Oct 5, 2026

Keeping data on American soil: A Q&A on Regional Restricted Access

We asked Tim Koubek (President of TeamViewer Americas) explains how US data residency became a boardroom issue, and how Regional Restricted Access addresses it.

Connect and support people

For regulated US organizations, "where does our data live?" is no longer a question you can answer with a single line in a vendor contract. Over the past few years, it's become a boardroom conversation, tied directly to customer trust, compliance obligations, and cybersecurity posture.

To understand what's driving that shift, and what regulated buyers now expect from remote access, we sat down with Tim Koubek, President of TeamViewer Americas. In his view, customers today aren't simply purchasing remote access. They're buying the confidence that their support operations won't introduce cross-border data risk.

Much deeper than a hosting question, this shift reflects a new standard for control, transparency, and enforceability, and it's exactly what TeamViewer's Regional Restricted Access (RRA) was built to meet.  

The problem: Why data residency became a boardroom priority

Q. From your vantage point leading the Americas, how has the conversation around data residency and data control changed among US organizations over the past couple of years?

 

A. Today, conversations around data residency and control are going much deeper than they ever have. It isn’t just “Where is our data generally hosted?” it’s much more precise, customers see all the capabilities we offer and they’re asking: “Can you prove our remote-access activity, account data, session data, policies, event logs, and connection flow stay within the United States?” For many US organizations, especially those serving government, healthcare, finance, and in general, highly regulated industries, data residency is now tied directly to customer trust and their overall cyber-security posture.

 

Ever since the major US Treasury data breach at the end of 2024, customers are hyper focused on fortifying their infrastructures. They are not just buying remote access; they are buying confidence that their support operations do not introduce cross-border data risk.

 

Q. What are you hearing directly from customers in regulated sectors (government, healthcare, finance) about where their remote-access data lives and who can touch it? How much of this is driven by regulation, compliance, or cyber-insurance pressure?

 

A. Customers are asking very practical questions: where does our data live, where are connections initiated and validated, where are access rules enforced, and can users or devices outside the US touch the environment? In regulated sectors, those questions are being driven by a mix of compliance obligations, internal governance, cyber-insurance requirements, and pressure from their own customers or constituents. The value they are looking for is reduced ambiguity. They want a remote-access model that helps them demonstrate control, simplify oversight, and reduce exposure to cross-border data-transfer concerns.

What's needed: The non-negotiables regulated buyers bring to the table

Q. When a regulated US buyer evaluates remote access today, what are the non-negotiables they bring to the table? What does "keeping data local" really mean to them in practice?

 

A. The non-negotiables are control, transparency, and enforceability. “Keeping data local” means more than storing records in a US data center. It means connections are initiated, validated, and established through our US infrastructure.

 

Consider our highly secure Conditional Access rule engine for example. This capability dictates who can connect, what systems they can connect to, when they can connect, if a manager, whether on-site or off-site, needs to approve their connection each time, and even what they can do during that remote connection. This rule engine lives on systems that are located in the US and handled in the US; so account and TeamViewer data remains here, and remote connections are limited to users and devices tied to our US-based systems.

 

In practice, customers want clear guardrails that help them support audits, align with sector-specific requirements, and reassure stakeholders that sensitive remote-access activity stays under US jurisdiction.

The solution: How Regional Restricted Access keeps data in the US

Q. At a high level, how does Regional Restricted Access deliver what these customers are asking for?

 

A. Regional Restricted Access gives customers a purpose-built way to run enterprise remote connectivity within a US-only operating model. It restricts data and connection flow to TeamViewer’s US infrastructure, uses US-based Conditional Access routers, limits connections to clients and hosts tied to this US infrastructure, and any TeamViewer information or data that is stored (such as account data, policies, etc.) is stored in US cloud instances —everything else is blocked.

 

For customers, the benefit is straightforward: they can keep remote-access activity aligned to their data-residency expectations while still using our industry leading Tensor capabilities for secure, scalable remote support.

 

Q. RRA launched US-first. From an Americas market standpoint, why was that the right place to start?

 

A. The US was the right place to start because demand is exceptionally strong among US organizations who have strict needs around data-governance. This requirement extends to entities like state and local governments, government-adjacent organizations, financial institutions, insurers, and even healthcare companies. For these customers, data residency can be a buying requirement, not a preference.

 

Launching US-first allows TeamViewer to address a clear customer need in a market where the value is immediate: helping organizations keep sensitive remote-access data and activity on US soil.

 

Q. TeamViewer's ServiceNow integration is a big part of the broader Tensor story. For a customer starting with RRA for data residency, how should they think about that relationship?

 

A. For customers, the connection between Regional Restricted Access and ServiceNow is really about making secure remote support feel natural inside the systems their teams are already using. Regional Restricted Access gives regulated US organizations confidence that their remote-access data and activity stay within a US operating model. ServiceNow then brings that secure remote-support experience directly into the incident workflow.

 

That means technicians can launch an auditable remote session from the ServiceNow incident, work with the context they need, and keep the service record updated without bouncing between tools. It helps IT move faster, but it also gives security and compliance teams the traceability they need to feel comfortable with how remote support is being delivered.

 

The bigger point is that this is not just a data-residency story, and it isn’t just an integration story. TeamViewer and ServiceNow give customers a controlled, workflow-connected support model. Together we’re jointly delivering autonomous IT: ServiceNow orchestrates the work, and TeamViewer brings action to the endpoint. For customers, that means faster resolution, less friction for technicians, and a stronger compliance posture.

The outcome: What changes for customers and their stakeholders

Q. For a customer who adopts RRA, what changes for them, both operationally and in the confidence they can give their own stakeholders, auditors, or constituents?

 

A. Operationally, customers gain a more controlled remote-access environment with clearer boundaries around where data is stored, processed, and routed. That can simplify internal reviews, reduce legal and operational risk, and give IT and security teams more confidence when explaining their remote-access posture to auditors, regulators, customers, or even constituents.

 

Strategically, it helps them show that they are taking data protection seriously, not just by policy, but by architecture.

 

Q. If you could leave one piece of advice with a US IT or security leader wrestling with data-residency pressure, what would it be?

 

A. For many US organizations, data residency is already a business requirement. The real question is whether their remote-access architecture can actually prove it and enforce it. My advice would be to look beyond policy language and ask: where is the data stored, where are connections routed, who can access the environment, and what evidence can we show auditors, customers, insurers, or public stakeholders?

 

When data residency is a must-have, the best solution is one that makes compliance the default operating model, not an exception teams have to manage manually. That is where the right architecture matters. It should give IT and security leaders clear boundaries, fewer gray areas, and the confidence to support the business without introducing new risk.

 

That is where TeamViewer’s Regional Restricted Access helps turn a data-residency requirement into an operating model customers can actually stand behind.

Ellen Cruise

Content Marketing Manager at TeamViewer

—

Ellen Cruise is a Content Marketing Manager at TeamViewer. With experience leading integrated campaigns across Tensor, DEX, and TeamViewer ONE, she enjoys translating complex technology into practical, customer-first content that reflects how organizations work.

Tim Koubek

President, Americas at TeamViewer

—

Tim Koubek is President, Americas at TeamViewer, where he leads the company's go-to-market strategy and growth across the region. An accomplished enterprise sales executive, he is known for scaling revenue, implementing disciplined sales methodologies, and driving transformational growth across infrastructure software businesses.

Learn more about Regional Restricted Access

Regional Restricted Access keeps enterprise remote connectivity within US infrastructure. See how it maps to your compliance requirements.