Trust and privacy
Subprocessors
The limited third parties that help Encypher deliver secure content authenticity services.
Last Updated: August 10, 2026
This page lists the third parties in our current service setup and what each one does. Listing them here does not promise any contract terms, notice period, or data location. Those promises apply only when they are written into a signed agreement.
To subscribe to subprocessor change notifications, email privacy@encypher.com. This page is referenced by our Privacy Policy and Terms of Service.
Current Subprocessors
| Subprocessor | Service provided | Categories of data processed |
|---|---|---|
| Railway | Application hosting and infrastructure | Service data stored in our database, application logs, performance metrics |
| Cloudflare | CDN, DNS, network security and DDoS mitigation | Connection and request metadata, IP addresses, security/traffic logs |
| Google Cloud | Cloud infrastructure and key management (KMS) | Cryptographic key material and key metadata; key management is engaged only where a customer enables personal-identity keys |
| Stripe | Payment processing and billing | Billing identity and organization details, payment and transaction status, transaction IDs (card data is held by Stripe; Encypher does not store card numbers) |
| Zoho | CRM, billing records, and transactional email (SMTP), including browser-extension signup verification codes and operational notifications | Account and contact details, billing records, email addresses (including extension-signup recipient addresses), transactional email content |
| Google Analytics | Marketing-website analytics only | Online identifiers and usage events on our marketing website, loaded only after cookie consent; not used on the authenticated signing/verification Service |
Independent Parties (Not Subprocessors of Personal Data)
SSL.com provides certificate authority services under its own Certificate Policy and Certification Practice Statement. Its legal role and data terms depend on the service flow and the agreements in place.
Hosting and data location
Service providers may process data wherever they operate. This page does not promise EU-only, or any other fixed data location. A specific data location applies only when your signed contract confirms it.
What We Do Not Do
- We do not send Customer Content to advertising, content-licensing, or AI-training third parties.
- Enterprise and compliance content is never indexed for coalition licensing.
- The subprocessors above support hosting, network/CDN, payments, CRM and email, marketing-website analytics, and (conditionally) key management only.
- Google Analytics runs only on our marketing website, only after affirmative cookie consent, and is not loaded on the authenticated Service.
Changes
We update this page when our service setup changes. Email privacy@encypher.com to ask about change notices. We do not promise a notice period unless your signed agreement states one.