This is a superseded version. It is kept at a permanent address so the text in force on a past date can be produced. It is not the current policy — read the current sub-processors instead.

Sub-processors — version 1.1
In effect from 2026-09-04. Supersedes version 1.0. Previous versions remain available at /legal/subprocessors/versions/.

Sub-processors

Version 1.1 · In effect from 4 September 2026

Aporta Systems, LLC uses the providers below to deliver the Service. Each is engaged under a written data processing agreement, and we remain responsible to our customers for what each of them does.

We give customers at least thirty days’ notice before we add or replace a provider, and a right to object on reasonable data protection grounds.

Provider What it does for us What personal data it can reach Location
Cloudflare, Inc. Edge compute; storage of audit records; DNS and email routing; cookieless analytics on this website and in the Aporta dashboard Encrypted audit records; tokenized content in transit. Prompt text is present unencrypted at the edge for the moment detection runs. Analytics on this website and in the dashboard are aggregate only, with no cookie and no visitor identifier. United States
Modal Labs, Inc. Second-tier detection Prompt text and extracted attachment text, in the clear, at the moment of detection. Processed in memory and not retained. A customer can turn this tier off. United States
Turso (ChiselStrike, Inc.) Per-customer vault and metadata databases Encrypted token-to-value mappings; account metadata United States
WorkOS, Inc. Sign-in, directory and role assignment Names, work email addresses, role assignments. No prompt content. United States
Microsoft Corporation Business email, document storage and support correspondence Contact details, and anything personal included in correspondence, contracts or support requests. No prompt content, token maps or audit records. United States
Stripe, Inc. Payment processing and billing Billing contact name and email, subscription and invoice records. Card details go to Stripe directly and are never held by us. No prompt content. United States

Two things worth saying plainly

Two of these do not run the Service. Microsoft holds our email and documents; Stripe holds our billing. Personal data reaches both. They are listed for the same reason as the four that run the Service — a provider holding your correspondence or your invoices is handling your personal data as surely as one running our servers, and a list covering only the second would be a list chosen to look short.

Our payment processor is not purely acting on our instructions. Stripe uses payment data on its own account for fraud prevention and regulatory compliance, as its own terms describe. That is true of every payment processor and is rarely said out loud.

Their vendors

The chain does not end here.

Our second-tier detection provider operates no physical infrastructure of its own. It schedules work across a pool of cloud providers it publishes. Our configuration fixes the country that work runs in. It does not fix which provider runs it.

Each of the others engages its own vendors under its own terms.

Notice we receive, compared with notice we give

We promise our customers thirty days. Three of these providers give us less.

Provider Notice we receive
Microsoft Six months for customer data; thirty days for sub-processors supporting AI features
Amazon Web Services (from the date it appears above) Thirty days
Stripe Thirty days
Cloudflare Thirty days
WorkOS Fourteen days, by updating a page we are responsible for checking
Turso Ten days, by email — and silence for ten days counts as agreement
Modal Thirty days, but it may replace a provider urgently and tell us afterwards

So for a change that starts in one of those chains, we cannot give you the thirty days we promise. We would give you what we have, as soon as we have it. We would rather say that than promise a chain of notice we cannot enforce.

Not on this list

Software stores. Our extension is distributed through the Chrome Web Store and Microsoft Edge Add-ons. They host a package and report install counts. No prompt content, token map or audit record reaches either, and the relationship each has with someone installing the extension is its own, not one we direct. They matter to us — they gate every release — but they are not sub-processors and we would rather not pad this list with names that hold nothing.

Questions

[email protected]


Changelog

1.1 — 4 September 2026. Added Stripe, Inc. (payment processing) on wiring billing. Added Microsoft Corporation (business email, document storage, support correspondence). Recorded cookieless analytics, on this website and in the dashboard, under Cloudflare’s existing entry. Added the notice comparison above.

1.0 — 4 September 2026. First published list.

Generated from docs/governance/legal/subprocessors.md. The source of truth is the governance register in the application repository, not this page.