Proxaradocs
Trust Center/Reference

Subprocessor List

Third-party sub-processors engaged by Proxara for managed deployments, including the Sigstore Rekor transparency log that anchors the audit chain. Change notification process and current processor details.

Updated July 2026

Sub-processor List

Last updated: July 2026

This page lists the sub-processors engaged by Proxara to process personal data on behalf of Customers in Proxara-Managed Dedicated Account deployments, as described in the Data Processing Addendum. It also identifies, for clarity, the providers that touch Customer Data but are the Customer's own providers rather than Proxara sub-processors.


Applicability

This list applies only to Proxara-Managed Dedicated Account deployments, where Proxara acts as a data processor under Article 28 of the GDPR and equivalent laws. It covers both Proxara products: Proxara Connect (the hosted connector that joins the firm's AI assistant to Microsoft 365 through the firm's dedicated environment) and Endpoint Protection (the device agent). Where an entry applies to only one product, the entry says so.

For Customer-Managed deployments, Proxara is a software licensor and does not process personal data on the Customer's behalf. In those models, AWS is the Customer's own provider, not Proxara's sub-processor.


Primary Sub-processor

Amazon Web Services, Inc.

Entity: Amazon Web Services, Inc.

Purpose: Hosts the Customer's dedicated, single-tenant AWS account and provides all core infrastructure for the Service.

Processing location: The Customer's dedicated AWS account, in the Customer-selected region (US regions by default). Bedrock inference runs under a managed cross-region inference profile within US regions.

Data processed: All Customer Data handled by the Service, including prompts, responses, employee metadata, classification results, redacted event records, audit archives, and, for Proxara Connect, Microsoft 365 content retrieved on the employee's behalf together with the encrypted workflow state, stand-in vault, and grant tokens described below.

AWS services used within the Customer's environment:

ServiceRoleData involvement
Compute (ECS Fargate)Runs the classification API, the compliance console, and, for Proxara Connect, the connector runtimeProcesses prompts, responses, metadata, and, for Proxara Connect, retrieved Microsoft 365 content, in transit
Amazon RDS (PostgreSQL)Stores audit records and event dataStores flagged event content, classification results, and reviewer actions on a short-retention window (seven days by default), and the signed audit-chain envelopes, which persist as the compliance record and archive to S3. For Proxara Connect: encrypted workflow state, clear-view documents held under a short time-to-live, the stand-in vault (the reversible mappings between protected references and their stand-ins), and encrypted per-employee Microsoft 365 grant tokens, all encrypted under the Customer's KMS keys
Amazon ElastiCache (Redis)Session, queue, and cache layerHolds transient session, queue, and workflow-coordination data
Amazon S3Archives audit proofs for long-term retentionStores encrypted, immutable audit archives (7-year COMPLIANCE Object Lock)
AWS KMSManages encryption keys for the Customer's accountEncrypts data at rest, including the Proxara Connect stand-in vault; does not itself store Customer Data
AWS Secrets ManagerStores API credentials and service secretsHolds secrets in encrypted form; does not process Customer Data
Amazon BedrockAI inference for data classificationReceives prompt and response text, extracted file text, and, for Proxara Connect, retrieved Microsoft 365 content, for real-time classification and the semantic identification of protected references; also powers the built-in assistant and MCP triage reasoning. Does not store inputs or outputs. Runs inside the AWS-managed service under a cross-region US inference profile
Amazon TextractDocument text extraction (OCR)Receives document page images for text extraction; does not store them
Amazon CloudWatchOperational monitoring and log aggregationReceives operational metrics and structured, content-free logs
Amazon CloudFrontStatic asset delivery for the compliance consoleServes static files; does not store Customer Data

Note: AI inference on Bedrock runs entirely inside the AWS-managed service. The contractual relationship for that inference is with Amazon Web Services; no separate model-vendor relationship processes Customer Data for classification. Where the firm's employees use Proxara Connect, the firm's own AI assistant additionally receives the policy-approved, protected material described in the next section; that relationship is the firm's own.


The Firm's Own Providers (not Proxara sub-processors)

Two providers sit in the Proxara Connect data path under agreements the Customer holds directly. They are listed here so the data map is complete, in the same way the compliance-archive providers below are listed. Neither is engaged by Proxara, and neither is a Proxara sub-processor.

The Customer's AI assistant (for example, Anthropic Claude)

Proxara Connect works inside the AI assistant the firm already runs, under the firm's own agreement with that provider (for example, the firm's Claude workspace agreement with Anthropic). When an employee asks the assistant to work across the firm's systems, the assistant receives only what the firm's policy permits: the substance of the work with protected references replaced by consistent stand-ins, or, in the stricter Private Analysis mode, only a safe status while the full result stays inside the firm's environment. The mapping between a stand-in and the real value never leaves the firm's environment.

Two honest boundaries apply. First, the substance of a fact can itself be identifying in rare cases even with the identifiers replaced, which is why firm policy can keep specific classes of information inside the firm entirely. Second, anything an employee types or uploads directly into the assistant is already visible to that assistant; Proxara Connect governs the connected path, and Endpoint Protection is the product that extends coverage to typed text and uploads on managed devices.

Microsoft Corporation (the Customer's own Microsoft 365 tenant)

For Proxara Connect, Proxara retrieves mail, calendar, Teams messages, files, and tasks from the Customer's own Microsoft 365 tenant through the Microsoft Graph interface, on the Customer's instruction and under each signed-in employee's own delegated permissions: the connector can only ever see what the signed-in employee can already see. Microsoft processes that data as the Customer's own productivity-suite provider under the Customer's existing Microsoft agreement. Proxara's access is granted by the Customer's tenant administrator, appears in the Customer's own Entra admin center under Enterprise applications, and can be restricted or revoked by the Customer unilaterally.


Outbound and Supporting Sub-processors

Google LLC (Google Workspace)

Purpose: Outbound transactional and notification email (compliance digests, invitation emails, PDF leave-behinds). Proxara sends email through Google Workspace SMTP (smtp.gmail.com).

Processing location: United States.

Data processed: Recipient email addresses and the content of outbound notification messages.

Sigstore Rekor (on by default)

Entity: Linux Foundation Sigstore project.

Purpose: Public-internet transparency log for audit-chain anchoring. Anchoring runs by default: every five-minute Merkle batch root from the audit chain is submitted so that timestamps cannot be altered after the fact. If Rekor is unreachable, the batch anchor is still recorded locally and the chain continues.

Processing location: Public service operated by the Linux Foundation.

Data processed: A signed statement carrying the SHA-256 Merkle root hash and the anchor public key. No Customer Data, no prompts, no responses, no PII, and no device or tenant identifiers. The hash reveals nothing about the underlying events; it only allows independent verification that the batch existed at the recorded time.

Exa

Purpose: Used only when Proxara encounters an unrecognized MCP server and needs to research its capabilities (an Endpoint Protection surface). A generated metadata query (server or software name) is sent to Exa.

Processing location: United States.

Data processed: Server and software metadata only. No employee content and no personal data are transmitted.

Hugging Face and the Ollama registry

Entities: Hugging Face, Inc. (huggingface.co); Ollama (registry.ollama.ai).

Purpose: License classification for locally-installed AI models (an Endpoint Protection surface). A weekly job resolves the license class of model identifiers discovered in the firm's device inventory.

Processing location: United States.

Data processed: Model repository and tag identifiers only (software metadata, for example a model name and version discovered on a device). No employee content and no personal data are transmitted.


Optional Customer-Connected Channels (off by default)

The following processors are engaged only when the Customer explicitly connects the corresponding integration. These channels handle compliance notifications and read-only contextual metadata. The Customer connects its own accounts and, in many cases, already has an independent relationship with these providers. Customer-configured webhooks, where enabled, deliver alert payloads over HTTPS to endpoints the Customer chooses and controls.

IntegrationEntityPurposeData processed
SlackSlack Technologies, Inc.Delivers compliance notifications to the firm's Slack workspaceChannel and user identifiers; alert cards carrying severity, employee name, firm name, a short summary of the interaction, and console links. Alert cards do not carry the prompt text.
Microsoft Teams and Microsoft Graph (Bot Framework, Entra ID, Intune)Microsoft CorporationDelivers compliance notifications to Teams; signs reviewers into the console with the firm's Entra identity; reads managed-device inventory from Intune for deployment health; reads calendar metadata for board-meeting contextTeams channel identifiers; alert cards carrying employee name, reason, data types, and up to 500 characters of the prompt excerpt, which for events where sensitive values were found is original prompt text; read-only device inventory; read-only calendar event metadata. Note: this integration is a notification and metadata channel. It is separate from Proxara Connect's retrieval of Microsoft 365 content, which runs under each employee's own delegated permissions and is described above under The Firm's Own Providers. The Endpoint Protection device agent does not intercept Microsoft 365 or Teams network traffic; it passes through unmodified.
Google CalendarGoogle LLCReads calendar event metadata for board-meeting contextRead-only calendar event metadata

Sub-processors Proxara Does Not Use

For clarity:

  • OpenAI: Proxara holds an OpenAI API key registration but makes no API calls to OpenAI. OpenAI is not a sub-processor. ChatGPT appears as an intercepted destination under Endpoint Protection, and where a firm connects ChatGPT as its AI assistant, OpenAI stands in the same position as the firm's own AI assistant described above, under the firm's own agreement.
  • AWS SES: Proxara does not use Amazon Simple Email Service. Outbound email uses Google Workspace SMTP.
  • Third-party analytics for Customer Data: No analytics, error-telemetry, or data-enrichment vendors process Customer Data (for example, no Sentry, Datadog, or PostHog on the product side).
  • AI training services: No Customer Data is shared with or used to train any external model.

Compliance Archive Providers

The Service can be configured to forward interaction records to the firm's designated compliance archive provider (for example, Smarsh or Global Relay). Such a provider is engaged directly by the Customer under the Customer's own agreement and operates as the Customer's sub-processor, not Proxara's. Proxara does not select, contract with, or assume responsibility for the archive provider.


Change Notification

In accordance with the Data Processing Addendum, Proxara will provide Customers with at least 30 days' advance written notice before engaging a new sub-processor or replacing an existing one. The notice will identify the new sub-processor, describe its processing activities, and state its processing location.

Customers may object to a sub-processor change within 15 days of receiving notice. Objections will be handled through the dispute resolution process in the Data Processing Addendum.

Subprocessor change notifications are sent to the Customer contact email in the applicable Order Form. The "Last updated" date at the top of this page also reflects the date of the most recent change.


Contact

For questions about this sub-processor list:

Proxara, Inc.

28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108

Email: support@proxara.ai

Security inquiries: security@proxara.ai