Subprocessors
Every company that has any part in running Authalla, what each one does, and where its ultimate parent company sits. If a company is not on this list, it is not involved.
Hetzner Online GmbH
Application hosting, PostgreSQL database and backups, object storage, authoritative DNS
- Ultimate parent
- Germany
- Region
- Finland (Helsinki)
- Added
- September 2026
- What data it sees
- All customer and end-user data held by Authalla.
Brevo (Sendinblue SAS)
Transactional email delivery: sign-in links, one-time codes, verification messages
- Ultimate parent
- France
- Region
- EU (Belgium)
- Added
- September 2026
- What data it sees
- End-user email addresses and the contents of the messages we send them. Brevo states that it stores data on its own servers and on Google Cloud in Belgium.
GitHub, Inc. (Microsoft Corporation)
Source code hosting, continuous integration, container registry
- Ultimate parent
- United States
- Region
- US
- Added
- September 2026
- What data it sees
- Source code and build artefacts only. No customer or end-user data is stored in or passes through it.
Internet Security Research Group (Let's Encrypt)
TLS certificate issuance for authalla.com and for customer custom domains
- Ultimate parent
- United States
- Region
- US
- Added
- September 2026
- What data it sees
- Domain names only, as part of requesting a certificate. No customer or end-user data.
Why two US companies are on the list
GitHub and Let’s Encrypt handle no customer or end-user data. GitHub holds our source code and builds our container images, and Let’s Encrypt issues our TLS certificates. A subprocessor list usually covers only the companies that process personal data, so we could have left both off.
We list them because the claim on the European page is about jurisdiction, and you can only check it against a list that includes every US company involved. A US order can make either of them hand over what they hold, and neither holds any of your data.
What is not on the list
Analytics and bot protection run on our own infrastructure: Umami for cookieless page statistics, and Cap, a proof-of-work captcha, on signup and the contact form. Neither sends anything to a third party, so neither is listed above.
Social and enterprise identity providers are not our subprocessors. If you enable Google or Microsoft sign-in, or connect a customer’s identity provider, that is your relationship with that provider, under their terms.
Our SDK is published to npm and the CLI to Homebrew. Both are US-operated. They deliver code to developers’ machines, nothing comes back from them, and neither plays any part in a sign-in.
When this list changes
We give account owners 30 days’ notice by email before a new subprocessor starts handling your data, and this page is the record.