Saifuro
Reference

Subprocessors

Third parties that process data on our behalf, and what each one sees.

The third parties below process data on our behalf. The list lives here in public, so your security team can work through it before there is any conversation to have.

SubprocessorPurposeData processedLocation
Amazon Web ServicesHosting of the policy engine, decision log, and customer environmentsDecision records, policy configuration, agent identifierseu-central-1, Frankfurt
Amazon Web Services (SES)Transactional and support emailContact details of named customer contactseu-central-1, Frankfurt
VGSCard credential tokenization at the edgeCard data, before it reaches SaifuroEuropean Union
DatadogInfrastructure monitoring and operational loggingOperational telemetry and system logsEuropean Union
LinearSupport and engineering issue trackingContents of support requests raised by customer contactsUnited States

Agent conversation content is not collected by Saifuro, so it is not passed to any subprocessor. Primary account numbers never enter Saifuro systems, and the only entry above that sees them is VGS, where tokenization happens before data reaches us.

The decision log and policy configuration stay in the European Union. The only subprocessor outside it is Linear, which holds support correspondence and no decision data.

Changes to this list

We notify customers at least 30 days before a new subprocessor begins processing customer data, which leaves time to object under the data processing agreement signed at onboarding.

Data residency and retention

The current region is eu-central-1 in Frankfurt. Additional regions are available on request. Retention windows for the decision log are set per deployment and recorded in the data processing agreement, which is provided for review before signature. The log is exportable by you at any time.

Last reviewed: 20 August 2026.

On this page