This is a superseded version. It is kept at a permanent address so the text in force on a past date can be produced. It is not the current policy — read the current sub-processors instead.

Sub-processors — version 1.2
In effect from 2026-09-10. Supersedes version 1.1. Previous versions remain available at /legal/subprocessors/versions/.

Sub-processors

Version 1.2 · In effect from 10 September 2026 · supersedes 1.1 of 4 September 2026

Aporta Systems, LLC uses the providers below to deliver the Service. Each is engaged under a written data processing agreement, and we remain responsible to our customers for what each of them does.

We give customers at least thirty days’ notice before we add or replace a provider, and a right to object on reasonable data protection grounds.

Provider What it does for us What personal data it can reach Location
Cloudflare, Inc. Edge compute; storage of audit records; DNS and email routing; cookieless analytics on this website and in the Aporta dashboard Encrypted audit records; tokenized content in transit. Prompt text is present unencrypted at the edge for the moment detection runs. Analytics on this website and in the dashboard are aggregate only, with no cookie and no visitor identifier. United States
Modal Labs, Inc. Second-tier detection Prompt text and extracted attachment text, in the clear, at the moment of detection. Processed in memory and not retained. A customer can turn this tier off. United States
Turso (ChiselStrike, Inc.) Per-customer vault and metadata databases Encrypted token-to-value mappings; account metadata United States
WorkOS, Inc. Sign-in, directory and role assignment Names, work email addresses, role assignments. No prompt content. United States
Resend (Plus Five Five, Inc.) Delivers one message, and only one: the email telling your administrators that browsers are waiting to be enrolled The work email addresses of those administrators, because they are the recipients — which also tells this provider your domain. The message itself carries a count of how many browsers are waiting and how long the oldest has waited. No employee names, no prompt content, no token mappings, no audit records, no account identifiers. Delivery metadata is held by the provider under its own terms. United States
Microsoft Corporation Business email, document storage and support correspondence Contact details, and anything personal included in correspondence, contracts or support requests. No prompt content, token maps or audit records. United States
Stripe, Inc. Payment processing and billing Billing contact name and email, subscription and invoice records. Card details go to Stripe directly and are never held by us. No prompt content. United States

Two things worth saying plainly

Two of these do not run the Service. Microsoft holds our email and documents; Stripe holds our billing. Personal data reaches both. They are listed for the same reason as the five that run the Service — a provider holding your correspondence or your invoices is handling your personal data as surely as one running our servers, and a list covering only the second would be a list chosen to look short.

Our payment processor is not purely acting on our instructions. Stripe uses payment data on its own account for fraud prevention and regulatory compliance, as its own terms describe. That is true of every payment processor and is rarely said out loud.

Their vendors

The chain does not end here.

Our second-tier detection provider operates no physical infrastructure of its own. It schedules work across a pool of cloud providers it publishes. Our configuration fixes the country that work runs in. It does not fix which provider runs it.

Each of the others engages its own vendors under its own terms.

Notice we receive, compared with notice we give

We promise our customers thirty days. Four of these providers give us less.

Provider Notice we receive
Microsoft Six months for customer data; thirty days for sub-processors supporting AI features
Amazon Web Services (from the date it appears above) Thirty days
Stripe Thirty days
Cloudflare Thirty days
WorkOS Fourteen days, by updating a page we are responsible for checking
Turso Ten days, by email — and silence for ten days counts as agreement
Modal Thirty days, but it may replace a provider urgently and tell us afterwards
Resend Fourteen days, in writing — and silence for fourteen days counts as agreement

So for a change that starts in one of those chains, we cannot give you the thirty days we promise. We would give you what we have, as soon as we have it. We would rather say that than promise a chain of notice we cannot enforce.

Not on this list

Software stores. Our extension is distributed through the Chrome Web Store and Microsoft Edge Add-ons. They host a package and report install counts. No prompt content, token map or audit record reaches either, and the relationship each has with someone installing the extension is its own, not one we direct. They matter to us — they gate every release — but they are not sub-processors and we would rather not pad this list with names that hold nothing.

Questions

[email protected]


Changelog

1.2 — 10 September 2026. Adds Resend (Plus Five Five, Inc.), which delivers the enrollment notice described in its row. It has been wired into the Service since that notice was built and appeared on no earlier version of this list; it was found on 9 September 2026 by reading our own code, which is not how a gap in this page should be found. Its location and notice period were taken from its data processing addendum rather than from what is usual, and the notice comparison above changes from three providers to four as a result.

1.1 — 4 September 2026. Added Stripe, Inc. (payment processing) on wiring billing. Added Microsoft Corporation (business email, document storage, support correspondence). Recorded cookieless analytics, on this website and in the dashboard, under Cloudflare’s existing entry. Added the notice comparison above.

1.0 — 4 September 2026. First published list.

Generated from docs/governance/legal/subprocessors.md. The source of truth is the governance register in the application repository, not this page.