The commitment
Customer data placed on CoreValley is processed and stored inside Nepal, in the np-ktm-1 region in Kathmandu. It is not replicated, backed up, cached or failed over to infrastructure outside the country.
This is a property of how the platform is built, not a setting you enable. There is no foreign region to accidentally schedule into.
What counts as customer data
Everything your workload touches:
- Datasets and files on block or object storage.
- Model weights, checkpoints and adapters.
- Container images you push to the registry.
- Prompts, completions and embeddings passing through model endpoints.
- Notebook state and JupyterHub home directories.
- Pod stdout, stderr and application logs.
Egress
Tenant networks are default-deny outbound on regulated projects. Nothing leaves your vCluster unless you write a policy that lets it, and every allowed destination is visible in the flow log. On standard projects egress is open by default, because most teams need to pull packages — it can be locked down per project from the portal at any time.
Where we are not sovereign
Being specific about the edges is the point. Four things do cross the border, and none of them carry customer workload data:
- Enquiries sent through the contact form on this website are delivered to our inbox by FormSubmit, a third-party form service with servers outside Nepal. They carry what you type into the form, so keep confidential details for a secure channel.
- Outbound email — invoices and system notifications — is relayed through a provider with servers outside Nepal. It contains billing metadata, not workload content.
- Public container and package registries you choose to pull from are outside our control and outside the country; the pull is your egress, under your policy.
- If you call a third-party model API from inside a pod, that request leaves Nepal. The platform cannot make someone else's endpoint sovereign.
Evidence
The append-only audit log records every control-plane action against your tenant, hash-chained so gaps are detectable, and exportable as JSON from the portal. For regulated deployments we will also provide a written data-flow description and a network policy review as part of onboarding. Ask your account contact, or write to compliance@corevalley.ai.