Sub-processors — version 1.2
In effect from 2026-09-10. Supersedes version 1.1. Previous versions remain available at/legal/subprocessors/versions/.
Sub-processors
Version 1.2 · In effect from 10 September 2026 · supersedes 1.1 of 4 September 2026
Aporta Systems, LLC uses the providers below to deliver the Service. Each is engaged under a written data processing agreement, and we remain responsible to our customers for what each of them does.
We give customers at least thirty days’ notice before we add or replace a provider, and a right to object on reasonable data protection grounds.
| Provider | What it does for us | What personal data it can reach | Location |
|---|---|---|---|
| Cloudflare, Inc. | Edge compute; storage of audit records; DNS and email routing; cookieless analytics on this website and in the Aporta dashboard | Encrypted audit records; tokenized content in transit. Prompt text is present unencrypted at the edge for the moment detection runs. Analytics on this website and in the dashboard are aggregate only, with no cookie and no visitor identifier. | United States |
| Modal Labs, Inc. | Second-tier detection | Prompt text and extracted attachment text, in the clear, at the moment of detection. Processed in memory and not retained. A customer can turn this tier off. | United States |
| Turso (ChiselStrike, Inc.) | Per-customer vault and metadata databases | Encrypted token-to-value mappings; account metadata | United States |
| WorkOS, Inc. | Sign-in, directory and role assignment | Names, work email addresses, role assignments. No prompt content. | United States |
| Resend (Plus Five Five, Inc.) | Delivers one message, and only one: the email telling your administrators that browsers are waiting to be enrolled | The work email addresses of those administrators, because they are the recipients — which also tells this provider your domain. The message itself carries a count of how many browsers are waiting and how long the oldest has waited. No employee names, no prompt content, no token mappings, no audit records, no account identifiers. Delivery metadata is held by the provider under its own terms. | United States |
| Microsoft Corporation | Business email, document storage and support correspondence | Contact details, and anything personal included in correspondence, contracts or support requests. No prompt content, token maps or audit records. | United States |
| Stripe, Inc. | Payment processing and billing | Billing contact name and email, subscription and invoice records. Card details go to Stripe directly and are never held by us. No prompt content. | United States |
Two things worth saying plainly
Two of these do not run the Service. Microsoft holds our email and documents; Stripe holds our billing. Personal data reaches both. They are listed for the same reason as the five that run the Service — a provider holding your correspondence or your invoices is handling your personal data as surely as one running our servers, and a list covering only the second would be a list chosen to look short.
Our payment processor is not purely acting on our instructions. Stripe uses payment data on its own account for fraud prevention and regulatory compliance, as its own terms describe. That is true of every payment processor and is rarely said out loud.
Their vendors
The chain does not end here.
Our second-tier detection provider operates no physical infrastructure of its own. It schedules work across a pool of cloud providers it publishes. Our configuration fixes the country that work runs in. It does not fix which provider runs it.
Each of the others engages its own vendors under its own terms.
Notice we receive, compared with notice we give
We promise our customers thirty days. Four of these providers give us less.
| Provider | Notice we receive |
|---|---|
| Microsoft | Six months for customer data; thirty days for sub-processors supporting AI features |
| Amazon Web Services (from the date it appears above) | Thirty days |
| Stripe | Thirty days |
| Cloudflare | Thirty days |
| WorkOS | Fourteen days, by updating a page we are responsible for checking |
| Turso | Ten days, by email — and silence for ten days counts as agreement |
| Modal | Thirty days, but it may replace a provider urgently and tell us afterwards |
| Resend | Fourteen days, in writing — and silence for fourteen days counts as agreement |
So for a change that starts in one of those chains, we cannot give you the thirty days we promise. We would give you what we have, as soon as we have it. We would rather say that than promise a chain of notice we cannot enforce.
Not on this list
Software stores. Our extension is distributed through the Chrome Web Store and Microsoft Edge Add-ons. They host a package and report install counts. No prompt content, token map or audit record reaches either, and the relationship each has with someone installing the extension is its own, not one we direct. They matter to us — they gate every release — but they are not sub-processors and we would rather not pad this list with names that hold nothing.
Questions
Changelog
1.2 — 10 September 2026. Adds Resend (Plus Five Five, Inc.), which delivers the enrollment notice described in its row. It has been wired into the Service since that notice was built and appeared on no earlier version of this list; it was found on 9 September 2026 by reading our own code, which is not how a gap in this page should be found. Its location and notice period were taken from its data processing addendum rather than from what is usual, and the notice comparison above changes from three providers to four as a result.
1.1 — 4 September 2026. Added Stripe, Inc. (payment processing) on wiring billing. Added Microsoft Corporation (business email, document storage, support correspondence). Recorded cookieless analytics, on this website and in the dashboard, under Cloudflare’s existing entry. Added the notice comparison above.
1.0 — 4 September 2026. First published list.