This page helps solution architects and compliance teams identify deployment questions that must be resolved when application data is subject to geographic or organisational location requirements.
Document the deployment scope
The Deployment overview describes deployment guidance for on-premises and cloud environments, including IIS, Azure, Docker, Linux, macOS, CI/CD, scaling, and load balancing.
Before selecting an architecture, document the infrastructure and services that will store, process, transmit, or receive application data. This assessment should include the application deployment, data storage, backups, logs, administrative access, deployment tooling, and external integrations.
Select deployment options deliberately
Choose deployment infrastructure that meets the organisation's technical, security, and location requirements. The available documentation includes deployment paths for:
- On-premises environments.
- Microsoft Azure.
- Docker containers.
- Windows IIS.
- Linux web-server environments.
- CI/CD-based deployment processes.
The supplied deployment overview does not state which geographic regions are available for any MDriven-managed offering, nor does it define a geographic-residency architecture. Do not infer a residency commitment from a deployment target alone; verify the location and handling of every relevant infrastructure service with the responsible provider.
Review integrations and access
MDriven states that applications can expose ViewModels as REST endpoints and can be extended with custom C#. Review each integration and API as a potential application-data flow. Record what data is exchanged, the receiving service, and the locations in which that service processes or stores the data.
MDriven also states that role-based access can be defined in the model. Use application access design together with the organisation's infrastructure and identity controls to limit access appropriately.
Plan availability and recovery
The deployment overview includes scaling and load-balancing topics, including load-balancing considerations for Turnkey and MDrivenServer. It does not, in the supplied material, specify a supported multi-region topology, replication method, backup location, or automated failover procedure.
Define and test availability, backup, restoration, and recovery procedures with the selected infrastructure and database providers. Where data-location requirements apply, verify that the planned recovery process meets those requirements before relying on it.
Deployment review checklist
- Identify the location and handling requirements for each data set.
- Select a documented deployment approach appropriate to the organisation's environment.
- Record all infrastructure and external services that store, process, transmit, or receive application data.
- Review API and integration data flows.
- Define access controls and operational responsibilities.
- Obtain provider and MDriven confirmation for regional availability, backups, support access, replication, and recovery arrangements where required.
- Test the approved recovery process and retain the resulting evidence.
