Subprocessors

Every vendor with any access to GuardKin data.

Material changes to this list are announced 30 days in advance via email to firm customers. Annual reviews verify each subprocessor’s attestation remains current.

Subprocessors with vendor name, purpose, region, and attestation
VendorPurposeRegionAttestation
Amazon Web ServicesCompute, storage, KMSUSSOC 2 Type II
VercelWeb hosting, edge deliveryGlobal edgeSOC 2 Type II
CloudflareDNS, WAF, DDoSGlobal edgeSOC 2 Type II
NeonPostgres databaseUSSOC 2 Type II
ClerkAuthentication, MFAUSSOC 2 Type II
StripePaymentsUSSOC 1 Type II, SOC 2 Type II, PCI DSS L1
PersonaIdentity verification (executor attestation)USSOC 2 Type II
AnthropicHelper LLM (zero-retention)USSOC 2 Type II
AxiomAudit log hot storeUSSOC 2 Type II
DatadogAPM, monitoringUSSOC 2 Type II
SentryError tracking (data-scrubbing on)USSOC 2 Type II
DopplerSecrets managementUSSOC 2 Type II
ResendTransactional emailUSSOC 2 Type II
InngestAsync job orchestrationUSSOC 2 Type II
TwilioSMS for multi-channel verificationUSSOC 2 Type II
GitHubSource code, CI/CDUSSOC 2 Type II
Have I Been Pwned (HIBP)Password-breach screening (k-anonymity prefix lookup, fail-open) — first 5 hex chars of SHA-1 only; no credential material or PII leaves GuardKinGlobal (Cloudflare-fronted)No SOC 2 — k-anonymity is the compensating control
Subprocessors · GuardKin