CLAVITORBlack-box credential issuance
Sign in Get free forever Get started

Legal

Subprocessors

Third parties that process data on behalf of Clavitor. All are GDPR-compliant and contractually bound to data protection standards equivalent to our own.

01
Infrastructure & hosting

Clavitor operates 21 Points of Presence (POPs) across six continents. Your vault data is stored encrypted at the POP nearest to you, with backups to geographically distant POPs for resilience. See the Looking Glass for the complete list of POPs with locations and latency.

ProviderPOPsScopeData typeCertifications
Amazon Web Services, Inc.
410 Terry Ave N, Seattle, WA, USA
17Primary provider for most regionsEncrypted vault data, metadata, logsSOC 2 Type II, ISO 27001, GDPR
Webrain OÜ (is*hosting)
Tallinn, Estonia
3Istanbul, Almaty, BogotáEncrypted vault data — regional POPsRegional compliance
Host Africa (Pty) Ltd
12 Helena Avenue, Somerset West, South Africa
1LagosEncrypted vault data — regional POPRegional compliance
Hostkey B.V.
Willem Frederik Hermansstraat 91, Amsterdam, Netherlands
--Zürich HQAdministrative operations, billing infrastructureISO 27001, GDPR
Cloudflare, Inc.
101 Townsend Street, San Francisco, CA, USA
--Global DNS resolutionDomain resolution only — no vault dataSOC 2 Type II, ISO 27001, GDPR
02
Payment processing
ProviderFunctionData processedCertifications
Paddle.com Market Ltd
Judd House, 18-29 Mora Street, London, UK
Subscription billing, payment processingPayment method (tokenized), billing address, invoice dataPCI DSS Level 1, SOC 2 Type II, GDPR
03
Communications & services
ProviderFunctionData processedCertifications
Proton AG
Route de la Galaise 32, Plan-les-Ouates, Geneva, Switzerland
Transactional emailEmail address, vault-related notificationsGDPR, Swiss FADP
Cloudflare, Inc.
101 Townsend Street, San Francisco, CA, USA
DNS resolutionDomain queries only — no vault data ever touches CloudflareSOC 2 Type II, ISO 27001, GDPR
04
What we don't use

We deliberately avoid common subprocessors that compromise privacy:

  • No Google: No Analytics, no Fonts, no reCAPTCHA, no Firebase
  • No Meta/Facebook: No tracking pixels, no social plugins
  • No third-party CDNs: All assets served from our own POPs (Cloudflare is DNS-only, never proxy/CDN)
  • No marketing platforms: No Mailchimp, HubSpot, or similar
  • No cloud logging: Logs stay within our infrastructure
05
Updates

We notify all active subscribers 30 days before adding any new subprocessor. For critical security updates, shorter notice may apply with immediate notification.

Last updated: May 2026