Active providers
- Amazon Web Services — production compute, network infrastructure, encrypted storage, and backup hosting in the United States.
- Mailgun — transactional email delivery, delivery events, bounces, complaints, and suppression processing.
- Stripe — subscription checkout, invoices, payment status, tax configuration, and customer billing portal.
- Cloudflare — Turnstile abuse prevention and, when configured, DNS, TLS, reverse proxy, and edge-security processing.
Self-hosted components
PostgreSQL, Redis, MinIO-compatible object storage, Nginx, and Playwright browser workers are operated within the selected production infrastructure and are not separate subprocessors merely because their software is used.
Changes and transfers
Material provider changes are posted to this register before or when processing begins, subject to urgent security or continuity needs. Provider contracts and lawful transfer mechanisms apply where required.
Operational implementation
- Assign an owner for implementing and reviewing the obligations described in Subprocessors.
- Map the policy to product settings, contracts, support procedures, data flows, records, and staff responsibilities.
- Keep the public language aligned with actual production behaviour and contracted commitments.
- Retain approval, effective-date, change-history, and customer-notice records.
Review triggers
- A material product, pricing, data-processing, security, vendor, or support change.
- A new jurisdiction, customer class, contract requirement, or regulatory obligation.
- An incident, complaint, audit finding, or operational exception that shows the published process is incomplete.
- A change that could create assigning work without scope, acceptance criteria, or a rollback path.
Turn subprocessors into an accountable record.
An implementation checklist showing where Subprocessors is reflected in product behaviour and business procedure.