Sub-processors
Last updated: 25 August 2026
Wytness uses the following categories of third-party sub-processors to deliver the Service. In accordance with our Data Processing Agreement, we will notify customers at least 30 days before engaging any new sub-processor. Each sub-processor receives only the minimum data required for its function.
Microsoft Azure
Cloudflare
Stripe
Microsoft Commercial Marketplace
AWS Marketplace
Resend
GitHub
Anthropic
Customer-Hosted Storage (Business Plan)
Customers on the Business plan with customer-hosted storage configured run the audit storage layer in their own cloud tenancy. That storage is operated by the customer and is not a Wytness sub-processor. Wytness signs, verifies, and reports on the events but does not retain a copy of the audit content in shared infrastructure.
Data Minimisation
Audit event payloads are stored only by Microsoft Azure (or, on the Business plan with customer-hosted storage, in the customer's own tenancy). Stripe receives only billing data. Resend receives only the recipient address and message content needed to deliver the email. Cloudflare, GitHub, and the marketplace billing providers do not receive event payloads. Cryptographic signing keys are never shared with any sub-processor; they remain exclusively in your environment.
How Obligations Flow Down to Sub-Processors
Under our Data Processing Agreement and Article 28(4) of the GDPR, we are required to flow our processor obligations down to each sub-processor. The mechanism varies by sub-processor:
- Direct contractual flow-down: every sub-processor in the list above has a Data Processing Agreement in force with us that incorporates equivalent obligations to those we owe you (security, breach notification, sub-processing controls, deletion or return on termination). Where the sub-processor is established outside Australia or the EEA, Standard Contractual Clauses (or equivalent transfer mechanism) are also in force.
- Programmatic erasure: where the sub-processor exposes an erasure API (currently: Stripe), our retention reaper invokes it when an organisation is hard-deleted, so the deletion cascade reaches the sub-processor automatically.
- Log retention policy only: for sub-processors that do not expose a programmatic erasure surface (currently: Cloudflare, GitHub, Resend, and the Microsoft and AWS marketplace billing providers), we rely on the sub-processor's own published log retention policy. Where this applies, the sub-processor receives metadata only (IP addresses, request paths, account identifiers, billing tokens) and never receives audit event payloads.
- Customer-controlled: on the Business plan with customer-hosted storage, audit content stays in your own cloud tenancy. Your tenancy is not a Wytness sub-processor; we sign and report on the events but do not retain a copy.
We document the flow-down mechanism for each sub-processor in our internal privacy inventory and re-review it on every release that touches sub-processors. If you would like a copy of the specific contractual terms for a sub-processor, contact support.
Subscribe to Change Notifications
To receive email notifications when this list changes, send a message with the subject "Sub-processor updates" to support@wytness.ai from the email address you would like added. We will provide at least 30 days' notice before adding or replacing a sub-processor. If you have concerns about a new sub-processor, you may object during the notice period as set out in the DPA.