Announcing CIMD support for MCP Client registration
Learn more

EU-Hosted Agent Integrations: Keeping Tokens, Tool Calls, and Logs in Frankfurt

EU-hosted agent integrations: tokens, tool calls and logs in Frankfurt. A Scalekit deployment pinned to the EU region (europe-west3) with your agent, token vault and logs inside; connected apps reached across the line; a faded US region with no connection.
Vishal Dhawani
Founding Architect @ Scalekit

TL;DR

  • For an agent integration layer, “EU data residency” has four parts: where the OAuth tokens are stored, where tool calls execute, whether the payloads passing through are kept, and where the logs live. A region badge covers some of these. Check all four.
  • Scalekit's EU region runs on Google Cloud in Frankfurt, separate from the US region with no shared state. You pick it at signup and the workspace stays there. In an EU workspace, tokens are stored encrypted in Frankfurt, tool calls execute in Frankfurt, payloads are processed in memory and not stored, and logs hold call metadata only.
  • GDPR does not require EU residency. Your customer's contract does. The obligations live in the vendor's DPA, so read the subprocessor list, the change-notice terms and the transfer mechanism.
  • The model is a separate hop. Tool results go from the integration layer to your agent and on to your LLM. Pin the model provider's region on its own.

What a DPO is really asking

“Confirm all personal data is processed in the EU.” It reads like a yes-or-no question. For an agent that acts in other systems it is not, because the data takes a route: a user authorizes the agent, a provider hands over tokens, the agent calls a tool, a response comes back, something logs the call, and the result goes to a model. Each of those is a place data can land. Here is where each one lands in an EU workspace on Scalekit.

The hops in one tool call

One tool call in a Scalekit EU workspace: the user's browser and the app provider feed the Frankfurt region, where the token vault, tool-calling gateway, in-memory payload and metadata logs live; the result then goes to your agent, your LLM provider and your application as separate hops.

Hop 1: tokens

The user authorizes your agent on the provider's consent screen, and the integration layer exchanges the authorization code for an access token and a refresh token. In an EU workspace, environment URLs end in .eu.scalekit.com for production and .eu.scalekit.dev for development, and the tokens are written to the vault in Frankfurt.

Each token is encrypted with AES-256-GCM under a data encryption key that belongs to one environment. That key is itself encrypted by a master key in Google Cloud KMS, held apart from the database and the application. The trust center describes the regional clusters as having region-specific encryption. Tokens stay until the connected account is deleted. If you want the root of that key hierarchy in your own Google Cloud KMS, the bring-your-own-key post in this series covers it.

Hop 2: the call

The gateway in Frankfurt looks up the user's credential, adds it to the request and calls the app's API. If the app only accepts traffic from known addresses, you allowlist Scalekit's outbound IP addresses for the EU region.

Say this plainly to your customers: the integration layer's region does not move the app's data. If their CRM tenant is hosted in the US, the CRM's data is in the US regardless of where the gateway runs. EU residency for the integration layer means the copy passing through it, and the credentials it holds, stay in the EU.

Hop 3: the payload

The response is the customer's data: a record, a thread, a file listing. On Scalekit, request and response payloads are processed in memory for the duration of the call and are not stored in Scalekit's database or logs. The response goes back to your agent and is not kept.

This hop carries the most personal data, so it is the one to press any vendor on. A platform that caches responses for retries or stores synced records has a second store of EU personal data with its own retention period.

Hop 4: the logs

Each tool call produces a log entry in the EU region holding the tool name, connection, connected account, user identifier, status, error code, duration and time. Successful responses are not logged.

Two settings decide how much personal data ends up there. Pass an internal user ID as the identifier, not an email address, or every log line carries personal data. And leave Store connector error details off outside debugging, because with it on the log keeps the error the app returned, which can include data from the app. Logs are kept for a fixed window, with longer, configurable retention on Enterprise.

Hop 5: the model

After the agent receives the tool result, it usually sends it to an LLM. That hop is outside the integration layer. Check your model provider's regional processing options, retention terms and DPA on their own. An EU-hosted integration layer feeding a model endpoint outside the EU still transfers the data here.

Hop 6: your application

The orchestrator, conversation state, memory and any vector store are yours. Their residency is your own infrastructure decision, and the DPO will ask about them next.

Where each piece of data sits

Data
Stored by Scalekit?
Where
Kept for
Users' OAuth tokens and API keys
Yes, encrypted per environment
Frankfurt
Until the connected account is deleted
Connection settings, including your OAuth app's client secret
Yes
Frankfurt
Until the connection is deleted
Tool-call inputs
No
Processed in memory in Frankfurt
Not stored
Tool-call responses
No
Processed in memory in Frankfurt
Not stored
Tool-call logs (metadata)
Yes
Frankfurt
A fixed window; longer and configurable on Enterprise
Your API client secrets
A one-way hash
Frankfurt
Until you delete it

What GDPR asks, and where to look in the DPA

GDPR does not require EU residency. It allows transfers outside the EEA with safeguards such as Standard Contractual Clauses. EU buyers write residency into contracts because every transfer they avoid is one fewer to assess.

When a vendor processes EU personal data for you, it is your processor, or your sub-processor if you process on behalf of your own customer. Article 28 of the GDPR requires a written contract and says a processor may engage sub-processors only with the controller's authorization; with a general authorization, the processor has to give notice of changes and a chance to object. Those terms live in the DPA.

Scalekit's DPA, effective January 1, 2026, gives a general authorization from the subprocessor list in Schedule A, at least 30 days' notice of any new or replaced subprocessor with a right to object, EU Standard Contractual Clauses for EEA transfers (Module 2 or 3, governed by Irish law) with UK and Swiss transfer provisions, breach notification without undue delay, audit reports such as SOC 2 on written request, and deletion of customer data on termination.

For any vendor, check five things: whether the subprocessor list and locations are the same for EU and US workspaces; the notice period for changes; the transfer mechanism for any processing or support outside the EEA; whether tool-call payloads are in scope of the DPA's data categories; and breach and deletion terms.

If the layer is self-hosted, the question changes shape. In a self-hosted Scalekit deployment customer data stays in your deployment and Scalekit is not a sub-processor for it. Self-hosted agent integrations covers that path.

Other vendors on EU hosting

From each vendor's own pages as of October 2026. “Not found” means not on their public pages.

Vendor
Managed EU region
What the vendor says
Scalekit
Yes, Frankfurt
Separate US and EU regions with no shared data; payloads processed in memory and not stored
Nango
No
Pricing page says it does not currently have an EU cloud; bring-your-own-cloud in any region on Enterprise. Its docs say cached sync records are pruned after 30 days without an update and deleted after 60 days without a sync run.
Arcade
No
Infrastructure docs say all Arcade Cloud infrastructure is in the United States; self-hosting for residency.
Paragon
Yes
Multi-tenant cloud with US or EU data residency, per its security page.
Merge
Yes
AWS regions in the US, EU and APAC, per its security page.
Composio
Not found
Pricing page says customer-managed keys cover secret storage, not data residency. Self-hosting on Enterprise.

The full comparison, including key custody and compliance, is in Best self-hosted agent integration platforms.

How Scalekit handles EU residency

Choose the region on the signup page, with Change Region, before you create your account. Your workspace and all its environments stay in that region; a workspace cannot move later, so a team serving both US and EU customers creates one workspace in each. The EU region runs on Google Cloud in europe-west3, Frankfurt, independent of the US region in Los Angeles, with no shared application state. EU residency is a $99 a month add-on on Growth and included on Enterprise, and the dashboard asks you to confirm it when you create an environment in an EU workspace.

Scalekit holds SOC 2 Type II and ISO 27001, is GDPR and CCPA compliant, and provides a standard DPA on every plan, with a custom DPA and a HIPAA BAA on Enterprise. The catalog of 500+ connectors and 20,000+ actions is the same in both regions.

Residency is one of three groups of questions a regulated buyer's review covers. The security questionnaire for AI agent vendors has all three, with Scalekit's answers.

Frequently asked questions

What does EU data residency cover for an agent integration layer?

The token vault, the compute that executes tool calls, any payload handling, and the logs. A vendor's region label covers some of these; ask about each one.

Does GDPR require data to stay in the EU?

No. GDPR allows transfers outside the EEA with safeguards such as Standard Contractual Clauses. EU residency is usually a contractual requirement from the buyer.

Where are OAuth tokens stored in Scalekit's EU region?

In Frankfurt, in Google Cloud europe-west3. Each token is encrypted with AES-256-GCM under a per-environment key, which is itself encrypted by a Google Cloud KMS master key held apart from the database.

Does Scalekit store tool-call payloads in the EU region?

No. Tool-call inputs and responses are processed in memory for the duration of the call and are not stored. Logs hold call metadata only.

Can I move an existing Scalekit workspace from the US region to the EU region?

No. The region is chosen at signup and the workspace stays in it. To use both regions, create a workspace in each.

No items found.
Agent
Auth Quickstart
On this page
Share this article
Agent
Auth Quickstart

Acquire enterprise customers with
‍zero upfront cost.

Every feature unlocked. No hidden fees.