Skip to main content

Subprocessors

The third-party services that process customer data

The 6 services AssetLab engages to deliver the platform, with the purpose, processing location, data accessed, and safeguards for each.

All legal documents
Version
1.6
Last updated
September 24, 2026

Scope

This is the published sub-processor list referenced by Section 8.7 of the Terms of Service, Section 5.1 of the Privacy Policy, and Annex 3 of the AssetLab Data Processing Agreement. Every sub-processor is bound by a written data processing agreement with obligations no less protective than those in our DPA, and AssetLab remains liable to customers for their acts and omissions.

Current subprocessors

Supabase, Inc.

Database hosting (PostgreSQL), object storage, Edge Functions

Processing location
Canada - AWS ca-central-1 (Montreal, QC) for the database, object storage and backups. Edge Functions execute in the AWS region nearest the caller unless the call specifies a region; from 21 September 2026 every AssetLab call specifies ca-central-1, enforced by a build check. Until 21 September 2026 calls originating in western Canada and outside Canada executed in the United States (us-west-2), processing the records those calls return; storage was unaffected throughout. Edge Functions do not connect to the database directly and reach the data tier over the same authenticated path as any other client. The Storage CDN is a global service with no in-region configuration. Supabase Realtime change streaming is not used (retired 17 September 2026).
Data accessed
All Customer Data (assets, work orders, vendors, custom fields, attachments, audit logs), plus a mirror of user identity (Clerk user ID, name, business email, role) used for application joins and audit logging.
Safeguards
DPA; SOC 2 Type II; Canadian data residency; AES-256 at rest

Clerk, Inc.

Authoritative identity store, authentication, MFA, passkeys, SSO/SAML, SCIM

Processing location
United States - hosted on Google Cloud Platform and Cloudflare
Data accessed
Full identity record: name, business email, MFA factors, session metadata, SSO configuration. No passwords: sign-in is by email one-time code, Microsoft OAuth or enterprise SSO only, so no password hashes are held for AssetLab users.
Safeguards
DPA; EU-U.S. Data Privacy Framework; SCCs; UK and Swiss addenda; SOC 2 Type II; TIA on file

Cloudflare, Inc.

Application delivery (single-page app via Workers and CDN), web application firewall, DNS, DDoS protection

Processing location
Global edge (US-headquartered)
Data accessed
Request and connection logs (IP address, timestamp, user agent, path); transit traffic decrypted at the edge for firewall inspection and not stored; administrative logs for AssetLab personnel; integration client registrations persisted in a globally replicated key-value store. The AssetLab MCP server runs as a Cloudflare Worker and executes at the Cloudflare location nearest the caller, which for AI-assistant callers is generally outside Canada. While a request is in flight it processes the asset records that request returns. Until 23 September 2026 the customer’s AssetLab API key was held for the duration of a connection (up to 24 hours) in plaintext in Cloudflare’s globally replicated key-value store; from 23 September 2026 it is held there only in encrypted form, under a key derived from the connection’s access token, which is itself never stored. No asset records or documents are stored at Cloudflare.
Safeguards
DPA; Data Privacy Framework; SCCs; UK and Swiss addenda; ISO/IEC 27001; ISO/IEC 27701; PCI DSS Level 1; SOC 2 Type II; TIA on file

Resend (Plus Five Five, Inc.)

Outbound transactional email delivery (work order, work request, preventive maintenance, contract and vendor notifications); inbound receiving for the optional email-to-work-request channel

Processing location
United States
Data accessed
Outbound: recipient address, organization name, record title and a deep link. Work request message notifications also carry up to the first 600 characters of the message body; vendor and preventive-maintenance share emails carry the message composed by the sending user. In-application bug reports are delivered through Resend with the reporter's name and email address and any files the reporter attaches. Inbound (optional): sender address and display name, subject, full message body.
Safeguards
DPA; EU-U.S. Data Privacy Framework and UK Extension; SCCs; UK and Swiss addenda; SOC 2 Type II (Resend Platform, Security criteria); TIA on file

Amazon Web Services, Inc.

Offsite encrypted backup of the database, storage buckets and identity export

Processing location
Canada - AWS ca-central-1 (Montreal, QC)
Data accessed
A complete copy of all Customer Data, held only as client-side encrypted archives. AssetLab encrypts every artefact before upload using a key pair whose private key AWS has never held; AWS stores ciphertext it has no means to decrypt.
Safeguards
DPA supplementing the AWS Customer Agreement; SCCs; regional no-transfer undertaking; object-lock immutability; SOC 2 Type II; TIA on file

Sentry (Functional Software, Inc.)

Application error monitoring and diagnostics

Processing location
United States and other countries
Data accessed
Opaque user and tenant identifiers, role, component and action tags, exception messages and stack traces. IP, user-agent and URL capture disabled; session replay off. No Customer records.
Safeguards
DPA executed 6 August 2026; Data Privacy Framework; SCCs; UK and Swiss addenda; sensitive data contractually prohibited; SOC 2 Type II; TIA on file

Retired subprocessors

Retained on this list for one revision so the change is legible. These services no longer process customer data.

GitHub, Inc. (a Microsoft company)

Scheduled execution of the nightly offsite backup job, 8 June 2026 to 2 September 2026. Retired 3 September 2026.

Processing location
GitHub-hosted build servers; region not selectable or disclosed by the provider
Data accessed
For the duration of each nightly run, a transient copy of the database, the private storage buckets and the weekly identity export existed on the build server before encryption for upload to AWS ca-central-1. No persistent storage. No longer processes Customer Data and holds no production credential.
Safeguards
GitHub DPA (incorporated in the GitHub Customer Agreement); Data Privacy Framework; SCCs; ISO/IEC 27001; SOC 2 Type II. Backup compute moved to AWS ca-central-1; a build check now fails if any job on GitHub infrastructure holds a credential able to read production data.

Changes to this list

We give as much advance notice of a new sub-processor, or of a material change to an existing relationship, as our own sub-processors allow, and in any event notify customers within five business days of becoming aware of the change, with a thirty-day objection window on reasonable data-protection grounds. See Terms of Service section 8.7 and the Data Processing Agreement section 6.3.