Security
Data residency and GDPR
Where StageReady stores your data, and how it handles personal data under GDPR.
Where your data lives
StageReady runs on Microsoft Azure in the European Union, specifically the Azure West Europe region in Amsterdam. The application, the database, and the vault all stay within the EU; your data isn't moved outside it.
The portal and API your technicians use.
Jobs, devices, templates, and the audit trail.
Client credentials, held nowhere else.
Client credentials
Credentials for each client's Microsoft environment are held only in Azure Key Vault, never in our database, in configuration, on the USB, or on the device. The application can read them only for the moment a job needs them. See the security model for the full picture.
Personal data
A device's hardware hash is the fingerprint needed to register it into Autopilot.
The hardware hash is treated as personal data
It identifies a specific physical machine, so StageReady handles it as personal data under GDPR: it is never written to logs, and it lives only on the device record it belongs to.
Your audit trail
Every code, step, and device is recorded so you can show any client exactly what was done, when, and by whom. Provisioning records are retained for a limited period and then removed, and you stay in control of your data throughout.