Legal

Sub-processors

Third-party providers Shieldra uses to deliver the service securely, with the purpose of each and where processing takes place. Effective August 16, 2026.

Key takeaways

  • The platform runs on Railway (application hosting) and Neon (managed PostgreSQL) in the United States, with Cloudflare providing DNS, CDN, and R2 object storage for customer documents.
  • Shieldra-managed AI features use Anthropic, OpenAI, and Google for LLM inference, under agreements or service terms that exclude use of Customer Data to train their models.
  • Sub-processors are engaged under terms no less protective than the Shieldra Data Processing Addendum, with at least 30 days’ notice of changes and a right to object.
  • Providers used only for Shieldra’s own website and go-to-market operations — analytics, fonts, prospect enrichment — do not process Customer Data and are listed separately.

Current sub-processors

ProviderPurposeLocation
RailwayApplication hosting and runtimeUnited States
NeonManaged PostgreSQL databaseUnited States
CloudflareDNS, CDN, DDoS protection, and R2 object storage for customer documentsGlobal
AnthropicLarge language model inference for Shieldra-managed AI featuresUnited States
OpenAILarge language model inference for Shieldra-managed AI featuresUnited States
GoogleLarge language model inference (Gemini) for Shieldra-managed AI featuresUnited States
ResendTransactional and program email deliveryUnited States
StripePayment processing and subscription billingUnited States

Service providers for Shieldra’s own operations

These providers support Shieldra’s own website and go-to-market operations and do not process Customer Data.

  • Google Analytics 4 — website analytics, consent-gated and IP-anonymized (site visitors, not Customer Data)
  • Cloudflare Web Analytics — cookieless website analytics
  • Meta (Facebook) Pixel — campaign attribution, loads only if you enable the Marketing cookie category
  • Google Fonts — web font delivery on the marketing site
  • Hunter.io — B2B contact enrichment for Shieldra’s own outreach (prospect data, not Customer Data)

How sub-processors are governed

Every sub-processor is bound by data-protection obligations no less protective than the Shieldra Data Processing Addendum, and Shieldra remains responsible for each sub-processor’s compliance. AI sub-processors are engaged under agreements or service terms that exclude use of Customer Data to train their models. Customers are notified of additions or replacements with at least 30 days’ notice and may object on reasonable data-protection grounds.

Third-party tools that customers choose to connect through integrations — such as Intune, Jamf, Kandji, JumpCloud, GitHub, KnowBe4, Wiz, Orca, Google Drive, OneDrive / SharePoint, or Amazon S3 — act under the customer’s own agreements with those vendors and are not Shieldra sub-processors.

Frequently asked questions

Where is Shieldra customer data hosted?

Application hosting runs on Railway and the database on Neon, both US-based providers, with uploaded customer documents stored in Cloudflare R2 object storage.

Does Shieldra send customer data to AI providers?

Shieldra-managed AI features use large language model inference through Anthropic, OpenAI, and Google, under agreements or service terms that exclude use of Customer Data to train their models. Customers can optionally bring their own AI provider key, in which case those calls run under their own agreement with that provider.

Are sub-processors bound by the same data protection terms?

Yes. Each sub-processor is engaged under obligations no less protective than the Shieldra Data Processing Addendum, and Shieldra remains responsible for their compliance. Changes come with at least 30 days’ notice and a right to object on reasonable data-protection grounds.