Solution

Sub-processors we work with

Every third party that processes customer or candidate data on our behalf — with what they handle, where they sit, and how to be notified of changes.

sub-processors listGDPR Article 28 sub-processorsproctoring vendor sub-processorsEU data residency proctoring
GDPR Art. 28 compliant

We publish the full list as required by GDPR Article 28(2), and notify customers within 30 days of any addition or replacement.

EU-only hosting and AI

All primary infrastructure (AWS Paris), AI processing (Mistral AI, France), and transactional email (Brevo, EU regions) are hosted in the EU. No customer or candidate data is transferred outside the European Economic Area.

Logical multi-tenancy with strict per-tenant scoping

We segregate tenant data with row-level scoping and tenant-scoped IAM policies. Compute and database are shared across customers; we do not offer a single-tenant deployment today.

ProctorSafe ("we", "us", "the Company") engages the third parties below to deliver the service. Each one is bound by a written data-processing agreement that satisfies GDPR Article 28, and where transfers outside the EEA are unavoidable, we rely on the EU Standard Contractual Clauses (SCCs) plus any supplementary measures required by a transfer impact assessment.

If you need the underlying list as a CSV or JSON for your own vendor register, write to [email protected].

Infrastructure and hosting

Sub-processorWhat they processHosting locationNotes
**Amazon Web Services (AWS)** — App Runner, S3, RDS for PostgreSQLTenant and session data, captures (screenshots, video clips when recording is on), AI analysis payloads**EU (Paris, `eu-west-3`)** — primary; some adjacent AWS services may reside in `eu-central-1` (Frankfurt) per `src/app/privacy/page.tsx`Production hosting. Encryption at rest with AWS KMS-managed keys. **Multi-tenant with logical segregation:** App Runner compute is shared across customers; the same RDS PostgreSQL instance hosts the schema for every tenant with row-level scoping. S3 buckets are tenant-scoped via IAM policies so a per-tenant read credential cannot reach another tenant's objects. Captures are encrypted at rest.
**Gandi.net** *(domain registrar)*Domain registration for `proctorsafe.eu`France / EURegistrar-only relationship (per the `217.70.184.38` resolver path). No customer or candidate data is exchanged with the registrar beyond the domain name itself.

AI providers

ProctorSafe offers AI analysis as an optional, per-section feature on top of the detection pipeline. We do not send candidate video or audio to AI providers — the structured event timeline is what the model sees. Mistral AI is our only AI sub-processor in any environment. The codebase has a developer-only alternate path for OpenAI (PROCTOR_AI_PROVIDER=openai), but it is not configured in any live environment and no customer or candidate data has ever flowed through it. We do not list it here.
Sub-processorWhat they processHosting locationNotes
**Mistral AI**Compressed event timeline (codes + timestamps + severity) — text only, no PII, no biometric data**EU (France)**Used for both the one-pass AI analysis and the multi-turn AI agent review. Default model: `mistral-large-latest`. Already named in our privacy notice at `/privacy`.
Your own AI provider *(BYO optional)*Compressed event timeline onlyYour chosen regionIf you bring your own AI provider, you can configure it for the analysis step instead of Mistral. The compressed event timeline (not the candidate's video, audio, or screenshots) is the only input. We would list your provider here with the standard 30-day notice if it processes data on our infrastructure rather than yours.

Email and notifications

Sub-processorWhat they processHosting locationNotes
**Brevo** (formerly Sendinblue) — SMTP relayOutbound email to internal staff (contact-form notifications, breach notifications, magic links). From address: `ProctorSafe <[email protected]>`. Reply-To: caller-supplied, defaulting to `[email protected]` unless `CONTACT_EMAIL_REPLY_TO` is set in the deployment env (commonly `[email protected]`).**EU** (Brevo's transactional infrastructure is hosted in France / EU regions; account and data centre selected at signup)Replaces an earlier Gmail-based SMTP setup. Brevo is on the EU sub-processor register of major EU SaaS providers and processes email payloads inside the EEA by default. Customer contact data is the email body text and the From / To / Reply-To headers — no candidate-facing email goes through this path.

Analytics and product telemetry

Sub-processorWhat they processHosting locationNotes
**Amplitude** (`@amplitude/unified` browser SDK)Anonymised product analytics events (CTA clicks, sign-in successes and failures, dashboard feature usage)EU data residency availableBrowser-side only. No session data, no event codes, no candidate PII. Loaded with `AMPLITUDE_PUBLIC_API_KEY` resolved at runtime via `/api/public-config`, so a single build works across environments. Optionally disabled via `NEXT_PUBLIC_AMPLITUDE_OPT_OUT`.

Observability and error reporting

Sub-processorWhat they processHosting locationNotes
**Application logs to stdout** — collected by **AWS CloudWatch** via the App Runner log-driverServer logs, request traces, error counts**EU (same region as the app)**30-day retention. Candidate id is the opaque session id, not PII. We do **not** ship logs to a third-party APM (Sentry, Datadog, etc.) — none are present in `package.json`. If that ever changes, this page updates with the same 30-day notice.

Customer support tooling

Sub-processorWhat they processHosting locationNotes
**Direct email** (no support-desk vendor)Inbound email from customers, support threadsProctorSafe mailserver (AWS region, EU)We do not currently use a third-party support-desk product. If we add one (Zendesk, Intercom, etc.), this page updates with the same 30-day notice.

Billing and payments

Sub-processorWhat they processHosting locationNotes
**No third-party payment processor today**n/an/aWe do not currently charge customers per usage; billing is in design (issue #322). When payments go live, the processor will be EU-hosted and added to this page with the standard 30-day notice. Customer payment details never reach our backend.

How we notify you of changes

We publish a sub-processor change notice to:
  • `[email protected]` subscribers (sign up by emailing
  • The in-app admin notification centre for tenant administrators.
[email protected] with subject subscribe to sub-processor changes).
  • The in-app admin notification centre for tenant administrators.
Notice is given at least 30 days before any new sub-processor is engaged for processing that affects customer or candidate data. If a change is required to address an incident or a security finding, we notify as soon as is reasonably practical, with the reasoning documented in the notice.

Right to object

If a sub-processor change is unacceptable for your deployment, you may terminate the relevant order form within the 30-day notice window and we will refund any pre-paid, unused fees on a pro-rata basis. If you have a specific sub-processor concern that cannot be addressed by the standard deployment, contact us — we will discuss whether a custom configuration is feasible.

Sub-processors we no longer use

For audit-trail purposes, the following sub-processors were previously listed and have since been retired:

  • Google LLC (Gmail + Google SMTP) — replaced by Brevo as the outbound SMTP sub-processor on 2026-09-23. Originally deployed with a personal Gmail account ([email protected]) as the credential and From address; migrated to Brevo for EU residency and contractual hygiene. Issue #325 covered the migration.

Contact

For questions about a specific sub-processor, a sub-processor change, or to subscribe to change notifications:


Last updated: 2026-09-22 Next scheduled review: 2026-12-22 (quarterly)

Ready to Get Started?

Start a free trial and run real sessions against your own application, try the interactive demo in your browser, or contact us for a walkthrough tailored to your program.