Legal
Sub-processors
Third-party providers Shieldra uses to deliver the service securely, with the purpose of each and where processing takes place. Effective August 16, 2026.
Key takeaways
- The platform runs on Railway (application hosting) and Neon (managed PostgreSQL) in the United States, with Cloudflare providing DNS, CDN, and R2 object storage for customer documents.
- Shieldra-managed AI features use Anthropic, OpenAI, and Google for LLM inference, under agreements or service terms that exclude use of Customer Data to train their models.
- Sub-processors are engaged under terms no less protective than the Shieldra Data Processing Addendum, with at least 30 days’ notice of changes and a right to object.
- Providers used only for Shieldra’s own website and go-to-market operations — analytics, fonts, prospect enrichment — do not process Customer Data and are listed separately.
Current sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Railway | Application hosting and runtime | United States |
| Neon | Managed PostgreSQL database | United States |
| Cloudflare | DNS, CDN, DDoS protection, and R2 object storage for customer documents | Global |
| Anthropic | Large language model inference for Shieldra-managed AI features | United States |
| OpenAI | Large language model inference for Shieldra-managed AI features | United States |
| Large language model inference (Gemini) for Shieldra-managed AI features | United States | |
| Resend | Transactional and program email delivery | United States |
| Stripe | Payment processing and subscription billing | United States |
Service providers for Shieldra’s own operations
These providers support Shieldra’s own website and go-to-market operations and do not process Customer Data.
- Google Analytics 4 — website analytics, consent-gated and IP-anonymized (site visitors, not Customer Data)
- Cloudflare Web Analytics — cookieless website analytics
- Meta (Facebook) Pixel — campaign attribution, loads only if you enable the Marketing cookie category
- Google Fonts — web font delivery on the marketing site
- Hunter.io — B2B contact enrichment for Shieldra’s own outreach (prospect data, not Customer Data)
How sub-processors are governed
Every sub-processor is bound by data-protection obligations no less protective than the Shieldra Data Processing Addendum, and Shieldra remains responsible for each sub-processor’s compliance. AI sub-processors are engaged under agreements or service terms that exclude use of Customer Data to train their models. Customers are notified of additions or replacements with at least 30 days’ notice and may object on reasonable data-protection grounds.
Third-party tools that customers choose to connect through integrations — such as Intune, Jamf, Kandji, JumpCloud, GitHub, KnowBe4, Wiz, Orca, Google Drive, OneDrive / SharePoint, or Amazon S3 — act under the customer’s own agreements with those vendors and are not Shieldra sub-processors.
Frequently asked questions
Where is Shieldra customer data hosted?
Application hosting runs on Railway and the database on Neon, both US-based providers, with uploaded customer documents stored in Cloudflare R2 object storage.
Does Shieldra send customer data to AI providers?
Shieldra-managed AI features use large language model inference through Anthropic, OpenAI, and Google, under agreements or service terms that exclude use of Customer Data to train their models. Customers can optionally bring their own AI provider key, in which case those calls run under their own agreement with that provider.
Are sub-processors bound by the same data protection terms?
Yes. Each sub-processor is engaged under obligations no less protective than the Shieldra Data Processing Addendum, and Shieldra remains responsible for their compliance. Changes come with at least 30 days’ notice and a right to object on reasonable data-protection grounds.