler the in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37) an offshore platform cannot meet. The tool bought to secure your estate becomes an offshore path for a classified map of its weaknesses.

This is a risk map, not a verdict — your duties turn on your data volumes and your role. Our China team can map your Qualys exposure →

What Qualys's own documentation says about China

FactPrimary source
Qualys runs no platform inside mainland China. Its own platform-identification page lists the shared platforms as US1, US2, US3, US4, a US GOV1, EU1, EU2, EU3, IN1 (India), CA1 (Canada), AE1 (UAE), UK1, AU1 (Australia) and KSA1 (Saudi Arabia), with customer-run Private Platforms listed separately — none in mainland China. So the asset inventory, vulnerability map and scan results your Qualys account holds come to rest in whichever offshore platform it was assigned. Qualys — Identify your Qualys platform (platform identification), retrieved 2026-10-10
Qualys's one in-country option is its customer-run Private Cloud Platform, not the shared cloud. Qualys markets the Private Cloud Platform (part of its Enterprise TruRisk Platform) to "Keep sensitive data local to a specific region, country or province, both in transit and in storage." Deployed on mainland-China infrastructure, that private appliance can keep the asset inventory, vulnerability map, scan results and authenticated-scan credentials on Chinese soil — the lawful, self-managed lever — whereas the shared platforms (US, EU, India, Canada, UAE, UK, Australia, Saudi Arabia) cannot. Qualys — Private Cloud Platform, retrieved 2026-10-10
The asset, scan and account data Qualys holds is personal information, and holding China-collected personal information in an offshore platform is a cross-border transfer under PIPL (Articles 38–40). The duty falls on the handler — you, Qualys's customer, not Qualys the processor: notice, a separate consent distinct from any general IT or employment agreement, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Where scans reach account credentials or individuals' security attributes, the data can touch the sensitive-personal-information category under PIPL Article 28. PIPL, Articles 28 and 38–43 (CAC)
For a critical information infrastructure operator or high-volume handler, personal information generated in China must be stored inside mainland China (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37 — renumbered by the 2025 amendment in force January 1, 2026, substance unchanged). An offshore Qualys platform cannot satisfy that duty no matter how the tenant is configured; a mainland-deployed Private Cloud Platform or a licensed in-country equivalent can. Above thresholds or for "important data," a data-export security assessment may be required before anything leaves. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

If your organization runs Qualys in mainland China, the first check is whether the scanners and Cloud Agents can reach the console. They generally can: Qualys is not a consumer service filtered at the border, so reachability is not where the China decision is settled. Data residency is — where the data Qualys concentrates comes to rest, and whether it lawfully left the country. And it concentrates a great deal: a full asset inventory, the vulnerability map cataloguing each exploitable weakness, the scan results, and, for authenticated scans, the privileged credentials that log into your systems. The irony is exact — the tool bought to find and close your weaknesses holds the master map of them, and in a mainland deployment that map comes to rest offshore, because Qualys runs no shared platform inside mainland China. A customer-run Private Cloud Platform is the one deployment that can sit in-country.

Qualys's own Platform Identification page listing its shared platforms — US1, US2, US3, US4, a US GOV1, EU1, EU2, EU3, IN1, CA1, AE1, UK1, AU1 and KSA1, with Private Platforms shown separately — and no mainland-China platform anywhere on the page
Qualys instructs customers to "Use the platform identifier in your Qualys username to determine your Qualys platform." The shared-platform list runs US1–US4, a US GOV1, EU1–EU3, IN1 (India), CA1 (Canada), AE1 (UAE), UK1, AU1 (Australia) and KSA1 (Saudi Arabia), with customer-run Private Platforms listed separately — none inside mainland China, so your asset inventory, vulnerability map and scan results come to rest in whichever offshore platform your account was assigned. Source: Qualys — Identify your Qualys platform

Qualys in China at a glance

What decides it In Qualys's own terms — and China's law
Where the data rests Offshore. Qualys's platform-identification page lists its shared platforms as US1–US4, a US GOV1, EU1–EU3, IN1, CA1, AE1, UK1, AU1 and KSA1 — the US, EU, India, Canada, the UAE, the UK, Australia and Saudi Arabia. There is no mainland-China platform. Your asset inventory, vulnerability map and scan results come to rest in whichever platform your account was assigned.
What it ingests A continuous, identifiable picture of your estate: hostnames, IP addresses, operating systems, installed software, logged-in accounts, and a ranked catalogue of each host's exploitable weaknesses. Authenticated scans add the privileged credentials used to log into your systems. That is personal information, and — where it reaches account credentials or individuals' security attributes — it can touch the sensitive-personal-information category under PIPL Article 28.
China data into an offshore platform Holding China-collected asset, scan and account data in a US, EU or other offshore platform is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The duty sits on you, the handler, not on Qualys the processor.
The in-country storage duty Above volume thresholds, for "important data," or for a critical information infrastructure operator, personal information generated in China must be stored in China: PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39 (substance unchanged). A data-export security assessment may also be required before anything leaves. An offshore Qualys platform cannot satisfy an in-country storage duty.
Reachability is not the axis The scanners and Cloud Agents generally reach the console from the mainland, so "can it connect?" is the wrong test. The lawful path is to keep the China security data in-country — a mainland-deployed Private Cloud Platform or a licensed in-country equivalent — and to serve the China-facing console and reporting over ICP-filed, in-country delivery. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention of any kind.

Where the data actually rests

Qualys’s China posture is set by where its platforms are, not by a load-time test. Its platform-identification page exists precisely because an account is pinned to one platform, and it names them plainly: the shared platforms are US1, US2, US3 and US4, a US GOV1, EU1, EU2 and EU3, IN1, CA1, AE1, UK1, AU1 and KSA1 — the United States, the European Union, India, Canada, the United Arab Emirates, the United Kingdom, Australia and Saudi Arabia. Not one is in mainland China. So the asset inventory, vulnerability map and scan results your Qualys account builds up come to rest in whichever of those offshore platforms you were assigned at provisioning.

There is one exception worth naming, and it is the lawful lever: Qualys offers a customer-run Private Cloud Platform — a self-contained appliance that brings the platform’s capabilities onto infrastructure you control. Qualys markets it to “Keep sensitive data local to a specific region, country or province, both in transit and in storage.” Deployed on mainland-China infrastructure, that private platform can keep the security data on Chinese soil. The shared platforms cannot — moving a tenant from the US platform to the EU platform merely relocates the cross-border transfer; it does not end it.

What it ingests is personal information

The residency question is sharper for vulnerability management than for most software, because of what Qualys holds. Its whole value is visibility: it records every host it can see, the software running on it, the accounts on it, and a ranked list of the weaknesses an attacker could exploit — a continuous, identifiable picture of your estate. For authenticated scans it goes further still, using the privileged credentials that log into those systems; Qualys documents storing and retrieving those secrets through its authentication records and credential vaults. That is the irony a security buyer feels immediately: the tool you deployed to protect the estate becomes the one place that concentrates a classified map of its weaknesses — and the keys to its hosts — in an offshore cloud.

That density is what China’s law scrutinizes most closely. The asset, scan and account data is personal information, and holding China-collected personal information offshore is a cross-border transfer under the Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization operating the hosts, not Qualys the processor: Articles 38–40 require notice, a separate consent distinct from any general IT or employment agreement, and one transfer mechanism. Where a scan reaches account credentials or individuals’ security attributes, the data can touch the sensitive-personal-information category under PIPL Article 28, which raises the bar again. And above certain volume thresholds, where the data qualifies as “important data,” or where your organization is a critical information infrastructure operator, the transfer may require China’s data-export security assessment (数据出境安全评估) before anything leaves the country.

Running it on a no-China-platform cloud doesn’t meet the residency duty — and what does

If you are a critical information infrastructure operator or a high-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37) requires personal information generated in China to be stored in China — an in-country storage duty no offshore Qualys platform can satisfy, no matter how the tenant is configured, because none of the shared platforms is on Chinese soil. The fix is not to point Qualys at “a different region”; the only homes the shared cloud offers are the US, the EU, India, Canada, the UAE, the UK, Australia and Saudi Arabia, and none of them resolves a China residency duty.

What does resolve it is running the security-data layer in-country. Qualys’s own Private Cloud Platform, deployed on mainland infrastructure, keeps the asset inventory, vulnerability map, scan results and scan credentials on Chinese soil; where that appliance is not the right fit, a licensed in-country or sovereign-cloud equivalent plays the same role. Either way you keep Qualys for the regions where it already serves you and localize only what must stay in China — no migration of your whole program, because you run the in-country layer in front of the stack you already operate.

This is a risk map, not a verdict: whether you owe separate consent, a transfer mechanism, a data-export security assessment, in-country storage, or some combination depends on your data volumes, your role as handler, and whose assets and accounts the scans cover — worth settling with counsel before you rely on it.

The lawful path — map, localize, deliver

There is a lawful way to run vulnerability management for a China presence, and it has a shape. First, map: our China team works through your PIPL exposure for what Qualys ingests — which asset, scan, account and credential data collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what notice and consent the people behind those accounts are owed. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate the security-data layer in-country — a mainland-deployed Private Cloud Platform or a licensed in-country equivalent — so the asset inventory, vulnerability map, scan results and scan credentials stop leaving the country by default, while you keep Qualys for the regions it already covers. Localize means running that layer on mainland soil, not routing the China data back out to an offshore endpoint.

Then deliver: the China-facing surfaces your teams and users actually hit — the admin console, the reporting portal, the self-service pages — are internet services, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a China presence that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules: 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Qualys store Chinese scan data in China?
Not on its shared cloud. Qualys's platform-identification page lists its shared platforms in the US, EU, India, Canada, the UAE, the UK, Australia and Saudi Arabia (plus a US government platform) — none in mainland China — so the asset inventory, vulnerability map, scan results and authenticated-scan credentials your account holds come to rest offshore. The one way to keep that data on Chinese soil is a customer-run Private Cloud Platform deployed in-country, or a licensed in-country equivalent.
Is it illegal to use Qualys in China?
Not inherently. The exposure is the cross-border transfer of personal information, which PIPL permits if you give notice, obtain separate consent and meet one of its transfer mechanisms. Whether you also face a data-localization duty depends on your role (for example, whether you are a critical information infrastructure operator) and the volume of personal information involved. Treat it as a risk to assess with counsel, not a blanket prohibition.
Can 21YunBox make our Qualys setup compliant in China?
Yes. Our China team maps the cross-border and residency exposure for your data volumes and role, helps run the security-data layer in-country — a mainland-deployed Private Cloud Platform or a licensed sovereign equivalent — so the asset inventory, vulnerability map and scan credentials stay on Chinese soil, and stands up ICP-filed, in-country delivery for the China-facing console and reporting your users reach. Get in touch to work through your case. 21YunBox never uses or suggests circumvention of any kind.

ARTICLES RELATED TO QUALYS

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.