Third-party sub-processors engaged by Proxara for managed deployments, including the Sigstore Rekor transparency log that anchors the audit chain. Change notification process and current processor details.
Updated July 2026
Last updated: July 2026
This page lists the sub-processors engaged by Proxara to process personal data on behalf of Customers in Proxara-Managed Dedicated Account deployments, as described in the Data Processing Addendum. It also identifies, for clarity, the providers that touch Customer Data but are the Customer's own providers rather than Proxara sub-processors.
This list applies only to Proxara-Managed Dedicated Account deployments, where Proxara acts as a data processor under Article 28 of the GDPR and equivalent laws. It covers both Proxara products: Proxara Connect (the hosted connector that joins the firm's AI assistant to Microsoft 365 through the firm's dedicated environment) and Endpoint Protection (the device agent). Where an entry applies to only one product, the entry says so.
For Customer-Managed deployments, Proxara is a software licensor and does not process personal data on the Customer's behalf. In those models, AWS is the Customer's own provider, not Proxara's sub-processor.
Entity: Amazon Web Services, Inc.
Purpose: Hosts the Customer's dedicated, single-tenant AWS account and provides all core infrastructure for the Service.
Processing location: The Customer's dedicated AWS account, in the Customer-selected region (US regions by default). Bedrock inference runs under a managed cross-region inference profile within US regions.
Data processed: All Customer Data handled by the Service, including prompts, responses, employee metadata, classification results, redacted event records, audit archives, and, for Proxara Connect, Microsoft 365 content retrieved on the employee's behalf together with the encrypted workflow state, stand-in vault, and grant tokens described below.
AWS services used within the Customer's environment:
| Service | Role | Data involvement |
|---|---|---|
| Compute (ECS Fargate) | Runs the classification API, the compliance console, and, for Proxara Connect, the connector runtime | Processes prompts, responses, metadata, and, for Proxara Connect, retrieved Microsoft 365 content, in transit |
| Amazon RDS (PostgreSQL) | Stores audit records and event data | Stores flagged event content, classification results, and reviewer actions on a short-retention window (seven days by default), and the signed audit-chain envelopes, which persist as the compliance record and archive to S3. For Proxara Connect: encrypted workflow state, clear-view documents held under a short time-to-live, the stand-in vault (the reversible mappings between protected references and their stand-ins), and encrypted per-employee Microsoft 365 grant tokens, all encrypted under the Customer's KMS keys |
| Amazon ElastiCache (Redis) | Session, queue, and cache layer | Holds transient session, queue, and workflow-coordination data |
| Amazon S3 | Archives audit proofs for long-term retention | Stores encrypted, immutable audit archives (7-year COMPLIANCE Object Lock) |
| AWS KMS | Manages encryption keys for the Customer's account | Encrypts data at rest, including the Proxara Connect stand-in vault; does not itself store Customer Data |
| AWS Secrets Manager | Stores API credentials and service secrets | Holds secrets in encrypted form; does not process Customer Data |
| Amazon Bedrock | AI inference for data classification | Receives prompt and response text, extracted file text, and, for Proxara Connect, retrieved Microsoft 365 content, for real-time classification and the semantic identification of protected references; also powers the built-in assistant and MCP triage reasoning. Does not store inputs or outputs. Runs inside the AWS-managed service under a cross-region US inference profile |
| Amazon Textract | Document text extraction (OCR) | Receives document page images for text extraction; does not store them |
| Amazon CloudWatch | Operational monitoring and log aggregation | Receives operational metrics and structured, content-free logs |
| Amazon CloudFront | Static asset delivery for the compliance console | Serves static files; does not store Customer Data |
Note: AI inference on Bedrock runs entirely inside the AWS-managed service. The contractual relationship for that inference is with Amazon Web Services; no separate model-vendor relationship processes Customer Data for classification. Where the firm's employees use Proxara Connect, the firm's own AI assistant additionally receives the policy-approved, protected material described in the next section; that relationship is the firm's own.
Two providers sit in the Proxara Connect data path under agreements the Customer holds directly. They are listed here so the data map is complete, in the same way the compliance-archive providers below are listed. Neither is engaged by Proxara, and neither is a Proxara sub-processor.
Proxara Connect works inside the AI assistant the firm already runs, under the firm's own agreement with that provider (for example, the firm's Claude workspace agreement with Anthropic). When an employee asks the assistant to work across the firm's systems, the assistant receives only what the firm's policy permits: the substance of the work with protected references replaced by consistent stand-ins, or, in the stricter Private Analysis mode, only a safe status while the full result stays inside the firm's environment. The mapping between a stand-in and the real value never leaves the firm's environment.
Two honest boundaries apply. First, the substance of a fact can itself be identifying in rare cases even with the identifiers replaced, which is why firm policy can keep specific classes of information inside the firm entirely. Second, anything an employee types or uploads directly into the assistant is already visible to that assistant; Proxara Connect governs the connected path, and Endpoint Protection is the product that extends coverage to typed text and uploads on managed devices.
For Proxara Connect, Proxara retrieves mail, calendar, Teams messages, files, and tasks from the Customer's own Microsoft 365 tenant through the Microsoft Graph interface, on the Customer's instruction and under each signed-in employee's own delegated permissions: the connector can only ever see what the signed-in employee can already see. Microsoft processes that data as the Customer's own productivity-suite provider under the Customer's existing Microsoft agreement. Proxara's access is granted by the Customer's tenant administrator, appears in the Customer's own Entra admin center under Enterprise applications, and can be restricted or revoked by the Customer unilaterally.
Purpose: Outbound transactional and notification email (compliance digests, invitation emails, PDF leave-behinds). Proxara sends email through Google Workspace SMTP (smtp.gmail.com).
Processing location: United States.
Data processed: Recipient email addresses and the content of outbound notification messages.
Entity: Linux Foundation Sigstore project.
Purpose: Public-internet transparency log for audit-chain anchoring. Anchoring runs by default: every five-minute Merkle batch root from the audit chain is submitted so that timestamps cannot be altered after the fact. If Rekor is unreachable, the batch anchor is still recorded locally and the chain continues.
Processing location: Public service operated by the Linux Foundation.
Data processed: A signed statement carrying the SHA-256 Merkle root hash and the anchor public key. No Customer Data, no prompts, no responses, no PII, and no device or tenant identifiers. The hash reveals nothing about the underlying events; it only allows independent verification that the batch existed at the recorded time.
Purpose: Used only when Proxara encounters an unrecognized MCP server and needs to research its capabilities (an Endpoint Protection surface). A generated metadata query (server or software name) is sent to Exa.
Processing location: United States.
Data processed: Server and software metadata only. No employee content and no personal data are transmitted.
Entities: Hugging Face, Inc. (huggingface.co); Ollama (registry.ollama.ai).
Purpose: License classification for locally-installed AI models (an Endpoint Protection surface). A weekly job resolves the license class of model identifiers discovered in the firm's device inventory.
Processing location: United States.
Data processed: Model repository and tag identifiers only (software metadata, for example a model name and version discovered on a device). No employee content and no personal data are transmitted.
The following processors are engaged only when the Customer explicitly connects the corresponding integration. These channels handle compliance notifications and read-only contextual metadata. The Customer connects its own accounts and, in many cases, already has an independent relationship with these providers. Customer-configured webhooks, where enabled, deliver alert payloads over HTTPS to endpoints the Customer chooses and controls.
| Integration | Entity | Purpose | Data processed |
|---|---|---|---|
| Slack | Slack Technologies, Inc. | Delivers compliance notifications to the firm's Slack workspace | Channel and user identifiers; alert cards carrying severity, employee name, firm name, a short summary of the interaction, and console links. Alert cards do not carry the prompt text. |
| Microsoft Teams and Microsoft Graph (Bot Framework, Entra ID, Intune) | Microsoft Corporation | Delivers compliance notifications to Teams; signs reviewers into the console with the firm's Entra identity; reads managed-device inventory from Intune for deployment health; reads calendar metadata for board-meeting context | Teams channel identifiers; alert cards carrying employee name, reason, data types, and up to 500 characters of the prompt excerpt, which for events where sensitive values were found is original prompt text; read-only device inventory; read-only calendar event metadata. Note: this integration is a notification and metadata channel. It is separate from Proxara Connect's retrieval of Microsoft 365 content, which runs under each employee's own delegated permissions and is described above under The Firm's Own Providers. The Endpoint Protection device agent does not intercept Microsoft 365 or Teams network traffic; it passes through unmodified. |
| Google Calendar | Google LLC | Reads calendar event metadata for board-meeting context | Read-only calendar event metadata |
For clarity:
The Service can be configured to forward interaction records to the firm's designated compliance archive provider (for example, Smarsh or Global Relay). Such a provider is engaged directly by the Customer under the Customer's own agreement and operates as the Customer's sub-processor, not Proxara's. Proxara does not select, contract with, or assume responsibility for the archive provider.
In accordance with the Data Processing Addendum, Proxara will provide Customers with at least 30 days' advance written notice before engaging a new sub-processor or replacing an existing one. The notice will identify the new sub-processor, describe its processing activities, and state its processing location.
Customers may object to a sub-processor change within 15 days of receiving notice. Objections will be handled through the dispute resolution process in the Data Processing Addendum.
Subprocessor change notifications are sent to the Customer contact email in the applicable Order Form. The "Last updated" date at the top of this page also reflects the date of the most recent change.
For questions about this sub-processor list:
Proxara, Inc.
28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108
Email: support@proxara.ai
Security inquiries: security@proxara.ai