Trust Center

Subprocessors

Every third party that processes customer data, what they do, and where they do it.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Every third party that processes customer data, what they do, and where they do it.

Why this list exists

Under HIPAA, your compliance exposure does not stop at your vendor — it runs through your vendor’s vendors. If SuperHIPAA is your business associate, our subcontractors that touch ePHI are subcontractor business associates, and you are entitled to know who they are. Plenty of vendors make you file a support ticket to find out. We publish the list, keep it current, and notify you before it changes.

Current subprocessors

The authoritative list, with each provider’s function, data categories handled, and processing location:

ProviderPurposeData categoriesLocationHandles ePHI / BAA
Amazon Web Services (AWS)Hosting and infrastructureCustomer workspace content, account data, logs, backupsUnited States (us-east-1 primary, us-west-2 backup)Yes — BAA signed
CloudflareCDN, DNS, and edge securityTraffic metadata; customer data in transitUnited StatesTransit only — BAA signed
Google WorkspaceEmail and internal documentsBusiness contact and support correspondenceUnited StatesNo — ePHI is not handled by email
HubSpotCRM and marketingBusiness contact data from forms and salesUnited StatesNo
SlackInternal communicationsBusiness contact data in operational notificationsUnited StatesNo
StripePayments and billingBilling contact and payment dataUnited StatesNo

Two reading notes. First, “processes customer data” is interpreted broadly here: if a provider could plausibly touch your data in the course of its function, it is on the list, even if the touch is incidental. Second, not every provider on the list handles ePHI — the table marks which ones do, because that distinction determines whether a downstream BAA is required or merely prudent.

How a vendor gets on this list

No subprocessor is added casually. Before any third party touches customer data, it goes through a documented review:

  • Security assessment — we review the provider’s audit reports, security documentation, and breach history before signing anything.
  • Contractual flow-down — providers handling ePHI sign a BAA with us; all providers handling customer data sign terms at least as protective as our commitments to you. HIPAA’s chain-of-trust requirement is not optional and we do not treat it as negotiable.
  • Minimum necessary scoping — each provider gets access to the categories of data its function requires, not a general feed.
  • Ongoing review — subprocessors are reassessed on a defined cadence (annually) and when something material changes, such as an acquisition or a disclosed incident.

Change notification

We give notice before adding or materially changing a subprocessor:

  • Notice period: at least 30 days before a new subprocessor processes customer data.
  • Delivery: email to your registered security contact, plus an update to this page. Subscribe once and you will not need to re-check this page on a schedule.
  • Objection: if your agreement includes an objection right and a new subprocessor is unacceptable to you, the agreement sets out the process and remedies. We would rather hear the objection during the notice window than at renewal.

Removals and role reductions are reflected on this page as they happen, with a change log maintained at the foot of this page so you can see history rather than only the current state.

What we commit to

  • We give at least 30 days’ notice before a new subprocessor processes customer data.
  • Every subprocessor that handles ePHI signs a BAA with us before it handles anything.
  • Every subprocessor is security-assessed before onboarding and reassessed annually, and after any material change such as an acquisition or a disclosed incident.

If a subprocessor has an incident

An incident at a subprocessor affecting customer data is treated as an incident of ours. Our contracts with subprocessors require prompt notification to us; our BAA with you defines what we must tell you and when. We do not launder responsibility through the supply chain — if your data was affected, you hear it from us, with what we know and what we are doing, not from a third party’s press release.

Documentation available on request

  • SOC 2 Type II report (under NDA)
  • Penetration test summary
  • Business Associate Agreement
  • Architecture and data flow diagram
  • Completed CAIQ / SIG Lite

Vendor-risk teams often want our subprocessor assessments summarised rather than just the list; that summary is part of the full security package, requestable through the form on this page.

Questions

Security questions go to [email protected] and get a human answer within one business day. If you spot a provider you believe should be on this list and is not, tell us — that is exactly the kind of external check a public list is for.

Questions

Will you sign our BAA instead of yours?

Usually yes. Send it over — we redline rather than refuse.

Can we get your SOC 2 report?

Yes, under NDA. Request it through the trust package form on this page.

Where is our data stored?

Region is selectable at provisioning. See the Infrastructure page for the current list.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo