Trust & Compliance

Sub-Processors

The third parties Canarie engages to deliver its compliance execution platform, the data they receive, where they receive it, and the safeguards in place to protect it.

Last updated: April 21, 2026

What is a Third-Party Sub-Processor?

A sub-processor is a vendor that Canarie uses to process data on behalf of our customers, who are the data controllers of that data. Canarie is the data processor; the sub-processors listed below act under our direction and are bound by written agreements that flow our customer commitments down to them.

Canarie's Process for Contracting with Sub-Processors

Canarie requires its sub-processors to satisfy obligations equivalent to those Canarie owes as a Data Processor under our Data Processing Addendum (DPA), including but not limited to the requirements to:

  • process personal data following the data controller's (i.e., the customer's) instructions, as communicated to the relevant sub-processor by Canarie;
  • use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable under applicable data protection laws;
  • maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest;
  • promptly inform Canarie about any security breach; and
  • cooperate with Canarie to address requests from data controllers, data subjects, or data protection authorities, as applicable.

Canarie owns or controls access to the infrastructure that hosts customer Restricted Data. Customer data is stored in United States regions only. Canarie also works with the service sub-processors listed below to provide specific platform functionality.

The following table describes the entities engaged in the processing or storage of customer data by Canarie acting as a Data Processor on behalf of its customers, the data controllers.

Canarie Authorized Sub-Processors

Vendors that may process customer data on Canarie's behalf.

Amazon Web Services, Inc.

Cloud Service Provider

Data Shared with Sub-Processor
  • Customer Restricted Data at rest and in transit
  • Application databases and encrypted backups
  • Object storage for evidence and uploaded files
  • Audit logs and platform telemetry
  • Secrets and encryption keys (via AWS KMS)
Location
United States (multiple regions)
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
AWS Compliance Center

Google LLC (Google Cloud Platform)

Cloud Service Provider

Data Shared with Sub-Processor
  • Customer Restricted Data at rest and in transit
  • Application databases (Cloud SQL) and encrypted backups
  • Object storage for evidence and uploaded files
  • Audit logs and platform telemetry
  • Secrets and encryption keys (via Cloud KMS)
Location
United States (Iowa, Oregon)
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
Google Cloud Trust Center

Cloudflare, Inc.

Content Delivery Network, DNS, TLS termination, WAF, DDoS protection

Data Shared with Sub-Processor
  • Encrypted application traffic (TLS 1.2+)
  • Request metadata and IP addresses
  • WAF and bot-management telemetry
Location
Global edge; data at rest in the United States
Transfer Mechanism
Standard Contractual Clauses (SCCs) for transit through non-US edge locations
Additional Safeguards
Cloudflare Trust Hub

Vercel Inc.

Marketing website hosting (canarie.ai)

Data Shared with Sub-Processor
  • Marketing site request logs
  • No customer Restricted Data is processed by this sub-processor
Location
United States
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
Vercel Trust Center

Clerk, Inc.

Authentication, SSO, MFA, and session management

Data Shared with Sub-Processor
  • Email address and name
  • Authentication identifiers and MFA factors
  • Session tokens and sign-in metadata
Location
United States
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
Clerk Trust Center

Stripe, Inc.

Payment processing for platform billing

Data Shared with Sub-Processor
  • Billing contact name and email
  • Payment method details (tokenized)
  • Transaction history and invoice metadata
Location
United States
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
Stripe Privacy Center

LogRocket, Inc.

Frontend session replay, product telemetry, and error tracking

Data Shared with Sub-Processor
  • Masked user inputs and scrubbed DOM snapshots
  • Error stack traces and browser metadata
  • Authenticated user identifier (email)
Location
United States
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
LogRocket Trust

Google LLC (Google Analytics)

Marketing website analytics (canarie.ai)

Data Shared with Sub-Processor
  • Anonymized IP address
  • Page-view events and referrer
  • Device and browser metadata
  • No customer Restricted Data is processed by this sub-processor
Location
United States
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
Google Privacy & Terms

OpenAI, L.L.C.

Large language model inference for AI-assisted features

Data Shared with Sub-Processor
  • Customer prompts and responses when AI features are invoked
  • Contextual evidence and policy excerpts provided at inference time
  • Inputs and outputs contractually excluded from model training
Location
United States
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
OpenAI Trust Portal

Anthropic, PBC

Large language model inference for AI-assisted features

Data Shared with Sub-Processor
  • Customer prompts and responses when AI features are invoked
  • Contextual evidence and policy excerpts provided at inference time
  • Inputs and outputs contractually excluded from model training
Location
United States
Transfer Mechanism
Domestic processing — United States
Additional Safeguards
Anthropic Trust Center

Corporate Tools

Internal tools Canarie uses to build, ship, and operate the platform. These are listed for transparency. They are not sub-processors of customer data — customer Restricted Data is not permitted in these systems by policy.

Google Workspace (Google LLC)

Business email, document collaboration, calendar, corporate SSO

Scope
Internal corporate productivity. Customer Restricted Data is not permitted in this system.
Location
United States
Additional Safeguards
Google Cloud Trust Center

GitHub, Inc.

Source code management, CI/CD, static analysis, secret scanning

Scope
Internal software development lifecycle. Customer Restricted Data is not permitted in this system.
Location
United States
Additional Safeguards
GitHub Trust Center

Slack (Salesforce, Inc.)

Internal team communication

Scope
Internal collaboration. Customer Restricted Data is not permitted in this system.
Location
United States
Additional Safeguards
Slack Trust

Linear, Inc.

Product and engineering issue tracking

Scope
Internal project and issue tracking. Customer Restricted Data is not permitted in this system.
Location
United States
Additional Safeguards
Linear Security

Updates

As our business grows and evolves, the sub-processors we use may also change. Before adding a new sub-processor that will process customer Restricted Data, Canarie will provide the owner of the customer's account with advance notice. Customers may object to a new sub-processor during the notice period; if the objection cannot be resolved, the customer may terminate the affected service in accordance with their order form.

Updates to this list that do not involve a new sub-processor (for example, scope clarifications or certification updates) will be reflected here with a revised "Last updated" date.

Subscribe to sub-processor updates

Get notified by email when this list changes. We use these addresses only to send sub-processor change notices.

You can also email hello@canarie.ai to subscribe or unsubscribe.

Contact

For questions about this list, to request a copy of our sub-processor agreement summaries, or to subscribe to change notifications:

Canarie AI

Email: hello@canarie.ai

Need our Trust & Security package?

We can share SOC 2 reports, security questionnaires, and DPAs under NDA. Reach out and we'll get them over.