Skip to main content

Subprocessors

Vendors that process data on NobleCloak's behalf. Split by what they can reach: platform subprocessors can touch customer content — the data the product processes. Corporate subprocessors touch only business-contact and commercial data.

Platform subprocessors

SubprocessorPurposeRegionData reached
Amazon Web ServicesEKS, RDS PostgreSQL, S3, CloudFront, Cognito, Secrets Manager, BedrockUSCustomer content
AnthropicFoundation models, accessed via Amazon Bedrock — AWS is the processor and Anthropic is a fourth party under AWS termsUSInference only; excluded from training by AWS Service Terms

Corporate subprocessors

SubprocessorPurposeRegionData reached
Google WorkspaceEmail, internal documentsUSCustomer correspondence; business contact data
PlanesCRMCustomer relationship managementUSBusiness contact data (minimal)
Intuit QuickBooksBilling, bookkeepingUSBilling contact, invoice records
GitHubSource control, CI/CD, package registryUSNone
Google Analytics 4Site analytics, IP anonymization enabledUSSite visitors only

PlanesCRM is built on a platform that uses Supabase for data storage, making Supabase a fourth party in that chain. We limit what customer data enters the CRM to business contact details.

Professional services

Our accounting and bookkeeping firm is under selection. Such firms typically act as independent controllers rather than processors, because they carry their own professional retention and reporting obligations. We list them here rather than omitting them, and will name the firm once engaged.

Payroll and HR

We do not yet have a payroll or HR platform subprocessor to disclose: payroll and HR administration do not touch customer data, so they are out of scope for this page. If that changes, any vendor that gains access to customer data would be added above.

Support

We do not yet operate a dedicated support desk platform. Support requests go directly to NobleCloak staff over email. If we adopt a support desk product, it will be disclosed here as a subprocessor at that time.

Integrations — not subprocessors

Systems you connect at your direction, under credentials you grant. Your data flows to your own systems, not to a vendor of ours. We request read-only scopes wherever the provider offers them.

IntegrationScopes requested
Google WorkspaceRead-only directory, token, and Marketplace enumeration
Microsoft Entra IDRead-only directory and service-principal enumeration
GitHubRead-only organization and installation metadata

Changes

Subprocessor additions and removals are published on this page, with the "Last updated" date below revised accordingly. We do not yet operate a separate trust center changelog, and we do not yet have a DPA or a contractual notice mechanism, so this page — not a change log or an advance notice — is the authoritative, current record. Check the date below rather than assuming you would be notified separately.

Last updated: 2026-07-27