Data-residency questions to ask before you choose a meeting platform
For a government or regulated buyer, “where does the meeting live” is not a footnote. It decides which laws apply, who can be compelled to hand over a recording, and what a breach of the provider would expose. Before you choose a meeting platform, these are the residency questions worth asking, and the answers that actually hold up.
Where do the media servers run?
The servers that carry and mix the audio and video are where the content is most exposed. Ask which country they run in, who operates them, and under whose jurisdiction. “Global infrastructure” usually means you cannot answer that question, which is itself the answer.
Where are recordings and transcripts stored?
A meeting that is protected in transit can still be recorded and stored somewhere you do not control. Ask where recordings, transcripts, and metadata are kept, for how long, and who can reach them.
Can it run inside our own boundary?
The strongest residency answer is not a promise about a provider’s region; it is that the platform runs on infrastructure you control. When the deployment is yours, residency becomes a property of where you put it, not a clause in someone else’s contract.
Is classification enforced by the system?
Residency controls are only as good as the classification that drives them. Ask whether a meeting’s security class is fixed when it is scheduled and enforced by the platform, or left to participants to remember. The latter drifts.
What is the encryption model, per room class?
Ask precisely: which rooms are protected only in transit (the server can see them, which is what allows recording), and which are end-to-end encrypted so the server cannot? A platform that blurs the two is telling you something.
How Dorbar answers
Dorbar is designed to run inside your own boundary, so residency is yours to set. A meeting’s class and who may join it are fixed at scheduling, the interface runs in Bengali or English at parity, and the two room classes are explicit: Official rooms are server-trusted and protected in transit (which is what lets them be recorded), and Sealed rooms are end-to-end encrypted so the server cannot read them. That sealed path runs at the browser tier and is rated medium assurance, pending external cryptographic review. Official rooms are never called end-to-end encrypted.

Md. Tawfiqul Bari
Md. Tawfiqul Bari is the founder and CEO of Vigilus Labs Incorporated, with a career spanning cybersecurity, cloud infrastructure, and enterprise security.
LinkedIn profileIf this maps to a system you run, the fastest next step is a 30-minute technical call: bring your engines, versions, and audit configuration, and we will run against a scenario you recognise. There is more on Dorbar: sovereign video meetings if you would rather read first.