Sub-processors
Tested with: List as of 2026-09; changes announced with 30 days' notice
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure for cells, object storage for backups, KMS | Customer instance data (encrypted), backups | Region you choose; HIPAA buckets in a dedicated account |
| Stripe | Payments, invoicing, tax | Billing contact, payment method (never stored by us) | US, EU |
| Ory (Kratos) | Customer identity | Email, password hash, MFA factors | Same region as the control plane |
| Transactional email provider | Notifications, invites, alerts | Email address, notification content (no PHI) | US, EU |
| Cloud WAF / CDN provider | Public API and website protection | Request metadata, IP addresses | Global edge |
| Compliance automation platform | Evidence collection for SOC 2 | Staff and configuration metadata; no customer data | US |
Sub-processors with access to PHI-bearing infrastructure (AWS) have a BAA with us. We notify org admins by email at least 30 days before adding a sub-processor that would process customer data; you may object by contacting [email protected].