Sub-Processor List
TruthVouch uses approved sub-processors (vendors) to provide our service. All sub-processors are bound by Data Processing Agreements ensuring adequate data protection.
Current Sub-Processors
Cloud Infrastructure
| Name | Purpose | Location | Data Types |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud compute, storage, databases, CDN | US, EU | All customer data |
| CloudFlare | DDoS protection, WAF, DNS | Global | Network traffic |
Authentication & Monitoring
| Name | Purpose | Location | Data Types |
|---|---|---|---|
| Auth0 | User authentication and SSO | US | User credentials (hashed) |
| DataDog | System monitoring and logging | US | System logs, metrics |
| Sentry | Error tracking and debugging | US | Application errors, crash reports |
| Prometheus | Metrics collection | Self-Hosted | System metrics |
| Grafana | Monitoring dashboards | Self-Hosted | System metrics |
Communications & Email
| Name | Purpose | Location | Data Types |
|---|---|---|---|
| SendGrid | Email delivery | US | Email addresses, message content |
| Slack (optional) | Alert notifications | US | Alert summaries |
| PagerDuty (optional) | Incident alerts | US | Alert summaries |
Payment Processing
| Name | Purpose | Location | Data Types |
|---|---|---|---|
| Stripe | Payment processing | US | Billing information (never stored by TruthVouch) |
Analytics (Optional)
| Name | Purpose | Location | Data Types |
|---|---|---|---|
| Google Analytics | Usage analytics | US | Anonymized usage data |
| Mixpanel | Product analytics | US | Feature usage, sessions |
Sub-Processor Agreements
All sub-processors are bound by:
- Data Processing Agreements (DPAs)
- Security requirements (encryption, access controls)
- Confidentiality obligations
- Limited use restrictions (only for service provision)
- Data subject rights support
Right to Object
Under GDPR Article 28(4), you have the right to object to sub-processors:
To Object:
- Email legal@truthvouch.com with your objection
- Specify which sub-processor(s) you object to
- Explain your concerns
We’ll work with you on alternatives or discuss the necessity of each sub-processor.
Sub-Processor Changes
If we add or replace sub-processors, we will:
- Notify you 30 days in advance
- Allow you to review the new sub-processor’s DPA
- Provide 15 days to object before implementation
Data Transfers
Sub-processors in the US are bound by Standard Contractual Clauses (included in DPA) for GDPR-compliant data transfers. EU-based sub-processors have no transfer restrictions.
Auditing Sub-Processors
We audit sub-processors annually through:
- Security questionnaires
- Annual SOC 2 reports (where available)
- Compliance certifications (ISO 27001, FedRAMP, etc.)
Questions About Sub-Processors
For questions about specific sub-processors or concerns about data handling:
Contact: legal@truthvouch.com
Subject: “[Sub-Processor] Data Processing Questions”
Last Updated: January 2024. Sub-processors updated monthly as needed.