EU Hosting for API Documentation, Now on Theneo Enterprise | Theneo Blog
EU Hosting for API Documentation, Now on Theneo Enterprise
Theneo now offers EU hosting on the Enterprise plan, so your workspace data sits on EU servers. What it covers, who needs it, and how it differs from GDPR compliance.
By
Mariam Lekveishvili
Published
May 11, 2026
Updated:
September 7, 2026
Theneo now offers EU hosting on the Enterprise plan. Your workspace data is hosted on servers located in the EU, which means the first question European procurement teams ask has a clear, documented answer.
The short version
EU hosting is available on Theneo Enterprise. Documentation content and version history, workspace and project configuration, user authentication and session data, API keys, collaboration activity, portal analytics and branding settings are all hosted on EU-based servers. Data is encrypted at rest and in transit, and a Data Processing Agreement is included. It sits alongside SSO (SAML), role-based access control, white-label branding and dedicated support.
Why documentation platforms come up in security review
Teams are often surprised that a developer portal triggers a data question at all. It looks like published pages.
It is not. A documentation platform holds authentication and session data, API keys and access tokens, workspace configuration, and a full record of who edited what and when. That is credential-adjacent data with an audit trail attached, which is exactly the category security reviewers care about. Once a reviewer sees the list, "it is only documentation" stops being a persuasive answer, and the vendor assessment starts in earnest.
The teams that move fastest through that review are the ones whose vendor already has the answer written down.
What EU hosting covers on Theneo Enterprise
With EU hosting enabled on your Enterprise workspace, the following is hosted on EU-based servers:
- API documentation content and version history
- Workspace and project configuration
- User authentication and session data
- API keys and access tokens
- Collaboration activity including comments, edits and review workflows
- Developer portal analytics and usage metrics
- Custom domain and branding configuration
Data is encrypted at rest and in transit. A Data Processing Agreement is included on the Enterprise plan rather than being a separate negotiation, which removes one of the more common sources of delay in a procurement cycle.
EU hosting and GDPR compliance answer different questions
These two get treated as one requirement, and knowing the difference is worth a few minutes because it changes what you ask vendors.
GDPR compliance is about how personal data is handled. Lawful basis for processing, data minimisation, subject access and erasure rights, breach notification, and valid safeguards for transfers outside the EU. It describes conduct.
Hosting location is about where the data sits. Which servers hold it, and in which region.
A vendor can be fully GDPR compliant while hosting your data in the United States, because standard contractual clauses and adequacy decisions exist to make those transfers lawful. GDPR does not by itself require EU storage. So "yes, we are GDPR compliant" is a real answer to a real question, but it is not an answer to "where is our data hosted?"
Theneo answers both. The platform is GDPR compliant and holds SOC 2, ISO 27001 and ISO 9001 certifications, and EU hosting is available on Enterprise. See the security and compliance overview for the full control set.
Who asks for EU hosting
Requests come overwhelmingly from teams whose procurement checklist contains a specific line about data location.
- Financial services and fintech working under EBA guidance and national banking rules, where any third-party platform holding access credentials draws closer scrutiny.
- Healthcare and life sciences operating under national health data laws.
- Public sector and government contractors, where procurement mandates frequently specify EU or national hosting for every SaaS vendor in the stack.
- Insurance teams modernising their APIs while working within Solvency II and national data protection rules.
If your checklist includes "where is customer data hosted?" and "is a DPA available?", both are answered on the Enterprise plan.
What the EU Data Act means for your vendor choice
The EU Data Act, formally Regulation (EU) 2023/2854, entered into force on 11 January 2024 and has been applicable since 12 September 2025. Its main obligations are live now, not pending.
Where GDPR governs personal data, the Data Act covers access to and use of data more broadly. The part that matters when choosing software is its treatment of data processing services, which targets vendor lock-in through provisions on switching providers and data portability. Further requirements phase in from 12 September 2026 and into 2027.
The practical translation for documentation is portability. Can you take your content, specifications and structure elsewhere without rebuilding? Theneo imports and exports across OpenAPI, Swagger, Postman, GraphQL and gRPC, and preserves your URL structure on migration, so your published paths and search rankings survive a move. The mechanics that make leaving possible are the same ones that make arriving painless, which is why migrations onto Theneo typically complete in days rather than quarters.
What to check before you commit
Three questions decide most documentation procurement reviews, and it is worth knowing where Theneo lands on each.
- Does hosting cover the whole product or only the published portal? On Theneo Enterprise, EU hosting covers your workspace data across the platform, not just the pages your developers read.
- Is a DPA standard or a negotiation? Included on Enterprise.
- Can you get your content out again? Full export across every supported specification format, with URL structure preserved.
Getting EU hosting
EU hosting is available now on the Theneo Enterprise plan, alongside SSO, role-based access control, white-label developer portals and SLA-backed support. If you are working through a security review or a procurement questionnaire, book a call and we will walk through your requirements directly.
Frequently Asked Questions
Does Theneo offer EU hosting for API documentation?
Yes. EU hosting is available on the Theneo Enterprise plan, and your workspace data is hosted on servers located in the EU. It sits alongside SAML SSO, role-based access control, white-label branding and SLA-backed support, with a Data Processing Agreement included.
What does Theneo's EU hosting cover?
Documentation content and version history, workspace and project configuration, user authentication and session data, API keys and access tokens, collaboration activity such as comments and review workflows, developer portal analytics, and custom domain and branding configuration. Data is encrypted at rest and in transit.
Is EU hosting the same as GDPR compliance?
No, they answer different questions. GDPR compliance is about how personal data is handled: lawful basis, minimisation, subject rights, breach notification and transfer safeguards. Hosting location is about where the data sits. A vendor can be GDPR compliant while hosting outside the EU, which is why procurement teams increasingly ask both. Theneo is GDPR compliant and offers EU hosting on Enterprise.
Which teams need EU-hosted developer portals?
Teams whose procurement checklist names data location: fintech and financial services under EBA guidance, healthcare and life sciences under national health data laws, public sector and government contractors with EU or national hosting mandates, and insurers working within Solvency II.
Does the EU Data Act change how I choose a documentation platform?
It should. Regulation (EU) 2023/2854 has applied since 12 September 2025, and its provisions on data processing services target vendor lock-in through switching and portability requirements. For documentation, that means checking whether you can export content, specifications and structure and move without rebuilding. Theneo exports across OpenAPI, Swagger, Postman, GraphQL and gRPC and preserves URL structure on migration.