SUBPROCESSORS
Last Updated: 08/2026
These are the third parties that may process data on our behalf when you use the hosted service. It is the list we would give you in a security questionnaire, so it is the list we publish.
Infrastructure subprocessors
| Subprocessor | Purpose | Data it receives | Region | Status |
|---|---|---|---|---|
| Google Cloud Platform | Application hosting (Cloud Run), secret management, logging | All data processed by the hosted API, including security events | us-central1 | Required (hosted) |
| Supabase | Managed Postgres database and authentication | Account data, projects, API key hashes, security events | United States | Required (hosted) |
| Vercel | Hosting for this website and the dashboard | Web request metadata; no prompt content | Global edge | Required (hosted) |
| Stripe | Payment and subscription processing | Billing contact and payment details. We never see or store card numbers. | United States / global | Required for paid plans |
| WorkOS | Enterprise SSO (SAML/OIDC) and SCIM directory sync | Directory identity data: name, email, group membership | United States | Only if you enable SSO/SCIM |
| Google Workspace | Transactional email (verification, alerts) and support mailboxes | Email address and message content you send us | United States | Required (hosted) |
Customer-directed recipients
Data reaches these because of a configuration choice you make. We list them anyway: what matters to your risk assessment is where data goes, not who picked the destination.
| Subprocessor | Purpose | Data it receives | Region | Status |
|---|---|---|---|---|
| Your LLM provider | The provider you configure — OpenAI, Anthropic, Google, Cohere, AWS Bedrock or another | The prompts and completions you send through the proxy, forwarded after scanning | Provider's own | You choose it |
| Hosted ML inference | Runs the machine-learning detection tier | The text being scanned | Provider's own | Optional — replaceable with a model server you host |
What is not on this list
This website runs no third-party analytics. No Google Analytics, no advertising pixels, no session recording, no heatmaps. You can verify that in your browser’s network tab, which is the point of saying it here.
We also use no third-party error-tracking or session-replay service in the application, so your prompt content is not duplicated into an observability vendor as a side effect.
Self-hosted and air-gapped deployments
Most of this list is a consequence of us running the service. Deploy the engine yourself and the infrastructure subprocessors fall away: in an air-gapped deployment there is no outbound connection at all, and licensing is verified offline rather than by calling us.
If your risk assessment cannot accept a subprocessor above, that is the path — see deployment models.
Changes and notification
We review this list when infrastructure changes and at least annually. Customers under a DPA are notified of a new subprocessor before it begins processing, with the opportunity to object as the DPA sets out.
Questions about a specific subprocessor: security@promptguard.co.