Every third party that processes customer or candidate data on our behalf — with what they handle, where they sit, and how to be notified of changes.
We publish the full list as required by GDPR Article 28(2), and notify customers within 30 days of any addition or replacement.
All primary infrastructure (AWS Paris), AI processing (Mistral AI, France), and transactional email (Brevo, EU regions) are hosted in the EU. No customer or candidate data is transferred outside the European Economic Area.
We segregate tenant data with row-level scoping and tenant-scoped IAM policies. Compute and database are shared across customers; we do not offer a single-tenant deployment today.
ProctorSafe ("we", "us", "the Company") engages the third parties below to deliver the service. Each one is bound by a written data-processing agreement that satisfies GDPR Article 28, and where transfers outside the EEA are unavoidable, we rely on the EU Standard Contractual Clauses (SCCs) plus any supplementary measures required by a transfer impact assessment.
If you need the underlying list as a CSV or JSON for your own vendor register, write to [email protected].
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| **Amazon Web Services (AWS)** — App Runner, S3, RDS for PostgreSQL | Tenant and session data, captures (screenshots, video clips when recording is on), AI analysis payloads | **EU (Paris, `eu-west-3`)** — primary; some adjacent AWS services may reside in `eu-central-1` (Frankfurt) per `src/app/privacy/page.tsx` | Production hosting. Encryption at rest with AWS KMS-managed keys. **Multi-tenant with logical segregation:** App Runner compute is shared across customers; the same RDS PostgreSQL instance hosts the schema for every tenant with row-level scoping. S3 buckets are tenant-scoped via IAM policies so a per-tenant read credential cannot reach another tenant's objects. Captures are encrypted at rest. |
| **Gandi.net** *(domain registrar)* | Domain registration for `proctorsafe.eu` | France / EU | Registrar-only relationship (per the `217.70.184.38` resolver path). No customer or candidate data is exchanged with the registrar beyond the domain name itself. |
PROCTOR_AI_PROVIDER=openai), but it is not configured in any live
environment and no customer or candidate data has ever flowed
through it. We do not list it here.| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| **Mistral AI** | Compressed event timeline (codes + timestamps + severity) — text only, no PII, no biometric data | **EU (France)** | Used for both the one-pass AI analysis and the multi-turn AI agent review. Default model: `mistral-large-latest`. Already named in our privacy notice at `/privacy`. |
| Your own AI provider *(BYO optional)* | Compressed event timeline only | Your chosen region | If you bring your own AI provider, you can configure it for the analysis step instead of Mistral. The compressed event timeline (not the candidate's video, audio, or screenshots) is the only input. We would list your provider here with the standard 30-day notice if it processes data on our infrastructure rather than yours. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| **Brevo** (formerly Sendinblue) — SMTP relay | Outbound email to internal staff (contact-form notifications, breach notifications, magic links). From address: `ProctorSafe <[email protected]>`. Reply-To: caller-supplied, defaulting to `[email protected]` unless `CONTACT_EMAIL_REPLY_TO` is set in the deployment env (commonly `[email protected]`). | **EU** (Brevo's transactional infrastructure is hosted in France / EU regions; account and data centre selected at signup) | Replaces an earlier Gmail-based SMTP setup. Brevo is on the EU sub-processor register of major EU SaaS providers and processes email payloads inside the EEA by default. Customer contact data is the email body text and the From / To / Reply-To headers — no candidate-facing email goes through this path. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| **Amplitude** (`@amplitude/unified` browser SDK) | Anonymised product analytics events (CTA clicks, sign-in successes and failures, dashboard feature usage) | EU data residency available | Browser-side only. No session data, no event codes, no candidate PII. Loaded with `AMPLITUDE_PUBLIC_API_KEY` resolved at runtime via `/api/public-config`, so a single build works across environments. Optionally disabled via `NEXT_PUBLIC_AMPLITUDE_OPT_OUT`. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| **Application logs to stdout** — collected by **AWS CloudWatch** via the App Runner log-driver | Server logs, request traces, error counts | **EU (same region as the app)** | 30-day retention. Candidate id is the opaque session id, not PII. We do **not** ship logs to a third-party APM (Sentry, Datadog, etc.) — none are present in `package.json`. If that ever changes, this page updates with the same 30-day notice. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| **Direct email** (no support-desk vendor) | Inbound email from customers, support threads | ProctorSafe mailserver (AWS region, EU) | We do not currently use a third-party support-desk product. If we add one (Zendesk, Intercom, etc.), this page updates with the same 30-day notice. |
| Sub-processor | What they process | Hosting location | Notes |
|---|---|---|---|
| **No third-party payment processor today** | n/a | n/a | We do not currently charge customers per usage; billing is in design (issue #322). When payments go live, the processor will be EU-hosted and added to this page with the standard 30-day notice. Customer payment details never reach our backend. |
[email protected] with subject subscribe to sub-processor changes).
If a sub-processor change is unacceptable for your deployment, you may terminate the relevant order form within the 30-day notice window and we will refund any pre-paid, unused fees on a pro-rata basis. If you have a specific sub-processor concern that cannot be addressed by the standard deployment, contact us — we will discuss whether a custom configuration is feasible.
For audit-trail purposes, the following sub-processors were previously listed and have since been retired:
[email protected]) as the
credential and From address; migrated to Brevo for EU residency
and contractual hygiene. Issue #325 covered the migration.For questions about a specific sub-processor, a sub-processor change, or to subscribe to change notifications:
[email protected]Last updated: 2026-09-22 Next scheduled review: 2026-12-22 (quarterly)
Dive deeper with guides from our articles library.
A practical breakdown of which GDPR articles apply to online exam proctoring, what they require, and how ProctorSafe's architecture addresses each requirement by design — not by policy.
Read articleRegulatory & complianceHow GDPR Article 25 changes remote assessment design: data minimization, default settings, and what “state of the art” means for proctoring.
Read articleRegulatory & complianceA DPIA blueprint for remote proctoring: necessity, proportionality, student risk assessment, and privacy-first mitigations.
Read articleStart a free trial and run real sessions against your own application, try the interactive demo in your browser, or contact us for a walkthrough tailored to your program.