Skip to main content

Subprocessors

The third-party services that process customer data

The 6 services AssetLab engages to deliver the platform, with the purpose, processing location, data accessed, and safeguards for each.

All legal documents
Version
1.2
Last updated
August 9, 2026

Scope

This is the published sub-processor list referenced by Section 8.7 of the Terms of Service, Section 5.1 of the Privacy Policy, and Annex 3 of the AssetLab Data Processing Agreement. Every sub-processor is bound by a written data processing agreement with obligations no less protective than those in our DPA, and AssetLab remains liable to customers for their acts and omissions.

Current subprocessors

Supabase, Inc.

Database hosting (PostgreSQL), object storage, Edge Functions

Processing location
Canada - AWS ca-central-1 (Montreal, QC)
Data accessed
All Customer Data, plus a mirror of user identity (Clerk user ID, name, business email, role) used for application joins and audit logging
Safeguards
DPA; SCCs; SOC 2 Type II; Canadian data residency; AES-256 at rest

Clerk, Inc.

Authoritative identity store, authentication, MFA, passkeys, SSO/SAML, SCIM

Processing location
United States
Data accessed
Full identity record: name, business email, password hashes, MFA factors, session metadata, SSO configuration
Safeguards
DPA; EU-U.S. Data Privacy Framework; SCCs; UK and Swiss addenda; SOC 2 Type II; TIA on file

Cloudflare, Inc.

Application delivery, web application firewall, DNS, DDoS protection

Processing location
Global edge (US-headquartered)
Data accessed
Request and connection logs; transit traffic decrypted at the edge for firewall inspection and not stored. No asset records, documents or credentials.
Safeguards
DPA; Data Privacy Framework; SCCs; UK and Swiss addenda; ISO/IEC 27001; ISO/IEC 27701; PCI DSS Level 1; SOC 2 Type II; TIA on file

Resend (Plus Five Five, Inc.)

Outbound transactional email; inbound receiving for the optional email-to-work-request channel

Processing location
United States
Data accessed
Outbound: recipient address, organization name, record title and a deep link - never record content or attachments. Inbound (optional): sender address and display name, subject, full message body.
Safeguards
DPA; EU-U.S. Data Privacy Framework and UK Extension; SCCs; UK and Swiss addenda; SOC 2 Type II (Resend Platform, Security criteria); TIA on file

Amazon Web Services, Inc.

Offsite encrypted backup of the database, storage buckets and identity export

Processing location
Canada - AWS ca-central-1 (Montreal, QC)
Data accessed
A complete copy of all Customer Data, held only as client-side encrypted archives. AWS stores ciphertext it has no means to decrypt.
Safeguards
DPA supplementing the AWS Customer Agreement; SCCs; regional no-transfer undertaking; object-lock immutability; SOC 2 Type II; TIA on file

Sentry (Functional Software, Inc.)

Application error monitoring and diagnostics

Processing location
United States
Data accessed
Opaque user and tenant identifiers, role, component and action tags, exception messages and stack traces. IP, user-agent and URL capture disabled; session replay off. No Customer records.
Safeguards
DPA executed 6 August 2026; Data Privacy Framework; SCCs; UK and Swiss addenda; sensitive data contractually prohibited; SOC 2 Type II; TIA on file

Changes to this list

We give at least thirty days advance notice before engaging a new sub-processor or materially changing an existing relationship, with a thirty-day objection window on reasonable data-protection grounds. See Terms of Service section 8.7 and the Data Processing Agreement section 6.3.