Documents, photos, and videos show TikTok's US datacenters have faced security failures and use servers made by Inspur, which the US sanctioned in March 2023
Emily Baker-White / Forbes :
Context & Ripple Effects
TikTok's Project Texas briefing in January promised to keep US user data inside a US subsidiary on Oracle Cloud as the core of its plan to keep operating in America. This Forbes report — documents, photos, and videos from inside TikTok's US datacenters — undercuts that pitch from the hardware side: the facilities have faced security failures and run servers made by Inspur, which the US sanctioned in March 2023.
The finding extends a pattern in the related coverage: TikTok already acknowledged to GOP senators that China-based employees could access some US user information, and Forbes later reported sensitive creator financial data stored on China-based servers. The question is shifting from who can see TikTok's data to what physical infrastructure Project Texas actually rests on.
First-order effects
- TikTok's Project Texas credibility takes a direct hit: a US datacenter running servers from a sanctioned Chinese vendor is hard to reconcile with the Oracle Cloud localization pitch it made to Washington.
- Oracle, as TikTok's named US cloud partner, faces scrutiny over whether the hardware inside its Project Texas footprint meets the security bar the deal was designed to signal.
Second-order effects
- Regulators and lawmakers weighing TikTok's future now have a supply-chain argument to add to the data-access argument, strengthening the case for divestment or a ban rather than a mitigation agreement.
- Other ByteDance-adjacent and Chinese-vendor hardware in US datacenters becomes audit targets, as procurement teams at US cloud and social platforms reassess sanctioned-component exposure.
Third-order effects
- If the pattern holds, data-localization pledges alone stop being sufficient political cover — US reviews of foreign platforms extend down to servers and components, making hardware provenance a standing condition for operating in the US market.
The trend: US scrutiny of Chinese-owned platforms is expanding from where user data lives to whose hardware it runs on, with sanctioned-vendor exposure becoming a test that software-level mitigation plans like Project Texas struggle to pass.