Regional Availability

Sectona PAM-Cloud is available across multiple cloud regions to help organisations address data residency, regulatory, compliance, and performance requirements. organisations can select the appropriate deployment region based on business requirements, applicable regulations, and network latency considerations.

Regional deployment enables organisations to host their PAM environment closer to users and managed infrastructure, helping optimise connectivity and application performance while supporting applicable data residency requirements. It also provides the flexibility to align PAM-Cloud deployments with regional regulatory and compliance obligations.

Key benefits include:

  • Data Residency: Enables organisations to select a deployment region that aligns with applicable data residency and regulatory requirements.

  • Performance Optimization: Supports region selection based on network proximity and latency requirements to provide responsive access to the PAM platform.

  • Regulatory Alignment: Helps organisations align their PAM deployment with applicable regional and industry-specific compliance requirements.

  • Business Continuity and Disaster Recovery: Regional availability supports deployment flexibility, but regional selection alone does not constitute disaster recovery or cross-region redundancy. Where required, Cross-Region Availability (CRA) can provide an additional resilience layer by supporting recovery from a regional-level service disruption. CRA is intended to support defined business continuity and disaster recovery objectives, including Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

This section describes:

Region Strategy

Sectona PAM-Cloud supports Intra-Region Availability (IRA) by default and Cross-Region Availability (CRA) as an optional capability. These mechanisms address different failure scenarios and provide distinct levels of resilience and business continuity.

IRA is designed to maintain service availability during component-level or Availability Zone failures within the primary region. CRA, in contrast, extends resilience beyond the primary region by providing a recovery environment in a separate cloud region to address regional-level outages or disasters. For deployments with stringent business continuity and disaster recovery requirements, CRA is recommended to provide protection against regional-level service disruptions.

Intra-Region Availability (IRA) — Default

The primary region hosts the customer instances and actively serves customer requests. Redundant components are distributed across multiple Availability Zones to maintain service availability in the event of component or zone-level failures. The primary region provides the operational PAM services required for day-to-day activities, including:

  • User authentication and access management

  • Application processing

  • Privileged session management

  • Credential and vault operations

  • Other core PAM services

IRA provides in-region high availability, but it does not provide protection against a complete regional outage.

Cross-Region Availability (CRA) — Optional

Cross-Region Availability (CRA) provides an additional disaster recovery and business continuity capability by maintaining a secondary recovery environment in a separate cloud region. The secondary region is maintained in a standby state and is not the primary environment for normal customer operations.

If the primary region becomes unavailable due to a regional outage or disaster, PAM-Cloud services can be recovered in the secondary region to restore service availability with minimal disruption. CRA therefore provides regional-level resilience, complementing IRA's protection against component and Availability Zone failures. It is recommended for environments with stringent business continuity, disaster recovery, RTO, and RPO requirements.

We recommend opting for Cross-Region Availability (CRA) for environments with stringent business continuity and disaster recovery requirements. CRA provides an additional layer of regional resilience by maintaining a recovery environment in a separate region, helping organisations restore PAM services in the event of a primary-region outage while maintaining appropriate security and operational controls.

Infrastructure Overview

Sectona PAM-Cloud is hosted on secure cloud infrastructure designed to provide a scalable, resilient, and highly available platform for enterprise deployments. The platform supports multiple geographic regions, with each region comprising multiple isolated Availability Zones. This architecture enables fault-tolerant service delivery and provides protection against component and Availability Zone-level failures.

Each region is designed to provide the following capabilities:

  • High Availability: Deploys redundant infrastructure components across multiple Availability Zones to minimize service disruption caused by component or zone-level failures.

  • Low Latency: Enables organisations to select a deployment region geographically closer to their users and managed infrastructure, helping reduce network latency and improve application responsiveness.

  • Scalability: Provides scalable infrastructure capacity to accommodate increasing workloads, users, managed assets, and privileged sessions based on business requirements.

  • Security: Incorporates enterprise-grade physical, infrastructure, and network security controls to protect the underlying cloud environment and customer workloads.

  • Regional Resilience: Provides Intra-Region Availability (IRA) by distributing redundant components across Availability Zones within the selected region. For enhanced business continuity and disaster recovery, Cross-Region Availability (CRA) can provide recovery capabilities in a separate geographic region.

Region Coverage Overview

Sectona PAM-Cloud supports deployment across multiple geographic regions. Each region is associated with a primaryIntra-Region Availability (IRA) deployment, with Cross-Region Availability (CRA) available where a secondary recovery region is supported.

Regional Deployment Coverage

Geographic Region

Region

Availability Role

Primary Usage

South Asia (SA)

Mumbai, India

Intra-Region Availability (IRA)

Hosts all active application workloads.

Hyderabad, India

Cross-Region Availability (CRA)

Provides backup, replication, and regional disaster recovery support.

Middle East (ME)

Dubai, UAE

Intra-Region Availability (IRA)

Hosts all active application workloads.

NA

Cross-Region Availability (CRA)

Not currently available.

United Kingdom (UK)

London, UK

Intra-Region Availability (IRA)

Hosts all active application workloads.

Ireland

Cross-Region Availability (CRA)

Provides backup, replication, and regional disaster recovery support.

European Union (EU)

Frankfurt, Germany

Intra-Region Availability (IRA)

Hosts all active application workloads.

Ireland

Cross-Region Availability (CRA)

Provides backup, replication, and regional disaster recovery support.

East Asia (EA)

Singapore

Intra-Region Availability (IRA)

Hosts all active application workloads.

NA

Cross-Region Availability (CRA)

Not currently available.

Regional Connectivity Endpoints

Geographic Region

PAM-Cloud Endpoint

RNA Proxy Server Endpoint

South Asia (SA)

*.sectona.cloud

*.rna.sectona.cloud

Middle East (ME)

*.sectona.cloud

*.rna.sectona.cloud

United Kingdom (UK)

*.sectona.cloud

*.rna.sectona.cloud

European Union (EU)

*.sectona.cloud

*.rna.sectona.cloud

East Asia (EA)

*.sectona.cloud

*.rna.sectona.cloud

Workload Distribution

Sectona PAM-Cloud distributes workloads across Intra-Region Availability (IRA) and Cross-Region Availability (CRA) according to their respective availability and recovery roles.

In IRA, application and supporting components operate within the primary region and provide active PAM services to customers. Redundant components are distributed across Availability Zones to support high availability and continuity during component or zone-level failures.

In CRA, selected data and infrastructure components are maintained in a separate recovery region in accordance with the configured disaster recovery architecture. CRA resources support backup, replication, and recovery operations and are intended to restore PAM services following a primary-region or regional-level failure.

Component

Intra-Region Availability (IRA)

Cross-Region Availability (CRA)

Application Node

Active / Active

Active / Standby

Vault Node

Active / Passive

Backup and Replication

Video Log Storage

Active / Passive

Data Replication

RNA Proxy Server

Active / Passive

Active / Standby

Workload Model

  • Application Nodes: IRA maintains multiple active application nodes to distribute workloads and provide high availability. CRA maintains standby application resources for recovery during a regional outage.

  • Vault Nodes: IRA uses an active/passive configuration to maintain vault availability and data integrity. CRA provides backup and replication of vault data to the recovery region.

  • Video Log Storage: IRA maintains the active session recording storage infrastructure. CRA replicates session recording data to support recovery and data retention requirements.

  • RNA Proxy Server: IRA maintains redundant proxy server components to support service availability. CRA maintains standby proxy resources that can be activated as part of regional recovery.

Cross-Region Availability (CRA) is an optional capability and is provisioned based on the customer's licensed features and subscription plan.

Geographical Access Restriction

Sectona PAM-Cloud enforces geographic access controls to restrict platform access based on the source country or geographic region of an access request. These controls provide an additional security layer to reduce unauthorized access from restricted or high-risk locations and help organisations meet applicable organisational, regulatory, and compliance requirements.

Restricted Countries: North Korea, Iran, Syria, Afghanistan.

Implementation:

  • Geo-Restriction Controls: Geographic access restrictions are enforced through Web Application Firewall (WAF) geo-restriction rules and supporting network-level security controls.

  • Default-Deny Access Model: Access is governed using a default-deny approach, with authentication requests permitted only from explicitly approved countries or regions.

  • Automated Request Blocking: Access requests originating from restricted or non-approved geographic locations are automatically blocked before the request can proceed to the authentication and application layers.

Access Evaluation:

Geographic access decisions are evaluated using contextual attributes associated with the access request, including:

  • User Geographic Location: The geographic location identified from the source of the access request.

  • Authentication Conditions: Applicable authentication and access conditions associated with the request.

  • Configured Geo-Restriction Policies: organisational policies defining permitted, restricted, or blocked countries and regions.

Geographic access restrictions provide an additional access-control layer and should be used in conjunction with authentication, authorization, network security, and other PAM security controls.