Skip to main content
Encypher Logo

Trust and privacy

Subprocessors

The limited third parties that help Encypher deliver secure content authenticity services.

Last Updated: August 10, 2026

This page lists the third parties in our current service setup and what each one does. Listing them here does not promise any contract terms, notice period, or data location. Those promises apply only when they are written into a signed agreement.

To subscribe to subprocessor change notifications, email privacy@encypher.com. This page is referenced by our Privacy Policy and Terms of Service.

Current Subprocessors

SubprocessorService providedCategories of data processed
RailwayApplication hosting and infrastructureService data stored in our database, application logs, performance metrics
CloudflareCDN, DNS, network security and DDoS mitigationConnection and request metadata, IP addresses, security/traffic logs
Google CloudCloud infrastructure and key management (KMS)Cryptographic key material and key metadata; key management is engaged only where a customer enables personal-identity keys
StripePayment processing and billingBilling identity and organization details, payment and transaction status, transaction IDs (card data is held by Stripe; Encypher does not store card numbers)
ZohoCRM, billing records, and transactional email (SMTP), including browser-extension signup verification codes and operational notificationsAccount and contact details, billing records, email addresses (including extension-signup recipient addresses), transactional email content
Google AnalyticsMarketing-website analytics onlyOnline identifiers and usage events on our marketing website, loaded only after cookie consent; not used on the authenticated signing/verification Service

Independent Parties (Not Subprocessors of Personal Data)

SSL.com provides certificate authority services under its own Certificate Policy and Certification Practice Statement. Its legal role and data terms depend on the service flow and the agreements in place.

Hosting and data location

Service providers may process data wherever they operate. This page does not promise EU-only, or any other fixed data location. A specific data location applies only when your signed contract confirms it.

What We Do Not Do

  • We do not send Customer Content to advertising, content-licensing, or AI-training third parties.
  • Enterprise and compliance content is never indexed for coalition licensing.
  • The subprocessors above support hosting, network/CDN, payments, CRM and email, marketing-website analytics, and (conditionally) key management only.
  • Google Analytics runs only on our marketing website, only after affirmative cookie consent, and is not loaded on the authenticated Service.

Changes

We update this page when our service setup changes. Email privacy@encypher.com to ask about change notices. We do not promise a notice period unless your signed agreement states one.