ASCP sub-processors
Last updated: 2026-08-11.
A sub-processor is a third party that processes customer personal data on our behalf. This list is what ASCP actually runs, taken from the infrastructure definition rather than from an intention. Customers under a Data Processing Addendum are notified before a sub-processor is added — see the DPA, §7.
Current sub-processors
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | All hosting, storage, database, email delivery, logging and secrets management | Everything the platform holds: account records, uploaded evidence, audit records, operational logs, outbound email | US East (N. Virginia), us-east-1 |
| Okta, Inc. (Auth0) | Identity provider for browser sign-in | Email address, display name, authentication events, group membership | US (Auth0 tenant region) |
That is the complete list. There is no analytics provider, no error-tracking service, no session recording, no customer-support tool with data access, no marketing platform, and no payment processor — because billing is not implemented.
AWS services in use
Listed individually because "AWS" is not a meaningful disclosure on its own:
| Service | What it holds |
|---|---|
| ECS Fargate | The running application. No durable data |
| RDS for PostgreSQL (Multi-AZ) | Every database record, including account and audit data. Encrypted at rest with a customer-managed KMS key. Automated backups retained 14 days |
| S3 | Uploaded evidence files, encrypted with SSE-KMS, per-tenant key prefixes. Load-balancer access logs in a separate private bucket |
| SES | Outbound transactional email — invitations, notifications, alerts |
| KMS | Encryption keys for the database, S3 objects and log groups |
| Secrets Manager | Application credentials. No customer data |
| CloudWatch Logs and Metrics | Operational logs and metrics. Logs carry correlation identifiers and, on some paths, the source IP address of a request |
| SNS | Internal operational alerts to our own staff. No customer data |
| SQS, Lambda, EventBridge Scheduler | Background job dispatch. Job metadata only |
| ALB, VPC, ACM, Route 53, ECR | Network, certificates, DNS and container images. No customer data |
Not a sub-processor
| Party | Why not |
|---|---|
| Squarespace | Domain registrar and nothing else. Holds our own company contact details for the domain registration; processes no customer data. DNS is served by Route 53 |
| Cloudflare | Used only for temporary tunnels when demonstrating a local build to a reviewer. Never in the path of production traffic, and no customer data passes through it |
| ClamAV | Open-source software we run ourselves inside our own VPC. Evidence files are scanned on our own infrastructure and are not sent to any third party |
Where your data is, plainly
Everything is in the United States, in AWS us-east-1. There is no EU, UK or Brazilian deployment today.
This matters if you are subject to GDPR or UK GDPR: using ASCP involves a transfer of personal data to the United States. Our DPA includes the European Commission's Standard Contractual Clauses to cover that transfer, and AWS is certified under the EU–US Data Privacy Framework.
A caveat we would rather state than have you discover. The platform has a data-residency field on a customer record, and it is descriptive, not enforced — setting it to "EU" records a preference and does not move any data. If contractual data residency in a particular region is a requirement for you, tell us before signing: today the honest answer is that we cannot meet it, and changing the region means standing up a new deployment rather than migrating this one.
Changes to this list
We notify customers under a DPA before adding or replacing a sub-processor, with enough notice to object. The mechanism today is email to the account's designated contacts; there is no subscription feed for this page yet.
If you object to a new sub-processor on reasonable data-protection grounds, the DPA sets out what happens — §7.