Skip to main content

Overview

We use a carefully vetted set of third-party services to deliver the platform. All vendors are reviewed for security posture and contractually bound to protect your data under our Data Processing Agreement (DPA).

Controls

  • Principle of least privilege and data minimization applied across all integrations
  • Data shared only as necessary to provide the service
  • Security and privacy commitments included in all vendor agreements
  • DPA and Standard Contractual Clauses (SCCs) in place for EU and UK data transfers

Subprocessors

We maintain a full public list of approved subprocessors — including the company name, country, and processing task for each. View full subprocessors list →

Change Notification

We notify customers with an active DPA of any intended addition or replacement of subprocessors at least 10 business days in advance.