Canadian data residency for an AI platform means data is stored and processed in Canada across the entire chain — including inference, embeddings, telemetry, and support access — not merely the primary database. MAIA runs with Canadian residency by default and can operate fully inside a customer's own environment, with subprocessors disclosed and any cross-border movement requiring explicit written authorisation.
Where residency promises quietly break
The primary database is almost never the leak. Residency breaks in the periphery: a model API in another jurisdiction, an error-tracking service that ships stack traces abroad, a support engineer screen-sharing from another country. Public-sector privacy statutes — FIPPA in British Columbia, and their provincial equivalents — treat those as disclosures.
The test to put to any vendor is simple: enumerate every system that touches the data, name its jurisdiction, and show the contract clause that keeps it there.
How MAIA holds the line
Residency is a deployment property, not a promise: the platform's decision loop — ingestion, reasoning, drafting, sealing — runs inside the resident environment. Private model instances keep inference in-country; the audit ledger stays with the data it describes.
For institutions with stricter postures, the same substrate deploys on-premise or air-gapped, where the residency question answers itself.
