Zscaler has expanded the global data sovereignty capabilities of its Zero Trust Exchange platform, introducing new regional controls and compliance features geared to help enterprises manage sensitive data within national boundaries.
The update reflects growing demand among multinational organizations for security platforms that can satisfy strict regulatory requirements while maintaining the performance needed for cloud services. Governments and industry regulators in Europe, North America and Asia are increasingly requiring companies to keep certain categories of data within local jurisdictions.
Decentralized Architecture
Zscaler’s approach relies on a decentralized architecture that separates three operational layers: the control plane, the data plane and the logging plane. Each layer performs a distinct function, enabling companies to maintain local authority over how data is processed and recorded.
“Effective data sovereignty requires customers to have verified authority over their data residency, telemetry and control data plane data,” said Misha Kuperman, chief reliability officer at Zscaler. “By separating control, data, and logging planes with a decentralized architecture, Zscaler enables customers to align with strict local sovereignty requirements while maintaining the resilience and availability needed for global business continuity.”
Analyzing Encrypted Network Traffic Locally
One of the most significant additions is the ability to perform encrypted traffic inspection within the same region where the data originates. Because the system decrypts and analyzes encrypted network traffic locally, it can identify potential malware without transferring the underlying files outside the jurisdiction.
For enterprises operating under regulatory requirements, Zscaler is also offering a deployment option called Private Service Edge. These single-tenant appliances are hosted by the customer but managed by Zscaler, giving organizations greater control over the infrastructure while retaining the company’s cloud-based security services.
A key feature for companies worried about data security: Independent third-party assessments confirm that the platform processes encrypted traffic without writing sensitive information to disk, a design intended to reduce the risk of data exposure.
Addressing Overlapping Regulatory Frameworks
The company has also introduced new compliance features aimed at simplifying the process of meeting overlapping regulatory frameworks. Its Collect Once, Certify All model allows a single security control set to align with multiple regulatory standards, including Europe’s General Data Protection Regulation (GDPR), the NIS2 cybersecurity directive and the U.S. Department of Defense’s Impact Level 5 requirements.
Additionally, customers retain exclusive control over encryption keys through integration with hardware security modules. This ensures that only authorized parties can decrypt protected traffic, providing an extra layer of assurance for organizations that must demonstrate strict custody over their data.
Zscaler operates its own globally distributed security cloud rather than relying solely on third-party hyperscaler infrastructure. The company claims this approach allows the platform to maintain service continuity even if a single data center becomes unavailable.

