Sub-processors
Atlas Logic uses the third parties below to deliver our service. Each is bound by a Data Processing Agreement that requires the same data-protection obligations we owe our customers. We review every sub-processor at least annually and on material change.
| Name | Category | Purpose | Data processed | Location | Transfer mechanism | Certifications |
|---|---|---|---|---|---|---|
| Microsoft Azure | Infrastructure & Hosting | Primary cloud infrastructure, AI Foundry model hosting, Key Vault, Blob Storage, Log Analytics |
| USA (primary); EU available | SCCs / DPF |
|
| MongoDB Atlas (Azure Cosmos DB-compatible) | Database & Storage | Compliance database, audit logs, evidence metadata, user records, subscription data |
| USA | SCCs |
|
| Anthropic (Claude API) | AI Processing | AI-powered compliance analysis, control recommendations, risk generation (via Azure AI Foundry proxy) |
| USA | DPA / SCCs |
Customer Data is contractually prohibited from use in model training. |
| xAI (Grok API) | AI Processing | AI analysis alternative provider, evidence review, chatbot responses |
| USA | DPA / SCCs |
EU/EEA Personal Data not routed via xAI until SCCs are executed; processed via Azure AI Foundry + Anthropic in the meantime. |
| Google OAuth 2.0 | Authentication | Identity provider, SSO authentication |
| USA | SCCs / DPF |
|
| Microsoft Entra ID | Authentication | Identity provider, SSO, MFA enforcement |
| USA / EU | SCCs |
|
| SendGrid (Twilio) | Email Delivery | Transactional email — invitations, breach notifications, subscription alerts |
| USA | SCCs |
|
| Stripe | Payments | Payment processing, subscription billing, partner commission payouts |
| USA | SCCs |
|
| GitHub | Code Integration | Code integration for evidence collection (Sentinel Enterprise plan) |
| USA | SCCs |
|
| AWS (optional) | Infrastructure & Hosting | Secondary infrastructure or customer-selected hosting region |
| Customer-selected | SCCs |
Activated only when a customer selects AWS as their hosting region. |
How we monitor them
We track certification status and incident notifications for every sub-processor, and we re-verify their reports (SOC 2, ISO 27001) on renewal. Material changes flow through our internal change-management process before going into effect.
Request DPAs or reports
Customers under NDA can request signed Data Processing Agreements and the underlying attestation reports for any sub-processor listed above.