Does Tanium Work in China? Data Residency, Localization & PIPL Cross-Border
Tanium Cloud (the SaaS) runs in offshore Global Data Regions on AWS, Microsoft, and Oracle with no mainland-China region, so the real-time endpoint telemetry it concentrates — device, user, process, file, and network state — comes to rest offshore and crosses the border under PIPL. A compliance-first look at Tanium's regions, the self-managed in-country lever, and the lawful path.
Does Tanium work in China?
The Tanium client reaches its server from the mainland, but that reachability is the easy half — Tanium Cloud runs no region inside mainland China, so the real-time endpoint telemetry it concentrates comes to rest offshore, and the personal information inside it crossing the border is a PIPL question, not a speed one.
Tanium's own List of Sub-Processors places Tanium Cloud hosting and storage with Oracle, AWS, and Microsoft across the "Global Data Regions in Tanium Cloud Trust Center," and names no mainland-China region. The telemetry Tanium concentrates — logged-in users, device identifiers, IP addresses, processes, file paths, and a classified map of where sensitive data lives — is dense personal information, often reaching Art 28 sensitive categories. Collected from China endpoints and held offshore, it is a cross-border transfer PIPL governs (notice, separate consent, a transfer mechanism, Articles 38–40), and for a critical information infrastructure operator or high-volume handler it must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). The lawful lever is Tanium's self-managed appliance, which runs on infrastructure you provide — including in the mainland.
This is a risk map, not a verdict — what applies turns on your data volumes, your role as handler, and whose endpoints you monitor. Our China team can map your exposure →
What Tanium's own documentation says about China
| Fact | Primary source |
|---|---|
| Tanium Cloud is hosted offshore, with no mainland-China region. Tanium's own List of Sub-Processors records Tanium Cloud hosting and storage provided by Oracle, Amazon Web Services, and Microsoft, located in the "Global Data Regions in Tanium Cloud Trust Center." Neither that disclosure nor Tanium's corporate footprint (affiliates in fourteen countries — Australia, Canada, France, Japan, Germany, Belgium, the Netherlands, Poland, Singapore, South Korea, Spain, Sweden, Switzerland, and the United Kingdom) names a mainland-China region, so the endpoint telemetry Tanium Cloud concentrates from China comes to rest offshore. | Tanium — List of Sub-Processors (tanium.com/subprocessors), retrieved 2026-10-10 |
| Tanium's self-managed appliance is the in-country lever. Tanium's Appliance product brief states the Tanium Virtual Appliance and Tanium Cloud Appliance are "software versions of the physical appliance, running on customer-provided hypervisor infrastructure or customer-purchased cloud provider infrastructure," and describes the appliance family as "rack-mount hardware appliances, on-premise virtual appliances or cloud appliances." Because the Tanium Server runs where you deploy it, a self-managed deployment can sit on mainland infrastructure and keep the China endpoint telemetry in-country — the lawful residency lever that the offshore Tanium Cloud SaaS does not offer. | Tanium — Tanium Appliance product brief (site.tanium.com), retrieved 2026-10-10 |
| Endpoint telemetry held offshore is a PIPL cross-border transfer. The real-time device, user, process, file, and network state Tanium streams from China endpoints is personal information — usernames, device identifiers, IP addresses, file and process activity. Collected in China and landing in an offshore Tanium Cloud region, that is a cross-border transfer of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Where it indexes where sensitive files live, it reaches the Article 28 category of sensitive personal information. | PIPL Articles 28 and 38–40, retrieved 2026-10-10 |
| For a CIIO or high-volume handler, the data must be stored in China. Where your organization is a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore-only Tanium Cloud region cannot meet that residency duty; a self-managed in-country deployment can. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For an organization running Tanium across endpoints in mainland China, the first instinct is to check whether the Tanium client can reach its server — and on the wire it generally can: Tanium’s agent is built to hold a secure, continuous link back to the Tanium Server, and it is not a consumer service blocked at the border. So reachability is not where the China decision is settled. What settles it is data residency and cross-border transfer — where the telemetry Tanium concentrates comes to rest, and whether moving it out of the country was lawful in the first place. Tanium concentrates an unusually complete picture: real-time device, user, process, file, and network state across every endpoint — a live map of the whole estate. The irony for a security buyer is sharp: the platform you deployed to see and control your endpoints is itself a live offshore path for your most sensitive operational data when it runs as Tanium Cloud, which has no mainland-China region. A self-managed Tanium appliance you host in-country is the lawful alternative.
Tanium in China at a glance
| What decides it | In Tanium's own terms — and China's law |
|---|---|
| Where the security data rests | Offshore for the SaaS. Tanium is “the one platform for endpoint management and security at enterprise scale.” As Tanium Cloud its hosting and storage sit with Oracle, AWS, and Microsoft across the “Global Data Regions in Tanium Cloud Trust Center” — none in mainland China. As a self-managed Tanium appliance (physical, “on-premise virtual,” or cloud appliance) it runs “on customer-provided hypervisor infrastructure or customer-purchased cloud provider infrastructure,” so it rests wherever you deploy it — including in-country. |
| What it ingests & why it's personal information | Tanium's client streams real-time endpoint state — logged-in users, device identifiers, IP addresses, running processes and command lines, file paths, and network connections — a continuous, identifiable map of every endpoint. Where its modules index where sensitive files and personal information live, that reaches the Art 28 category of sensitive personal information (financial, health, government-ID). This is dense personal information under PIPL. |
| Your China endpoints' data = cross-border | Collected from China endpoints and held in an offshore Tanium Cloud region, that telemetry is a cross-border transfer (数据出境) under PIPL Articles 38–40: notice, a separate consent distinct from any general IT or employment agreement, and one transfer mechanism. |
| The in-country storage duty | For a critical information infrastructure operator or a high-volume handler, personal information generated in China must be stored in China — PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) — a data-residency duty an offshore Tanium Cloud region cannot meet however the tenant is configured. |
| Reachability is not the axis | The Tanium client generally reaches its server from the mainland — that is not the China question. A self-managed appliance run in-country keeps the telemetry on mainland soil, and any China-facing admin or self-service console you expose carries an ICP filing (备案) duty and needs compliant, in-country delivery over lawful, ICP-filed infrastructure. 21YunBox maps, localizes, and delivers in front of the stack you already run. |
Where the data actually rests
Tanium’s China posture is set by where its data regions are, not by a load-time test. The platform runs in two shapes, and they land in very different places. Publicly, Tanium now leads with the cloud: the Tanium Autonomous IT Platform delivered as Tanium Cloud, a managed service hosted by AWS, Microsoft, and Oracle across the Global Data Regions named in the Tanium Cloud Trust Center. Tanium’s cloud has added local data centers over time — Canada, the United Kingdom, Brazil, and Australia, alongside earlier sites in the United States, Germany, and Japan — but none is in the mainland, and Tanium’s own corporate affiliates span fourteen countries with no China entity among them. So on today’s map Tanium Cloud has no in-country home; the endpoint telemetry it concentrates from China devices lands in a region outside the mainland.
The second shape is the self-managed Tanium appliance — the Tanium Server you stand up and operate yourself. Tanium documents it as a physical appliance, an “on-premise virtual” appliance, or a cloud appliance that runs “on customer-provided hypervisor infrastructure or customer-purchased cloud provider infrastructure.” Because it runs where you put it, you can host the Tanium Server on mainland infrastructure and keep the China endpoint telemetry in-country. That distinction — managed-offshore versus self-managed-in-country — is the whole residency decision, and it is a legal question before it is a technical one.
What it ingests is personal information
The residency question is sharper for Tanium than for most software, because of what the telemetry is. Tanium’s entire value is total, real-time visibility: who is logged in, what is executing, what connected where, which files sit on which device, and — through its data-risk and asset capabilities — a classified map of where sensitive and regulated data lives across the estate. That is continuous, identifiable personal information, and where it inventories the location of financial, health, or government-ID data it reaches the Article 28 category of sensitive personal information that China’s Personal Information Protection Law scrutinizes most closely. The irony is exact: the platform bought to secure and control the estate is itself a live, offshore feed of the estate’s most sensitive operational data and a catalogue of where its personal information rests.
That density pulls in two regimes beyond the baseline transfer rules. First, assessment: above certain volume thresholds, where the data qualifies as “important data,” or where your organization is a critical information infrastructure operator, the transfer may require China’s data-export security assessment (数据出境安全评估) before anything leaves the country. Second, residency: if you are a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires personal information generated in China to be stored in China. An offshore Tanium Cloud region cannot satisfy that duty no matter how the tenant is configured — and none of this turns on how fast an event is ingested; it turns on whether the data had a lawful basis to be there, and in what volume.
Running it on a no-China-region cloud doesn’t meet the residency duty — and what does
The obvious move is to switch the Tanium Cloud “region” and keep the data in place — but every region Tanium Cloud offers sits in the United States, Europe, or Asia-Pacific outside the mainland, so moving a tenant from one to another merely relocates the cross-border transfer; it does not end it. The lawful lever for Tanium specifically is its self-managed deployment. Because the Tanium Virtual or Cloud Appliance is “software versions of the physical appliance, running on customer-provided hypervisor infrastructure or customer-purchased cloud provider infrastructure,” you can stand the Tanium Server up on mainland infrastructure and keep the China endpoint telemetry in-country, sending offshore Tanium only what may lawfully leave. The software is residency-flexible; it runs where you deploy it, so this is never about the tool being “blocked.”
Be clear-eyed about one thing: Tanium’s public momentum is cloud-first, so the in-country path means deliberately running the self-managed appliance on mainland infrastructure, or a licensed in-country equivalent — not defaulting to the offshore SaaS and routing data back to it. Migration isn’t needed; you keep Tanium and run its China data layer in-country. This is a risk map, not a verdict: whether you owe separate consent, a transfer mechanism, a data-export security assessment, in-country storage, or some combination depends on your data volumes, your role as handler, and whose endpoints you monitor — worth settling with counsel before you rely on it.
The lawful path — map, localize, deliver
There is a lawful way to run endpoint security and management for a China presence, and it has a shape. First, map: our China team works through your PIPL exposure for the endpoint telemetry — which device, user, process, file, and network data collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what notice and separate consent the people behind those endpoints are owed. We build the technical picture; the legal conclusions are settled with counsel.
Then localize: we run the China security-data layer in-country — a self-managed Tanium appliance on mainland infrastructure, or a licensed in-country equivalent — so the real-time visibility you depend on keeps working while that sensitive telemetry stops leaving the country by default. Localize means running the security-data layer in-country, not routing it back to an offshore endpoint. You keep Tanium for the regions where it already serves you.
Then deliver: any China-facing surface in front of the platform — the admin console, the reporting portal, or a self-service page your mainland users hit — is a public internet service, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no second codebase. The result is a China presence that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
