Legal
Sub-processors
Third-party providers Shieldra uses to deliver the service securely, with the purpose of each and where processing takes place. Effective April 13, 2026.
By the Shieldra Compliance Team · Last updated April 13, 2026
Key takeaways
- Primary hosting, storage, and compute run on AWS in the United States (us-east-1 and us-west-2).
- Sub-processors are engaged under terms no less protective than the Shieldra Data Processing Addendum.
- Error monitoring receives no Customer Data, and product analytics are anonymized.
- The full, current list with links to each provider’s trust documentation is published on this page.
Current sub-processors
| Provider | Purpose |
|---|
| Amazon Web Services | Primary cloud hosting, storage, and compute — United States (us-east-1, us-west-2) |
| Railway | Application deployment and runtime |
| Anthropic | Large language model inference for AI features |
| Stripe | Payment processing and subscription billing |
| Postmark | Transactional email delivery |
| Cloudflare | CDN, DNS, and network security |
| Error monitoring provider | Application error monitoring — no Customer Data sent |
| Product analytics provider | Product analytics — anonymized |
How sub-processors are governed
Every sub-processor is engaged under the Data Processing Addendum, which imposes data protection obligations no less protective than those Shieldra owes its customers. Shieldra remains responsible for each sub-processor’s compliance.
Where personal data is transferred internationally, Shieldra conducts transfer impact assessments and applies supplementary measures where required. This page is the authoritative current list; customers should treat it as the reference point for vendor reviews and their own risk registers.
Frequently asked questions
Where is Shieldra customer data hosted?
Primary hosting, storage, and compute run on Amazon Web Services in the United States, in the us-east-1 and us-west-2 regions.
Does Shieldra send customer data to AI providers?
AI features use large language model inference through Anthropic. Shieldra is also bring-your-own-key: when you configure your own AI provider, prompts and responses flow directly between your tenant and that provider under your terms with them.
Are sub-processors bound by the same data protection terms?
Yes. Each sub-processor is engaged under obligations no less protective than the Shieldra Data Processing Addendum, and Shieldra remains responsible for their compliance.