Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Securiti Work in China? Consent & DSR Data, PIPL Cross-Border & Data Residency

Securiti is a data-privacy and consent platform — yet its own Security page says it is "hosted on Amazon Web Services(AWS) and Google Cloud(GCP)," in US and EU production clouds, with no mainland-China region. For China that turns the consent records, cookie preferences and data-subject requests it collects into a cross-border transfer under PIPL, with no ICP-filing footing and no in-country storage. A compliance-first look at the data-residency and reachability exposure — and the lawful in-country path.

Does Securiti work in China?

Here is the twist that is also the answer: Securiti is the platform you buy to stay compliant, yet run as-is for mainland China it can turn into a compliance exposure of its own. Reaching it isn't the problem — where it keeps your Chinese users' consent and request records is.

Securiti's own Security page says its solution is "hosted on Amazon Web Services(AWS) and Google Cloud(GCP)," running in "a given AWS (or GCP) region," and its terms name a US and an EU production cloud (app.eu.securiti.ai) — none in the mainland. So every consent receipt, cookie preference and data-subject request it records from a Chinese visitor is personal information that leaves China, a cross-border transfer PIPL governs (notice, a separate consent and one transfer mechanism, Articles 38–40), with an in-country storage duty for a CIIO or large-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). The consent gate itself is fetched from that offshore infrastructure, so from inside China it can load slowly or fail — and a gate that can't load can hold up the page it guards. The table below is Securiti's own wording and the rule each line triggers.

This is a risk map, not a verdict — what you owe turns on your data volumes, your role as handler and who your users are, and it's worth settling with counsel. Our China team can map your exposure with you →

What Securiti's own documentation says about China

FactPrimary source
Securiti states its platform is hosted on AWS and GCP — offshore, with no mainland-China region. Its Security page, under “Infrastructure,” says: “Our solution is hosted on Amazon Web Services(AWS) and Google Cloud(GCP),” engineered to “make use of multiple availability zones in a given AWS (or GCP) region.” For a consent and privacy platform that is the point in reverse: the record proving a Chinese user consented is itself personal information held offshore — a cross-border transfer of personal information under PIPL (notice, a separate consent and one transfer mechanism, Articles 38–40). Securiti, “Security” (Infrastructure section, securiti.ai), retrieved 2026-10-09; PIPL Articles 38–40
Securiti's production clouds are US- and EU-based — it names no China production cloud. Its service terms (Support SLA) reference a dedicated EU production cloud reached at “app.eu.securiti.ai,” distinct from the default US environment, and Securiti self-certifies under the EU-U.S. Data Privacy Framework for transfers into the United States. Neither location is in mainland China, so there is no in-country production cloud for consent, cookie-preference and request data to live on, and none to attach an ICP filing to. Securiti Terms (Support Services and Availability SLA; International Data Transfers), securiti.ai, retrieved 2026-10-09
China-collected consent and request records sent to an offshore account are a PIPL cross-border transfer. Moving the consent receipts, cookie preferences and data-subject-request records Securiti gathers from people in mainland China to an account hosted in the US or EU triggers PIPL Articles 38–40: notice, a separate consent distinct from any general agreement to use your product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09
For some handlers the data must stay in China — and serving from inside the mainland triggers an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore store cannot satisfy. And any public site actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Securiti does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-09.

For an audience in mainland China, Securiti raises a question with a built-in paradox. Securiti is the platform a company adopts in order to stay on the right side of privacy law — consent management, data-subject-request automation, data mapping, a privacy center — yet pointed at China as it ships, it can become an exposure of its own. This is not a question of whether it loads. It is that the consent receipts, cookie preferences and data-subject requests Securiti records from your Chinese users come to rest on infrastructure outside the mainland, and that the consent experiences it serves arrive over an offshore network. The first is a data-residency and cross-border question under Chinese law; the second is a reachability one. Both sit ahead of performance — and Securiti settles the first in its own Security documentation.

Securiti's own Security page, Infrastructure section, stating that its solution is hosted on Amazon Web Services (AWS) and Google Cloud (GCP) and runs in an AWS or GCP region — naming no mainland-China hosting region
Securiti's own Security page, under “Infrastructure”: “Our solution is hosted on Amazon Web Services(AWS) and Google Cloud(GCP),” engineered to “make use of multiple availability zones in a given AWS (or GCP) region.” Its production clouds are US- and EU-based (app.eu.securiti.ai for the EU); none sits inside mainland China — so the record of a Chinese user's consent is itself held offshore. Source: Securiti — Security (Infrastructure)

Securiti in China at a glance

What decides it In Securiti's own terms — and China's law
What Securiti holds Securiti's Privacy suite runs Consent Management, Data Subject Request Automation and Data Mapping. So it keeps a running record of who consented to what, each visitor's cookie preferences, and the data-subject requests your Chinese users file — every item of it personal information.
Where the records live Its Security page says the solution is “hosted on Amazon Web Services(AWS) and Google Cloud(GCP)” and runs in “a given AWS (or GCP) region.” The production clouds it names are US- and EU-based (app.eu.securiti.ai for the EU). None is inside mainland China.
Your China users' records Consent receipts, cookie preferences and request records collected from people in China and held offshore are a cross-border transfer of personal information PIPL governs (Articles 38–40): notice, a separate consent, and one transfer mechanism.
How the consent gate arrives A cookie-consent experience is a client-side script the browser fetches before the page settles. Delivered from Securiti's offshore AWS and GCP infrastructure, it makes the same cross-border round trip every offshore asset makes from inside China, so the gate can stall or fail.
Residency & serving the public For a critical information infrastructure operator or a large-volume handler, personal information collected in China must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore store cannot do. A site served from inside China also needs an ICP filing bound to a mainland hosting resource Securiti does not provide.

The awkward part here is structural, not a detail. Securiti’s job is to capture and keep the proof that you handled personal information lawfully — the consent a visitor gave, the cookie choices they set, the trail behind a data-subject request. But Securiti’s own Security page states that its solution is “hosted on Amazon Web Services(AWS) and Google Cloud(GCP),” engineered to run across “multiple availability zones in a given AWS (or GCP) region,” and its service terms describe a US production cloud and a separate EU production cloud at app.eu.securiti.ai — not a mainland-China one. So the record that proves a Chinese user consented is kept in the United States or Europe, which means the privacy platform has quietly manufactured the very thing it exists to document.

Under China’s Personal Information Protection Law that is a cross-border transfer, and the duty falls on the personal-information handler — you, not Securiti. You owe notice, a separate consent for the overseas transfer, and one cleared transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). The platform that collects the consent does not absorb the obligation that attaches to wherever that consent is then stored.

No mainland region, so no in-country storage and no ICP footing

Securiti names AWS and GCP as its hosts and points to US and EU production clouds; it publishes no mainland-China region. That geography answers two separate questions before speed is ever in the frame.

First, residency. If you are a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 — the data-localization provision renumbered from Article 37 by the 2025 Cybersecurity Law amendment that took effect on January 1, 2026, with its substance unchanged). An offshore consent-and-request store cannot satisfy that duty however it is configured, and above certain volume thresholds — or where the records count as important data — the transfer may also require China’s data-export security assessment before anything leaves. Second, licensing. A public-facing site actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing has to attach to a hosting resource physically in the mainland. Securiti offers none, so there is nothing on Securiti to file against. “We already run Securiti for privacy” does not carry across the border; the clean data-handling story the platform is meant to give you is exactly what it leaves open in China.

The reachability half is real too, and for a consent banner it bites harder than for an ordinary script. A cookie-consent experience is loaded client-side, often wired to gate the page until the visitor makes a choice. Because Securiti’s infrastructure sits on offshore AWS and GCP regions, that script and its configuration are fetched from outside the mainland — the same cross-border hop every offshore asset takes to reach a user in China.

So when an offshore-served consent gate loads slowly or fails from inside China, it does not fail quietly off to one side — it can stall the very content it is meant to guard. That is a delivery problem, not a legal one, but on a China-facing site the two compound: the gate that is hardest to deliver is also the one carrying the cross-border exposure. We publish no first-party China latency figure for Securiti here, because speed is not the axis this decision turns on, and a number without a method, a sample and a date would only mislead. One thing 21YunBox never does — and what no lawful provider can offer — is route around China’s data-export rules or any network restriction: we never use or suggest circumvention of any kind.

This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, in-country storage, a data-export assessment, an ICP filing, or some combination depends on your data volumes, your role as handler, and who your users are — worth settling with counsel before you depend on it.

The lawful path — map, localize, deliver

There is a compliant way to run Securiti for a China-facing audience, and it has a shape. First, map: our China team works through the PIPL cross-border and data-residency obligations that attach to the consent, preference and request data Securiti records — against your entity, your data volumes and who your users are — and marks where a data-export assessment or an Article 39 storage duty bites. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: for the records that must stay in the country, we stand up and integrate a China-resident store and a consent flow that runs on an ICP-filed, in-country footing — the lawful in-country pattern of consented, in-country processing and storage — so what cannot lawfully leave no longer does, while you keep Securiti for the markets where it already serves you.

Then deliver: the China-facing site or app that presents the consent gate is itself a public service in the mainland, so it carries an ICP filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is a privacy and consent setup that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Securiti store Chinese users' consent and request data in China?
No. By Securiti's own Security page the platform is "hosted on Amazon Web Services(AWS) and Google Cloud(GCP)" and runs in AWS or GCP regions, and its terms name US and EU production clouds (app.eu.securiti.ai) — none in the mainland. The consent receipts, cookie preferences and data-subject requests it records from Chinese visitors are held offshore, which makes them a cross-border transfer of personal information under PIPL: the handler (you, not Securiti) owes notice, a separate consent and a transfer mechanism.
If Securiti is a privacy tool, how can it be a compliance risk in China?
Because compliance in China turns on where the data lives, not on what the tool is for. A consent and request platform exists to prove you handled personal information lawfully — but if that proof is stored in the US or EU, you have created the exact cross-border transfer PIPL regulates, and for a CIIO or large-volume handler the data-residency duty an offshore store cannot meet. Treat it as a risk to work through with counsel: adopting a privacy tool does not exempt the personal information it collects from China's transfer and residency rules.
Can 21YunBox help make our Securiti setup work in China?
Yes. Our China team can map your exposure — the PIPL cross-border and data-residency obligations that attach to the consent, preference and request data Securiti records, for your entity, data volumes and users — and stand up the ICP-filed, in-country delivery and storage a compliant China presence needs, in front of the Securiti stack you already run. We never use or suggest circumvention of any kind. Get in touch to work through your specific case.

ARTICLES RELATED TO SECURITI

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.