Subprocessors

The complete list, with data classes and DPAs.

Garde1 uses a small number of vetted subprocessors to operate the platform. Each is U.S.-resident, each is under a written data-processing agreement, and each receives only the data classes documented below. This list is authoritative; the Privacy Policy and Customer Responsibility Matrix point here.

Change-notice policy. Material additions, removals, or changes to this list are posted on this page at least 30 days before they take effect, except where a faster change is required for security. Customers may object to a new subprocessor under the terms of their MSA.

Current subprocessors

Amazon Web Services, Inc.

Primary hosting (us-east-2): ECS Fargate compute, Aurora PostgreSQL, S3 object storage, DynamoDB audit log, KMS, Secrets Manager, ALB, CloudFront, WAFv2, SES (transactional email), SQS (background queues).

Data classesAll Customer Data, SPD, account metadata, audit logs, encrypted secrets.
Regionus-east-2 primary; us-east-1 for CloudFront / WAFv2 globals.
DPAAWS Customer Agreement + GDPR Data Processing Addendum executed.

Microsoft Corporation (Entra External ID)

OIDC identity provider for customer sign-in. SAML and SCIM federate into Entra; Garde1 itself speaks only OIDC.

Data classesUser principals (email, display name, group memberships), authentication events, federation tokens. No business data.
RegionUnited States (Microsoft Azure).
DPAMicrosoft Online Services Data Protection Addendum (DPA) executed.

Microsoft Corporation (Azure AI — OpenAI + Cohere Rerank)

LLM inference for policy prose generation, evidence evaluation, and the in-app assistant (Azure OpenAI). Retrieval relevance scoring before LLM evaluation (Cohere Rerank, hosted on Azure AI Foundry under the same Garde1 Azure tenancy). Zero-retention on both.

Data classesControl text, scope facts, evidence excerpts, questionnaire answers. See garde1.com/security/ai for the full list.
RegionUnited States (Azure, U.S. region).
DPAMicrosoft Online Services DPA + Azure OpenAI abuse-monitoring opt-out enabled. Prompts, completions, and rerank inputs are not retained; not used to train or fine-tune any model in the Azure AI catalog.

Stripe, Inc.

Payment processing and subscription billing.

Data classesBilling email, subscription tier, invoice history, last-four card digits. Garde1 does not store full card numbers or CVCs.
RegionUnited States.
DPAStripe Services Agreement + DPA executed.

Vercel, Inc.

Hosting for the public marketing site (garde1.com) and the status page (status.garde1.com).

Data classesPublic content only. No Customer Data. Marketing-form submissions are forwarded directly to SES and not stored on Vercel.
RegionUnited States.
DPAVercel Customer Terms + DPA executed.

What we don't use

For the record, Garde1's production stack does not include the following classes of subprocessor:

How to receive change notices

Subprocessor changes are posted on this page at least 30 days in advance. If you want email notifications to a compliance distribution list (not the sign-in account), use the form below with the distribution address you'd like to subscribe.

Request a DPA copy or change notices

Use the form below to request a copy of any executed subprocessor DPA or to subscribe a distribution list to change notices.

One business day · No sales drip