Subprocessors

Every company that has any part in running Authalla, what each one does, and where its ultimate parent company sits. If a company is not on this list, it is not involved.

  • Hetzner Online GmbH

    Application hosting, PostgreSQL database and backups, object storage, authoritative DNS

    Ultimate parent
    Germany
    Region
    Finland (Helsinki)
    Added
    September 2026
    What data it sees
    All customer and end-user data held by Authalla.
  • Brevo (Sendinblue SAS)

    Transactional email delivery: sign-in links, one-time codes, verification messages

    Ultimate parent
    France
    Region
    EU (Belgium)
    Added
    September 2026
    What data it sees
    End-user email addresses and the contents of the messages we send them. Brevo states that it stores data on its own servers and on Google Cloud in Belgium.
  • GitHub, Inc. (Microsoft Corporation)

    Source code hosting, continuous integration, container registry

    Ultimate parent
    United States
    Region
    US
    Added
    September 2026
    What data it sees
    Source code and build artefacts only. No customer or end-user data is stored in or passes through it.
  • Internet Security Research Group (Let's Encrypt)

    TLS certificate issuance for authalla.com and for customer custom domains

    Ultimate parent
    United States
    Region
    US
    Added
    September 2026
    What data it sees
    Domain names only, as part of requesting a certificate. No customer or end-user data.

Why two US companies are on the list

GitHub and Let’s Encrypt handle no customer or end-user data. GitHub holds our source code and builds our container images, and Let’s Encrypt issues our TLS certificates. A subprocessor list usually covers only the companies that process personal data, so we could have left both off.

We list them because the claim on the European page is about jurisdiction, and you can only check it against a list that includes every US company involved. A US order can make either of them hand over what they hold, and neither holds any of your data.

What is not on the list

Analytics and bot protection run on our own infrastructure: Umami for cookieless page statistics, and Cap, a proof-of-work captcha, on signup and the contact form. Neither sends anything to a third party, so neither is listed above.

Social and enterprise identity providers are not our subprocessors. If you enable Google or Microsoft sign-in, or connect a customer’s identity provider, that is your relationship with that provider, under their terms.

Our SDK is published to npm and the CLI to Homebrew. Both are US-operated. They deliver code to developers’ machines, nothing comes back from them, and neither plays any part in a sign-in.

When this list changes

We give account owners 30 days’ notice by email before a new subprocessor starts handling your data, and this page is the record.