Public-facing subprocessor list per the KURAL Data Processing Agreement, Schedule 2. Last reviewed 2026-05-15.
| Name | Purpose | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Hetzner Online GmbH Hetzner Online GmbH, Gunzenhausen, Germany | Primary hosting — compute, Postgres database storage, container runtime | All categories of Customer Personal Data processed under the DPA | EU only (Falkenstein DE primary, single-region today; Helsinki FI warm-standby on Q3 2026 roadmap) | Hetzner Auftragsverarbeitungsvertrag (AV) + ISO 27001 + GDPR-compliant DE jurisdiction; AES-256 at rest, TLS 1.3 in transit |
| Cloudflare, Inc. Cloudflare Germany GmbH (for EU traffic) + Cloudflare, Inc. (US) | DNS, CDN, WAF for kural.tech / app.kural.tech / api.kural.tech; object storage (R2 EU) for encrypted WAL archive | TLS-encrypted traffic metadata; encrypted database backups (age-encrypted before upload, Cloudflare never sees plaintext) | EU-only routing for kural.tech; R2 bucket in EU region | Cloudflare DPA + EU SCCs + ISO 27001 + SOC 2 Type II + EU Data Boundary opt-in |
| Anthropic, PBC Anthropic, PBC (USA) | Claude API for: (1) reg-change extraction from regulator-published text, (2) cert-PDF field extraction (Phase 2.5: rasterized images only — raw PDF bytes are never sent), (3) industry-news classification | Public regulator documents; rasterized cert-PDF images (operator-uploaded, operator-classified Tier-A or Tier-B data only); never raw KYC, SAR content, or identified player PII | US (Anthropic Commercial DPA + EU SCCs Module 3) | Anthropic Commercial Agreement + DPA + EU SCCs + zero-retention on the API tier we use; sub-processor list at trust.anthropic.com/subprocessors; Customer can opt out per-feature |
| DigiCert, Inc. DigiCert, Inc. (USA) | RFC 3161 trusted-timestamp authority for evidence-ledger anchors | SHA-256 digests of evidence records only — no payload; DigiCert never sees underlying data | US (digest-only, no SCC requirement under EDPB guidance — digests are not personal data) | RFC 3161 protocol; digests are one-way hashes; DigiCert provides only a signed timestamp token |
| FreeTSA.org FreeTSA.org (NGO operated under .at domain) | Secondary RFC 3161 trusted-timestamp authority for dual-anchor redundancy | SHA-256 digests of evidence records only | EU (no personal data transferred) | RFC 3161 protocol; redundant to DigiCert; digests are one-way hashes |
| Refinitiv (LSEG Data & Analytics) Refinitiv Limited (UK) / London Stock Exchange Group plc | World-Check One screening-list snapshots for AML / sanctions checks (operator-enabled) | Aggregate snapshot data + per-customer screening queries (when operator enables live mode) | UK / EEA | Refinitiv DPA + UK Adequacy; HMAC-SHA256 authentication; per-tenant credentials |
| GitHub, Inc. GitHub, Inc. (subsidiary of Microsoft Corporation) | Source code repository and CI; NCC Escode escrow deposits flow via GitHub | No Customer Personal Data — only KURAL source code + Escode deposits (encrypted) | EU & US | Microsoft DPA + EU-US Data Privacy Framework + UK IDTA |
| Atlassian Pty Ltd Atlassian Pty Ltd (Australia) — operator-side Jira Cloud tenant | Operator-initiated Jira Cloud integration: KURAL writes Findings as Jira issues into the operator's own Jira Cloud project. KURAL acts as caller; the operator's Atlassian tenant is the system of record. | Finding title + control_id + severity + remediation guidance only; never SAR content, KYC, or player PII (filtered server-side before write) | Operator-chosen Atlassian region (EU recommended; US if operator chooses) | OAuth 2.0 with operator-issued tokens (encrypted at rest in OperatorSecret); Atlassian DPA + EU SCCs apply between operator and Atlassian; KURAL never holds Atlassian platform-level credentials |
| Microsoft Corporation (Microsoft Graph) Microsoft Ireland Operations Ltd — operator-side M365 tenant | Operator-initiated M365 calendar push (/calendar OAuth) and SharePoint policy-library read (doc-sharepoint connector). KURAL acts as a delegated OAuth client to the operator's Entra ID tenant. | Calendar events with named owner + external contact; policy documents the operator has tagged as compliance-relevant. No raw mailbox content. | Operator's M365 geo (default EU) | OAuth 2.0 delegated permissions only; refresh tokens encrypted at rest in OperatorSecret; consent revocable at any time from the operator's Entra ID admin centre; Microsoft DPA + EU SCCs apply between operator and Microsoft |
Email privacy@kural.tech. We respond within 5 business days.