Trust & Compliance
Sub-Processors
The third parties Canarie engages to deliver its compliance execution platform, the data they receive, where they receive it, and the safeguards in place to protect it.
Last updated: April 21, 2026
What is a Third-Party Sub-Processor?
A sub-processor is a vendor that Canarie uses to process data on behalf of our customers, who are the data controllers of that data. Canarie is the data processor; the sub-processors listed below act under our direction and are bound by written agreements that flow our customer commitments down to them.
Canarie's Process for Contracting with Sub-Processors
Canarie requires its sub-processors to satisfy obligations equivalent to those Canarie owes as a Data Processor under our Data Processing Addendum (DPA), including but not limited to the requirements to:
- process personal data following the data controller's (i.e., the customer's) instructions, as communicated to the relevant sub-processor by Canarie;
- use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable under applicable data protection laws;
- maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest;
- promptly inform Canarie about any security breach; and
- cooperate with Canarie to address requests from data controllers, data subjects, or data protection authorities, as applicable.
Canarie owns or controls access to the infrastructure that hosts customer Restricted Data. Customer data is stored in United States regions only. Canarie also works with the service sub-processors listed below to provide specific platform functionality.
The following table describes the entities engaged in the processing or storage of customer data by Canarie acting as a Data Processor on behalf of its customers, the data controllers.
Canarie Authorized Sub-Processors
Vendors that may process customer data on Canarie's behalf.
| Name | Purpose | Data Shared with Sub-Processor | Location | Transfer Mechanism | Additional Safeguards |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. | Cloud Service Provider |
| United States (multiple regions) | Domestic processing — United States | AWS Compliance Center |
| Google LLC (Google Cloud Platform) | Cloud Service Provider |
| United States (Iowa, Oregon) | Domestic processing — United States | Google Cloud Trust Center |
| Cloudflare, Inc. | Content Delivery Network, DNS, TLS termination, WAF, DDoS protection |
| Global edge; data at rest in the United States | Standard Contractual Clauses (SCCs) for transit through non-US edge locations | Cloudflare Trust Hub |
| Vercel Inc. | Marketing website hosting (canarie.ai) |
| United States | Domestic processing — United States | Vercel Trust Center |
| Clerk, Inc. | Authentication, SSO, MFA, and session management |
| United States | Domestic processing — United States | Clerk Trust Center |
| Stripe, Inc. | Payment processing for platform billing |
| United States | Domestic processing — United States | Stripe Privacy Center |
| LogRocket, Inc. | Frontend session replay, product telemetry, and error tracking |
| United States | Domestic processing — United States | LogRocket Trust |
| Google LLC (Google Analytics) | Marketing website analytics (canarie.ai) |
| United States | Domestic processing — United States | Google Privacy & Terms |
| OpenAI, L.L.C. | Large language model inference for AI-assisted features |
| United States | Domestic processing — United States | OpenAI Trust Portal |
| Anthropic, PBC | Large language model inference for AI-assisted features |
| United States | Domestic processing — United States | Anthropic Trust Center |
Amazon Web Services, Inc.
Cloud Service Provider
- Data Shared with Sub-Processor
- Customer Restricted Data at rest and in transit
- Application databases and encrypted backups
- Object storage for evidence and uploaded files
- Audit logs and platform telemetry
- Secrets and encryption keys (via AWS KMS)
- Location
- United States (multiple regions)
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- AWS Compliance Center
Google LLC (Google Cloud Platform)
Cloud Service Provider
- Data Shared with Sub-Processor
- Customer Restricted Data at rest and in transit
- Application databases (Cloud SQL) and encrypted backups
- Object storage for evidence and uploaded files
- Audit logs and platform telemetry
- Secrets and encryption keys (via Cloud KMS)
- Location
- United States (Iowa, Oregon)
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- Google Cloud Trust Center
Cloudflare, Inc.
Content Delivery Network, DNS, TLS termination, WAF, DDoS protection
- Data Shared with Sub-Processor
- Encrypted application traffic (TLS 1.2+)
- Request metadata and IP addresses
- WAF and bot-management telemetry
- Location
- Global edge; data at rest in the United States
- Transfer Mechanism
- Standard Contractual Clauses (SCCs) for transit through non-US edge locations
- Additional Safeguards
- Cloudflare Trust Hub
Vercel Inc.
Marketing website hosting (canarie.ai)
- Data Shared with Sub-Processor
- Marketing site request logs
- No customer Restricted Data is processed by this sub-processor
- Location
- United States
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- Vercel Trust Center
Clerk, Inc.
Authentication, SSO, MFA, and session management
- Data Shared with Sub-Processor
- Email address and name
- Authentication identifiers and MFA factors
- Session tokens and sign-in metadata
- Location
- United States
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- Clerk Trust Center
Stripe, Inc.
Payment processing for platform billing
- Data Shared with Sub-Processor
- Billing contact name and email
- Payment method details (tokenized)
- Transaction history and invoice metadata
- Location
- United States
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- Stripe Privacy Center
LogRocket, Inc.
Frontend session replay, product telemetry, and error tracking
- Data Shared with Sub-Processor
- Masked user inputs and scrubbed DOM snapshots
- Error stack traces and browser metadata
- Authenticated user identifier (email)
- Location
- United States
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- LogRocket Trust
Google LLC (Google Analytics)
Marketing website analytics (canarie.ai)
- Data Shared with Sub-Processor
- Anonymized IP address
- Page-view events and referrer
- Device and browser metadata
- No customer Restricted Data is processed by this sub-processor
- Location
- United States
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- Google Privacy & Terms
OpenAI, L.L.C.
Large language model inference for AI-assisted features
- Data Shared with Sub-Processor
- Customer prompts and responses when AI features are invoked
- Contextual evidence and policy excerpts provided at inference time
- Inputs and outputs contractually excluded from model training
- Location
- United States
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- OpenAI Trust Portal
Anthropic, PBC
Large language model inference for AI-assisted features
- Data Shared with Sub-Processor
- Customer prompts and responses when AI features are invoked
- Contextual evidence and policy excerpts provided at inference time
- Inputs and outputs contractually excluded from model training
- Location
- United States
- Transfer Mechanism
- Domestic processing — United States
- Additional Safeguards
- Anthropic Trust Center
Corporate Tools
Internal tools Canarie uses to build, ship, and operate the platform. These are listed for transparency. They are not sub-processors of customer data — customer Restricted Data is not permitted in these systems by policy.
| Name | Purpose | Scope | Location | Additional Safeguards |
|---|---|---|---|---|
| Google Workspace (Google LLC) | Business email, document collaboration, calendar, corporate SSO | Internal corporate productivity. Customer Restricted Data is not permitted in this system. | United States | Google Cloud Trust Center |
| GitHub, Inc. | Source code management, CI/CD, static analysis, secret scanning | Internal software development lifecycle. Customer Restricted Data is not permitted in this system. | United States | GitHub Trust Center |
| Slack (Salesforce, Inc.) | Internal team communication | Internal collaboration. Customer Restricted Data is not permitted in this system. | United States | Slack Trust |
| Linear, Inc. | Product and engineering issue tracking | Internal project and issue tracking. Customer Restricted Data is not permitted in this system. | United States | Linear Security |
Google Workspace (Google LLC)
Business email, document collaboration, calendar, corporate SSO
- Scope
- Internal corporate productivity. Customer Restricted Data is not permitted in this system.
- Location
- United States
- Additional Safeguards
- Google Cloud Trust Center
GitHub, Inc.
Source code management, CI/CD, static analysis, secret scanning
- Scope
- Internal software development lifecycle. Customer Restricted Data is not permitted in this system.
- Location
- United States
- Additional Safeguards
- GitHub Trust Center
Slack (Salesforce, Inc.)
Internal team communication
- Scope
- Internal collaboration. Customer Restricted Data is not permitted in this system.
- Location
- United States
- Additional Safeguards
- Slack Trust
Linear, Inc.
Product and engineering issue tracking
- Scope
- Internal project and issue tracking. Customer Restricted Data is not permitted in this system.
- Location
- United States
- Additional Safeguards
- Linear Security
Updates
As our business grows and evolves, the sub-processors we use may also change. Before adding a new sub-processor that will process customer Restricted Data, Canarie will provide the owner of the customer's account with advance notice. Customers may object to a new sub-processor during the notice period; if the objection cannot be resolved, the customer may terminate the affected service in accordance with their order form.
Updates to this list that do not involve a new sub-processor (for example, scope clarifications or certification updates) will be reflected here with a revised "Last updated" date.
Subscribe to sub-processor updates
Get notified by email when this list changes. We use these addresses only to send sub-processor change notices.
You can also email hello@canarie.ai to subscribe or unsubscribe.
Contact
For questions about this list, to request a copy of our sub-processor agreement summaries, or to subscribe to change notifications:
Canarie AI
Email: hello@canarie.ai
Need our Trust & Security package?
We can share SOC 2 reports, security questionnaires, and DPAs under NDA. Reach out and we'll get them over.