Sub-processors.
A sub-processor is any third party that processes personal data on CertiFlow PLUS’s behalf in the course of delivering the service. We disclose every one of them, what they do, where they do it, and what categories of data they touch. This list is part of the Data Processing Agreement annex and is the binding source of truth.
Last updated 2026-06-08
01 · Sub-processors that hold customer evidence
Ciphertext only. None of them can read your evidence.
These sub-processors hold ciphertext only. A subpoena to any of them returns ciphertext + plaintext metadata only — the decryption key never touches their infrastructure.
| Sub-processor | Role | Data categories | Location |
|---|---|---|---|
| Supabase Inc. | Application database + object storage + authentication | Ciphertext evidence blobs, encrypted DEKs, encrypted Vault Keys, plaintext metadata (control IDs, framework names, timestamps, audit chain), profile rows | EU — Frankfurt (eu-central-1) |
| Vercel Inc. | Web application hosting + edge CDN + edge WAF | HTTP request metadata, session cookies, no customer evidence | US (entity); edge globally; data residency varies by route |
02 · Volatile plaintext — in-flight only, no persistence
Two participants see plaintext briefly during an active session.
Plaintext processing happens only when you are actively using the product and only inside customer-initiated request scopes. Volatile memory only, no persistence to durable storage.
| Sub-processor | Role | Data categories | Location |
|---|---|---|---|
| Anthropic, PBC | AI inference for the Advisor, Analyzer, Scan, Draft Policy, Draft Evidence, Red Team, and Document Review surfaces. Called only when a user submits explicit request text (a question, URL, or snippet). | Prompt content (plaintext) supplied by the user at request time; response text returned to the user's tenant. Prompt content is not retained by CertiFlow PLUS after the response is delivered. Anthropic's data-handling terms apply to the inference call itself (see anthropic.com/legal/data-processing). | US-based entity, EU region-preferred inference where available. Volatile-plaintext-in-flight only — CertiFlow PLUS does not persist the prompt content. |
| Google LLC (Gemini API) | Independent verification of AI-drafted compliance documents. Guided Compile drafts a document with Anthropic, then submits it to Google's Gemini model for a second, adversarial review before the customer sees it. Two models from different vendors have uncorrelated failure modes, so a claim invented by one is materially more likely to be caught by the other. Called only during a Guided Compile run. | The drafted document text, the customer's declared company facts, and the control clauses being assessed — all plaintext, all supplied at request time. Nothing from the zero-knowledge evidence vault is ever sent: encrypted evidence is not readable by CertiFlow PLUS and therefore cannot be forwarded to any model. Prompt content is not retained by CertiFlow PLUS after the review returns. | US-based entity. Volatile-plaintext-in-flight only — CertiFlow PLUS does not persist the prompt content. Google's API terms apply to the inference call itself (see ai.google.dev/gemini-api/terms). |
| Customer's own browser | Argon2id key derivation, Vault Key unwrap, DEK unwrap, file decrypt for view, plaintext rendering | Master Password (typed by customer), Account Key (derived in browser), file plaintext during active view | Customer device — sessionStorage only, purged on tab close or 30-min idle |
03 · Infrastructure sub-processors that never see evidence
Payments, email, CDN, source control.
These sub-processors are involved in running the company but do not handle customer evidence in any form — neither plaintext nor ciphertext.
| Sub-processor | Role | Data categories | Location |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing — subscription management, invoicing | Billing data: name, email, billing address, card-tokenised reference (never raw PAN at DCS) | Ireland |
| Stackmail SARL | Transactional email — OTPs, billing receipts, notifications | Email address; minimal body content | Switzerland |
| Cloudflare, Inc. | CDN, DNS, DDoS protection, WAF for the marketing site | IP addresses (transient request log), browser fingerprint (transient) | Edge locations worldwide; logs in Ireland |
| GitHub, Inc. | Source-code hosting and CI/CD execution (engineering data only) | DCS contributor identities, commit metadata. NO customer personal data. | United States |
Why this list is shorter than incumbents
Vanta, Drata, and Sprinto’s sub-processor lists are 25 to 40 entries long because they integrate with customer SaaS tools (Okta, Slack, Microsoft, Google, AWS, GitHub, …) and pull plaintext evidence into their own systems for indexing and continuous monitoring.
CertiFlow PLUS’s sub-processor list is intentionally short. We never integrate directly with customer-side SaaS tools because doing so would require us to hold customer evidence in plaintext — which would break our zero-knowledge guarantee. The integration sources you use to gather evidence are your sub-processors, not ours; the relationship between you and Okta is yours, not ours.
Change notice protocol
- 30 days advance notice to all active customers before any addition, removal, or material scope change. Notice goes to the contracted notice address (typically legal@your-domain) and to the in-product notification feed for tenant admins.
- 15 days to object from notice on reasonable grounds. If unable to reach resolution, you may terminate the affected service without penalty.
- No silent additions. Every new sub-processor is documented here and dated, including the historical record below.
Removed sub-processors (historical record)
Contact
Sub-processor enquiries, DPA requests, and supervisory-authority correspondence: shaun@directcs.net.
See also: our Data Processing Agreement, Privacy notice, and Security page.