Solution

Sub-processors we work with

Every third party that processes customer or candidate data on our behalf — with what they handle, where they sit, and how to be notified of changes.

sub-processors listGDPR Article 28 sub-processorsproctoring vendor sub-processorsEU data residency proctoring
GDPR Art. 28 compliant

We publish the full list as required by GDPR Article 28(2), and notify customers within 30 days of any addition or replacement.

EU-hosted, EU-routed

All primary infrastructure and AI processing is hosted in the EU. No customer or candidate data is transferred outside the European Economic Area by default.

Customer-controlled single-tenant option

For workloads that require zero third-party sub-processors, we offer an EU-only single-tenant deployment. Contact us for details.

ProctorSafe ("we", "us", "the Company") engages the third parties below to deliver the service. Each one is bound by a written data-processing agreement that satisfies GDPR Article 28, and where transfers outside the EEA are unavoidable, we rely on the EU Standard Contractual Clauses (SCCs) plus any supplementary measures required by an updated transfer impact assessment.

If you need the underlying list as a CSV or JSON for your own vendor register, write to [email protected].

Infrastructure and hosting

Sub-processorWhat they processHosting locationNotes
Primary cloud providerTenant and session data, captures (if recording on), backup snapshotsEU (Frankfurt, primary; Dublin, failover)Object storage, PostgreSQL, container runtime. EU-only by default.
Object storage (S3-compatible)Temporary session-capture storage, AI analysis payloadsEUBuckets are tenant-scoped, encryption at rest with KMS-managed keys.
DNS providerDomain resolution for `proctorsafe.eu`Global anycast, EU resolvers availableNo customer data flows through DNS.

AI providers

ProctorSafe offers AI analysis as an optional, per-section feature on top of the detection pipeline. We do not send candidate video or audio to AI providers — the structured event timeline is what the model sees. The model is configurable per tenant; the providers we integrate with by default are listed below.
Sub-processorWhat they processHosting locationNotes
Primary AI provider (EU tier)Compressed event timeline (codes + timestamps + severity)EUUsed for session-level recommendations (`APPROVE` / `SPOT_CHECK` / `INVESTIGATE` / `VOID`). Disabled by default per section.
Secondary AI provider (US tier)SameUSUsed only when a tenant explicitly opts in. Customer-supplied API key in this mode; no per-tenant data crosses our backend.

Email and notifications

Sub-processorWhat they processHosting locationNotes
Transactional emailOutbound email to tenant admins and reviewers (magic links, alerts, breach notifications)EUUsed only for service emails. We do not send candidate-facing email from this system.

Observability and error reporting

Sub-processorWhat they processHosting locationNotes
Application performanceAnonymised request traces, error counts, slow queriesEUNo candidate PII, no session payloads, no event codes. Tenant id present.
Log aggregationServer logs, anonymisedEU30-day retention. Candidate id is the opaque session id, not PII.
Uptime monitoringEndpoint reachabilityEUNo customer data leaves our network.

Customer support tooling

Sub-processorWhat they processHosting locationNotes
Support inboxInbound email from customers, support ticketsEUUsed only for tickets that customers send to support addresses.
Internal wikiInternal runbooksEUNot customer-facing.

Billing and payments

Sub-processorWhat they processHosting locationNotes
Payment processorCard details, billing address, invoice historyEUUsed only for customer billing. Candidate data never touches this processor.

How we notify you of changes

We publish a sub-processor change notice to:
  • `[email protected]` subscribers (sign up by emailing
  • The in-app admin notification centre for tenant administrators.
[email protected] with subject subscribe to sub-processor changes).
  • The in-app admin notification centre for tenant administrators.
Notice is given at least 30 days before any new sub-processor is engaged for processing that affects customer or candidate data. If a change is required to address an incident or a security finding, we notify as soon as is reasonably practical, with the reasoning documented in the notice.

Right to object

If a sub-processor change is unacceptable for your deployment, you may terminate the relevant order form within the 30-day notice window and we will refund any pre-paid, unused fees on a pro-rata basis. If you require a sub-processor-free deployment, ask us about the EU-only single-tenant option.

Sub-processors we no longer use

For audit-trail purposes, the following sub-processors were previously listed and have since been retired:

  • (none retired since first publication of this page.)

Contact

For questions about a specific sub-processor, a sub-processor change, or to subscribe to change notifications:


Last updated: 2026-09-22 Next scheduled review: 2026-12-22 (quarterly)

Ready to Get Started?

Start a free trial and run real sessions against your own application, try the interactive demo in your browser, or contact us for a walkthrough tailored to your program.