Sub-processors — version 1.1
In effect from 2026-09-04. Supersedes version 1.0. Previous versions remain available at/legal/subprocessors/versions/.
Sub-processors
Version 1.1 · In effect from 4 September 2026
Aporta Systems, LLC uses the providers below to deliver the Service. Each is engaged under a written data processing agreement, and we remain responsible to our customers for what each of them does.
We give customers at least thirty days’ notice before we add or replace a provider, and a right to object on reasonable data protection grounds.
| Provider | What it does for us | What personal data it can reach | Location |
|---|---|---|---|
| Cloudflare, Inc. | Edge compute; storage of audit records; DNS and email routing; cookieless analytics on this website and in the Aporta dashboard | Encrypted audit records; tokenized content in transit. Prompt text is present unencrypted at the edge for the moment detection runs. Analytics on this website and in the dashboard are aggregate only, with no cookie and no visitor identifier. | United States |
| Modal Labs, Inc. | Second-tier detection | Prompt text and extracted attachment text, in the clear, at the moment of detection. Processed in memory and not retained. A customer can turn this tier off. | United States |
| Turso (ChiselStrike, Inc.) | Per-customer vault and metadata databases | Encrypted token-to-value mappings; account metadata | United States |
| WorkOS, Inc. | Sign-in, directory and role assignment | Names, work email addresses, role assignments. No prompt content. | United States |
| Microsoft Corporation | Business email, document storage and support correspondence | Contact details, and anything personal included in correspondence, contracts or support requests. No prompt content, token maps or audit records. | United States |
| Stripe, Inc. | Payment processing and billing | Billing contact name and email, subscription and invoice records. Card details go to Stripe directly and are never held by us. No prompt content. | United States |
Two things worth saying plainly
Two of these do not run the Service. Microsoft holds our email and documents; Stripe holds our billing. Personal data reaches both. They are listed for the same reason as the four that run the Service — a provider holding your correspondence or your invoices is handling your personal data as surely as one running our servers, and a list covering only the second would be a list chosen to look short.
Our payment processor is not purely acting on our instructions. Stripe uses payment data on its own account for fraud prevention and regulatory compliance, as its own terms describe. That is true of every payment processor and is rarely said out loud.
Their vendors
The chain does not end here.
Our second-tier detection provider operates no physical infrastructure of its own. It schedules work across a pool of cloud providers it publishes. Our configuration fixes the country that work runs in. It does not fix which provider runs it.
Each of the others engages its own vendors under its own terms.
Notice we receive, compared with notice we give
We promise our customers thirty days. Three of these providers give us less.
| Provider | Notice we receive |
|---|---|
| Microsoft | Six months for customer data; thirty days for sub-processors supporting AI features |
| Amazon Web Services (from the date it appears above) | Thirty days |
| Stripe | Thirty days |
| Cloudflare | Thirty days |
| WorkOS | Fourteen days, by updating a page we are responsible for checking |
| Turso | Ten days, by email — and silence for ten days counts as agreement |
| Modal | Thirty days, but it may replace a provider urgently and tell us afterwards |
So for a change that starts in one of those chains, we cannot give you the thirty days we promise. We would give you what we have, as soon as we have it. We would rather say that than promise a chain of notice we cannot enforce.
Not on this list
Software stores. Our extension is distributed through the Chrome Web Store and Microsoft Edge Add-ons. They host a package and report install counts. No prompt content, token map or audit record reaches either, and the relationship each has with someone installing the extension is its own, not one we direct. They matter to us — they gate every release — but they are not sub-processors and we would rather not pad this list with names that hold nothing.
Questions
Changelog
1.1 — 4 September 2026. Added Stripe, Inc. (payment processing) on wiring billing. Added Microsoft Corporation (business email, document storage, support correspondence). Recorded cookieless analytics, on this website and in the dashboard, under Cloudflare’s existing entry. Added the notice comparison above.
1.0 — 4 September 2026. First published list.