Third-party sub-processors engaged by Proxara for managed deployments, including the Sigstore Rekor transparency log that anchors the audit chain. Change notification process and current processor details.
Updated July 2026
Last updated: July 2026
This page lists the sub-processors engaged by Proxara to process personal data on behalf of Customers in Proxara-Managed Dedicated Account deployments, as described in the Data Processing Addendum. It also identifies, for clarity, the providers that touch Customer Data but are the Customer's own providers rather than Proxara sub-processors.
This list applies only to Proxara-Managed Dedicated Account deployments, where Proxara acts as a data processor under Article 28 of the GDPR and equivalent laws. It covers both Proxara products: Proxara Connect, which joins the firm's AI assistant to the firm's own systems (Karbon, Microsoft 365 and SharePoint, selected tax systems, document stores, and a CRM where the firm runs one) through the firm's dedicated environment, and Endpoint Protection, the device agent. Where an entry applies to only one product, the entry says so.
For Customer-Managed deployments, Proxara is a software licensor and does not process personal data on the Customer's behalf. In those models, AWS is the Customer's own provider, not Proxara's sub-processor.
Entity: Amazon Web Services, Inc.
Purpose: Hosts the Customer's dedicated, single-tenant AWS account and provides all core infrastructure for the Service.
Processing location: The Customer's dedicated AWS account, in the Customer-selected region (US regions by default). For Endpoint Protection, Bedrock inference runs under a managed cross-region inference profile within US regions.
Data processed: All Customer Data handled by the Service, including prompts, responses, employee metadata, classification results, redacted event records, audit archives, and, for Proxara Connect, content retrieved from the Customer's connected systems on the employee's behalf together with the encrypted workflow state, stand-in vault, and grant tokens described below.
AWS services used within the Customer's environment:
| Service | Role | Data involvement |
|---|---|---|
| Compute (ECS Fargate) | Runs the classification API, the compliance console, and, for Proxara Connect, the connector runtime | Processes prompts, responses, metadata, and, for Proxara Connect, retrieved source content, in transit |
| Amazon RDS (PostgreSQL) | Stores audit records and event data | Stores flagged event content, classification results, and reviewer actions on a short-retention window (seven days by default), and the signed audit-chain envelopes, which persist as the compliance record and archive to S3. For Proxara Connect: encrypted workflow state, the clear artifacts the first-party workspace renders, the stand-in vault (the reversible mappings between protected references and their stand-ins), and encrypted per-employee grant tokens, all encrypted under the Customer's KMS keys |
| Amazon ElastiCache (Redis) | Session, queue, and cache layer | Holds transient session, queue, and workflow-coordination data |
| Amazon S3 | Archives audit proofs for long-term retention | Stores encrypted, immutable audit archives (7-year COMPLIANCE Object Lock) |
| AWS KMS | Manages encryption keys for the Customer's account | Encrypts data at rest, including the Proxara Connect stand-in vault; does not itself store Customer Data |
| AWS Secrets Manager | Stores API credentials and service secrets | Holds secrets in encrypted form; does not process Customer Data |
| Amazon Bedrock (Endpoint Protection) | AI inference for data classification | Receives prompt and response text and extracted file text for real-time classification; also powers the built-in assistant and MCP triage reasoning. Does not store inputs or outputs. Runs inside the AWS-managed service under a cross-region US inference profile |
| Amazon Textract (Endpoint Protection) | Document text extraction (OCR) | Receives document page images for text extraction; does not store them |
| Amazon CloudWatch | Operational monitoring and log aggregation | Receives operational metrics and structured, content-free logs |
| Amazon CloudFront | Static asset delivery for the compliance console | Serves static files; does not store Customer Data |
Bedrock is the Endpoint Protection classification engine. That inference runs inside the AWS-managed service, and the contractual relationship for it is with Amazon Web Services.
Proxara Connect routes work to one of four places. Deterministic work, and the classification and reasoning that must read raw or sensitive material, run inside the firm's own environment; the customer-contained inference plane that does the semantic part of that has no internet route, no route to an external model, no provider credentials, and no independent access to a source system. An approved external model receives only the constructed release package. A fourth route, raw material to an external processor, exists only where the firm has separately configured it for one purpose, processor, data class and destination. A managed endpoint reached over a private network link is still a managed external processor. How Proxara works sets out the four routes.
The providers below sit in the Proxara Connect data path under agreements the Customer holds directly. They are listed here so the data map is complete, in the same way the compliance-archive providers below are listed. None is engaged by Proxara, and none is a Proxara sub-processor.
Proxara Connect works inside the AI assistant the firm already runs, under the firm's own agreement with that provider (for example, a Claude or ChatGPT workspace agreement). The assistant receives only the release package the firm's policy admitted for that work: typed claims, with stand-ins in place of protected references, or, where policy keeps the work inside the firm, only a safe status. The mapping between a stand-in and the real value never leaves the firm's environment.
Two boundaries apply. A fact whose substance is unique enough can be identifying even with the identifiers replaced, which is why firm policy can keep a class of information inside the firm entirely. And anything an employee types or uploads directly into the assistant is already visible to that assistant; Connect governs the connected path.
For Proxara Connect, Proxara retrieves mail, calendar, Teams messages, files, and tasks from the Customer's own Microsoft 365 tenant through Microsoft Graph, on the Customer's instruction and under each signed-in employee's own delegated permissions: the connector can only ever see what that employee can already see. Microsoft processes that data as the Customer's own productivity-suite provider under the Customer's existing Microsoft agreement. Proxara's access is granted by the Customer's tenant administrator, appears in the Customer's own Entra admin center under Enterprise applications, and can be restricted or revoked by the Customer unilaterally.
Where the Customer connects Karbon, a selected tax system, a document store, or a CRM (Salesforce is one supported option; no CRM is required by the accounting product), Proxara reads and records updates through that provider's own interfaces, on the Customer's instruction, under the Customer's existing agreement with it, and within the permissions the Customer already maintains there. Each connection is approved by the Customer as its own separate consent and can be restricted or revoked by the Customer at any time. Each of those providers is the Customer's own provider, not a Proxara sub-processor.
Purpose: Outbound transactional and notification email (compliance digests, invitation emails, PDF leave-behinds). Proxara sends email through Google Workspace SMTP (smtp.gmail.com).
Processing location: United States.
Data processed: Recipient email addresses and the content of outbound notification messages.
Entity: Linux Foundation Sigstore project.
Purpose: Public-internet transparency log for anchoring the device agent's audit chain. Every five-minute Merkle batch root is submitted so that timestamps cannot be altered after the fact. If Rekor is unreachable, the batch anchor is still recorded locally and the chain continues. The Proxara Connect record is not anchored to a transparency log and carries no inclusion proofs.
Processing location: Public service operated by the Linux Foundation.
Data processed: A signed statement carrying the SHA-256 Merkle root hash and the anchor public key. No Customer Data, no prompts, no responses, no PII, and no device or tenant identifiers. The hash reveals nothing about the underlying events; it only allows independent verification that the batch existed at the recorded time.
Purpose: Used only when Proxara encounters an unrecognized MCP server and needs to research its capabilities (an Endpoint Protection surface). A generated metadata query (server or software name) is sent to Exa.
Processing location: United States.
Data processed: Server and software metadata only. No employee content and no personal data are transmitted.
Entities: Hugging Face, Inc. (huggingface.co); Ollama (registry.ollama.ai).
Purpose: License classification for locally-installed AI models (an Endpoint Protection surface). A weekly job resolves the license class of model identifiers discovered in the firm's device inventory.
Processing location: United States.
Data processed: Model repository and tag identifiers only (software metadata, for example a model name and version discovered on a device). No employee content and no personal data are transmitted.
The following processors are engaged only when the Customer explicitly connects the corresponding integration. These channels handle compliance notifications and read-only contextual metadata. The Customer connects its own accounts and, in many cases, already has an independent relationship with these providers. Customer-configured webhooks, where enabled, deliver alert payloads over HTTPS to endpoints the Customer chooses and controls.
| Integration | Entity | Purpose | Data processed |
|---|---|---|---|
| Slack | Slack Technologies, Inc. | Delivers compliance notifications to the firm's Slack workspace | Channel and user identifiers; alert cards carrying severity, employee name, firm name, a short summary of the interaction, and console links. Alert cards do not carry the prompt text. |
| Microsoft Teams and Microsoft Graph (Bot Framework, Entra ID, Intune) | Microsoft Corporation | Delivers compliance notifications to Teams; signs reviewers into the console with the firm's Entra identity; reads managed-device inventory from Intune for deployment health; reads calendar metadata for board-meeting context | Teams channel identifiers; alert cards carrying employee name, reason, data types, and up to 500 characters of the prompt excerpt, which for events where sensitive values were found is original prompt text; read-only device inventory; read-only calendar event metadata. This is a notification and metadata channel, separate from Proxara Connect's retrieval of Microsoft 365 content described above. The Endpoint Protection device agent does not intercept Microsoft 365 or Teams network traffic; it passes through unmodified. |
| Google Calendar | Google LLC | Reads calendar event metadata for board-meeting context | Read-only calendar event metadata |
For clarity:
The Service can be configured to forward interaction records to the firm's designated compliance archive provider (for example, Smarsh or Global Relay). Such a provider is engaged directly by the Customer under the Customer's own agreement and operates as the Customer's sub-processor, not Proxara's. Proxara does not select, contract with, or assume responsibility for the archive provider.
In accordance with the Data Processing Addendum, Proxara will provide Customers with at least 30 days' advance written notice before engaging a new sub-processor or replacing an existing one. The notice will identify the new sub-processor, describe its processing activities, and state its processing location.
Customers may object to a sub-processor change within 15 days of receiving notice. Objections will be handled through the dispute resolution process in the Data Processing Addendum.
Subprocessor change notifications are sent to the Customer contact email in the applicable Order Form. The "Last updated" date at the top of this page also reflects the date of the most recent change.
For questions about this sub-processor list:
Proxara, Inc.
28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108
Email: support@proxara.ai
Security inquiries: security@proxara.ai