These are the vendors that process customer personal data on our behalf. This list is the subprocessor annex of our Data Processing Agreement. Each vendor is bound by data protection terms at least as protective as the DPA, and each publishes its own security posture (linked from our Security page).
Change notice
We email account owners at least 30 days before a new subprocessor starts processing customer data, and we update this page and its "Last updated" date with every change. Objection rights are in the DPA, section 4.
Current subprocessors
| Vendor | Purpose | Data touched | Location |
|---|---|---|---|
| Clerk | Authentication | Email address, name, password hash, session data | United States |
| Cloudflare | Hosting, DNS, storage (R2), inbound report email | All service data in transit; raw report files at rest (7 days) | United States (global edge) |
| Neon | Postgres database hosting | Account data, domain names, parsed DMARC report data, audit log | United States |
| Anthropic | AI summaries (Claude API) | Domain names + parsed DMARC tags, under a Zero Data Retention agreement: inputs and outputs are not logged, stored, or used for training | United States |
| Resend | Outbound transactional email | Recipient email address, digest and alert content | United States |
| Stripe | Payment processing | Billing name, email, card details (Stripe only; we never see card data) | United States |
DNS lookups
To label sending sources, we resolve the server IP addresses that appear in DMARC aggregate reports to their network operator and country via DNS queries to Team Cymru's public IP-to-ASN service. Only the IP address travels in the query, never account data, and no customer account is identifiable from it.
What is not on this list
Integrations you connect yourself (for example Slack or Google Postmaster Tools) run under your own agreement with that provider; we only talk to them on your instruction. Advertising and analytics vendors are not on this list because we do not use any: analytics are first-party, as described in the Privacy Policy.
See also: Data Processing Agreement · Privacy Policy · Security.