This page lists the third-party service providers ("Subprocessors") that ElasticD3M, LLC engages to deliver the AutoGRC™ Services. The Data Processing Addendum governs how Subprocessors handle Personal Data. We give Customer at least thirty (30) days' advance notice of any new Subprocessor that will process Customer Personal Data, with a right to object.
No AI subprocessor. The AutoGRC™ analysis engine is deterministic control-mapping arithmetic. Customer findings are not sent to any large-language-model provider, and no Subprocessor listed here receives Customer findings as model input. Adding an AI Subprocessor would require the thirty (30) day notice and right to object described below.
Trade-compliance note. All listed Subprocessors are U.S.-domiciled or are bound by Standard Contractual Clauses with comparable trade-compliance covenants. None are organized in or operated from an OFAC-embargoed jurisdiction. ElasticD3M, LLC reviews Subprocessor sanctions status at onboarding and at least annually.
Active Subprocessors
| Subprocessor | Purpose | Data Scope | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing for paid AutoGRC™ services (the AutoGRC Coverage Report and AutoGRC subscriptions); consent collection at checkout. | Billing identity, payment method (Stripe stores card data; we receive only metadata). | United States (Delaware). stripe.com/privacy |
| Cloudflare, Inc. | Hosting, CDN, DNS, WAF, bot management, and Cloudflare Web Analytics for ai4grc.ai. No cookies on the analytics product. | Technical metadata (IP, user-agent, request paths); no Customer Data payload. | United States (global edge). cloudflare.com/privacypolicy |
| Resend, Inc. | Transactional email delivery (welcome emails, deliverable notifications, support replies). | Identity / contact information, email message contents. | United States. resend.com/legal/privacy-policy |
| Sentry (Functional Software, Inc.) | Application-error telemetry and performance monitoring for the production backend. | Stack traces, request metadata, scrubbed parameters; no Customer Data payload by configuration. | United States. sentry.io/privacy |
| Railway Corp. | Application hosting and deployment for the backend services, and the managed PostgreSQL database holding account, subscription, fulfillment-ledger and audit-log state. | Identity / contact information, account metadata, fulfillment records, audit-log records. Submitted findings are analyzed in-request and are not written to the database. | United States. railway.com/legal/privacy |
How We Manage Subprocessors
- Due diligence at onboarding: Each Subprocessor is evaluated for security posture, applicable compliance certifications (SOC 2 Type II, ISO 27001, PCI-DSS where applicable), and contractual commitments substantially equivalent to those in our DPA. Sanctions and denied-party screening is run at onboarding.
- Annual review: Active Subprocessors are reviewed at least annually for continued compliance, updated certifications, and material changes in ownership or jurisdiction.
- Contractual flow-down: Each Subprocessor is bound by data-protection obligations no less protective than those in our DPA with Customer, including SCCs / UK IDTA where personal data crosses jurisdictional boundaries.
- Change notice: Customer receives at least thirty (30) days' advance notice of any new Subprocessor that will process Customer Personal Data, via update to this page and email to the primary account contact.
Right to Object
If Customer objects to a new Subprocessor, Customer may notify ElasticD3M, LLC in writing within thirty (30) days of the notice. The parties will work in good faith to resolve the objection (for example, by configuring the Services to avoid the new Subprocessor for Customer's account). If the parties cannot resolve the objection, Customer may terminate the affected portion of the Services and receive a pro-rata refund of any unused prepaid fees.
Contact
Subprocessor questions or objections: privacy@elasticd3m.com
Last Updated: May 12, 2026 · Version: 2.0