Sub-processor List
Last updated 13 August 2026
This page lists the third-party providers Glassbreak uses to operate the Service. We distinguish between infrastructure sub-processors (which handle encrypted Customer Data in some form, including ciphertext, metadata, and request-path data) and business sub-processors (which handle account or billing data but not Customer secret content).
Customers with an executed Data Processing Agreement may object to a proposed sub-processor on reasonable grounds during the 30 days' advance notice period described in section 13 of the Terms. The change log at the bottom of this page records every material change so customers can audit our sub-processor history.
Zero-knowledge boundary
All Customer secret content is encrypted on the user's device with AES-256-GCM under a key the user controls. Neither Glassbreak nor any sub-processor holds the decryption key. Sub-processors that handle Customer Data therefore handle ciphertext only— they cannot read the underlying secret, contact, or message content, even with full infrastructure access.
One deliberate exception sits at the delivery edge: sending an SMS or placing a voice call requires a plaintext phone number at the moment of dispatch. When an emergency notification fires, recipient numbers are handled in plaintext transiently by the delivery pipeline and passed to Twilio; they are not part of the encrypted contact store's at-rest guarantees during that window. Stored contact records themselves remain within the encrypted envelope described above.
A second exception sits on the call path. When two participants cannot connect directly, media is relayed through a TURN server. Glassbreak brokers across four interchangeable TURN vendors (Twilio, Cloudflare, Metered, Xirsys) and deliberately returns endpoints from at least two of them, so a single vendor incident cannot take calls down. A relay necessarily observes both participants' IP addresses and the timing and volume of the media it forwards. It does not observe content: call media is encrypted with a per-call AES-256-GCM key wrapped under the hybrid post-quantum KEM and applied via insertable streams, so the relay forwards ciphertext. Which vendor carries a given call is chosen at call setup and may change mid-call on failover. Calls that connect peer-to-peer use no relay at all, and the SFU used for larger calls is self-hosted on Glassbreak infrastructure rather than a third party.
For NAT discovery the client may also contact public STUN endpoints operated by Google, Cloudflare, Mozilla, and Nextcloud. A STUN exchange reveals only the client's public IP and port to that endpoint; no account data, no media, and no credentials are involved. These are listed for completeness rather than as processors of Customer Data.
Account-level personal data (email, name, billing address) is held in cleartext by definition, and is the subject of the GDPR / UK GDPR / CCPA controller-to-processor relationship between you and us (and between us and our sub-processors).
1. Infrastructure sub-processors
Some entries below are marked planned or candidate. Those process nothing today and, in most cases, we hold no account with them yet. They are listed so that a customer assessing us can see where we may go, not to imply a relationship that does not exist — and listing one here is not a substitute for the notice in section 4. If a candidate ever begins actually processing Customer Data, that is a material change to its role, and the 30 days' notice and right to object apply exactly as they would for a vendor we had never mentioned.
Amazon Web Services (AWS)
- Legal entity
- Amazon Web Services, Inc. (US) and its regional affiliates
- Role
- VM compute and block storage for the AWS box; Amazon SES for transactional email.
- Processing location
- us-east-1 (United States).
- Data categories
- Ciphertext only (encrypted Customer Data); account metadata; request-path metadata (IP, user agent) for audit logs; recipient email address for transactional mail via SES.
Scaleway
- Legal entity
- Scaleway SAS (France)
- Role
- VM compute and block storage for the Scaleway box; Scaleway Transactional Email (TEM). Hosts the EU-direct door (glassbreak.cloud).
- Processing location
- fr-par (Paris, EU).
- Data categories
- Ciphertext only (encrypted Customer Data); account metadata; request-path metadata (IP, user agent); recipient email address for transactional mail via TEM.
Tailscale
- Legal entity
- Tailscale Inc. (Canada)
- Role
- Private administrative network. The production boxes expose NO public SSH — Tailscale SSH is the only path by which staff or CI reach them, and it also carries the WireGuard mesh used for inter-box replication.
- Processing location
- Coordination plane in the US/Canada; traffic itself is peer-to-peer between our own hosts.
- Data categories
- No Customer Data. The coordination plane sees node identities, public keys and connection metadata for our own infrastructure and staff devices. Listed because it is the control path to systems holding Customer Data, which is material to anyone assessing our access controls.
DNS and domain registration
- Legal entity
- deSEC e.V. (Germany), Gandi SAS (France), Porkbun LLC (US), DNSimple Corporation (US), Scaleway SAS (France)
- Role
- Authoritative DNS and domain registration for the glassbreak.io, glass-break.com and glassbreak.cloud domains. Fastly additionally serves DNS for the Fastly-fronted properties.
- Processing location
- EU and US, per provider.
- Data categories
- None of Customer Data. Authoritative DNS answers queries from RESOLVERS, not from end users, so what these providers observe is resolver IP addresses and query names rather than the personal data of the people using the Service. We list them because they are part of the path by which the Service is reached, and because taking that position explicitly is better than leaving it to inference.
Backblaze
- Legal entity
- Backblaze, Inc. (US)
- Role
- Off-box, immutable backup storage (B2 with Object Lock) for the encrypted PostgreSQL backup repository, ACTIVE since 13 August 2026. Object Lock is what makes a backup that ransomware — or a compromised operator holding our own credentials — cannot delete or overwrite within its retention window. The repository also receives the continuous write-ahead-log stream, so point-in-time recovery is possible from the off-box copy rather than only recovery to the last full backup.
- Processing location
- Backblaze B2 EU Central (Amsterdam, Netherlands) — the bucket is sited in the EEA, so the encrypted backup repository does not leave it. Backblaze, Inc. is a US-incorporated company, so the VENDOR is US even though the STORAGE is EU; that distinction is deliberate here rather than glossed, because it is the parent entity, not the bucket, that determines who could be compelled to act. What such an order could yield is the repository as Backblaze holds it: ciphertext under a key we never send them.
- Data categories
- The encrypted backup repository only. pgBackRest encrypts the repository ON THE BOX, with a key of ours that Backblaze never receives, before anything is uploaded — so the contents are opaque to them exactly as they are to the cloud hosting the box. Backblaze additionally applies its own at-rest encryption (SSE-B2) with a key it creates and manages; that layer protects against loss of physical media and is NOT what makes the data unreadable to Backblaze — our pre-encryption is. Object Lock retains each object for 30 days by default.
Microsoft Azure
- Legal entity
- Microsoft Corporation (US)
- Role
- Japan (Tokyo) data-residency vertical (VM compute + block storage), ONBOARDING IMMINENT. Unlike the AWS and Scaleway boxes, which form one replicated cluster, this vertical runs hard-disconnected so that data entered through it stays in Japan.
- Processing location
- Japan (Tokyo). Japan is covered by a European Commission adequacy decision, so EEA transfers to this vertical require no supplementary transfer mechanism.
- Data categories
- Once live, the same scope as the other boxes: ciphertext only (encrypted Customer Data), account metadata, and request-path metadata (IP, user agent) for audit logs. Because the vertical is hard-disconnected, data entered through it is NOT replicated to the AWS or Scaleway boxes — that isolation is the point of it.
- Notes
- Onboarding imminent — provisioning is underway and this entry will move to fully active, with a change-log line, at or before the moment it first processes Customer Data. It processes none today.
Google Cloud Platform
- Legal entity
- Google Cloud EMEA Limited (Ireland) / Google LLC (US)
- Role
- Candidate additional cloud vertical, roughly the same scope as the AWS and Scaleway boxes if adopted.
- Processing location
- To be selected at onboarding.
- Data categories
- Would match the other boxes (ciphertext + metadata). Nothing today.
- Notes
- Candidate; not yet onboarded and no account in place.
IBM Cloud
- Legal entity
- IBM Corporation (US) and its regional affiliates
- Role
- Candidate additional cloud vertical, roughly the same scope as the AWS and Scaleway boxes if adopted.
- Processing location
- To be selected at onboarding.
- Data categories
- Would match the other boxes (ciphertext + metadata). Nothing today.
- Notes
- Candidate; not yet onboarded and no account in place.
Fastly
- Legal entity
- Fastly, Inc. (US)
- Role
- Multi-origin CDN, request routing (health-checked failover), DNS, TLS termination for glassbreak.io.
- Processing location
- Global edge; control plane in the US.
- Data categories
- Request-path metadata (IP, user agent, request URL). No body inspection. TLS is terminated at the edge; backends present their own certificates downstream.
Grafana Cloud
- Legal entity
- Grafana Labs (US)
- Role
- Observability platform: metrics, logs, traces, and dashboards for operating and securing the Service.
- Processing location
- Telemetry hosted in au-southeast-1 (Australia).
- Data categories
- Client IP addresses; request-path metadata (method, host, path, user agent, status); application and security logs that may include email addresses and user IDs in authentication and security events; PostgreSQL replication/pgaudit statement text (bound parameter values are NOT logged); and request traces. Never decrypted secret, contact, or message content (only operational data). Session tokens and passwords are redacted at the edge.
Twilio
- Legal entity
- Twilio Inc. (US)
- Role
- SMS and voice emergency-notification delivery; TURN relay for in-app calls (one of four interchangeable TURN vendors — see below).
- Processing location
- US / global carrier routing.
- Data categories
- Recipient phone numbers, message and call metadata, and delivery status. As a TURN relay: the IP addresses of both call participants and relayed media packets, which are end-to-end encrypted. Never Customer secret content.
Cloudflare
- Legal entity
- Cloudflare, Inc. (US)
- Role
- TURN relay for in-app calls (Cloudflare Realtime), and a STUN endpoint used for NAT binding discovery.
- Processing location
- Global anycast edge; control plane in the US.
- Data categories
- IP addresses of call participants and relayed media packets. Media is end-to-end encrypted with a per-call AES-256-GCM key wrapped under the hybrid KEM, so a relay never sees plaintext audio or video. No account data.
- Notes
- Cloudflare was removed as a CDN/DNS provider in May 2026 and re-onboarded in a different, narrower role (TURN/STUN only) when multi-vendor call relay shipped.
Metered
- Legal entity
- Metered Inc. (US)
- Role
- TURN relay for in-app calls (one of four interchangeable TURN vendors).
- Processing location
- Global relay footprint; control plane in the US.
- Data categories
- IP addresses of call participants and relayed media packets (end-to-end encrypted). No account data.
Xirsys
- Legal entity
- Xirsys LLC (US)
- Role
- TURN relay for in-app calls (one of four interchangeable TURN vendors).
- Processing location
- Global relay footprint; control plane in the US.
- Data categories
- IP addresses of call participants and relayed media packets (end-to-end encrypted). No account data.
2. Business sub-processors
Stripe
- Legal entity
- Stripe, Inc. (US) / Stripe Payments Europe Ltd (Ireland)
- Role
- Payment processing, subscription billing, invoice issuance. Billing is not yet live (early access).
- Processing location
- Global (per Stripe routing); EU customers processed via Stripe Payments Europe Ltd.
- Data categories
- Account email, billing name, billing address, tax ID, card data (held by Stripe, not by Glassbreak), subscription state.
Plausible Analytics
- Legal entity
- Plausible Insights OÜ (Estonia)
- Role
- Privacy-respecting, cookie-free website analytics.
- Processing location
- EU (Estonia/Germany).
- Data categories
- Aggregate, anonymous traffic metrics. No cookies, no cross-site tracking, no IP storage, no personal identifiers.
PostHog
- Legal entity
- PostHog, Inc. (US)
- Role
- Product analytics for the PUBLIC MARKETING SITE ONLY (glassbreak.io and its backup doors): which pages lead to sign-ups, and referral attribution. PLANNED — shipped dark, not yet in service. Never loaded on the secure application (app.{door}), where Customer Data is decrypted in the browser; a test in the web build fails if the secure app ever references it.
- Processing location
- EU Cloud (Frankfurt, Germany). The vendor is a US company; the SCC (Module 2) terms in the DPA apply to the entity relationship.
- Data categories
- Aggregate, anonymous marketing-site traffic: page views, referrer, campaign (utm) parameters, browser and device family, country-level location, and the marketing site's own conversion events (for example a call-to-action click). Cookieless mode — no cookies, nothing stored on the device, no persistent identifier, no person profiles. No session recording, heatmaps, autocapture, surveys, feature flags or error reports; the tracker cannot fetch code or configuration from PostHog at runtime. Events reach PostHog only through our own api.{door} proxy, which truncates the IP address (IPv4 /24, IPv6 /48) and forwards nothing but the event payload and user agent; page addresses are stripped to campaign parameters before they leave the browser; Global Privacy Control and Do Not Track are honoured by not loading the tracker at all. No account email address or other personal identifier is ever sent. No Customer Data.
- Notes
- Planned. Advance notice given 31 August 2026 (this entry and the change log). The tracker ships dark — no project key is baked into the marketing bundle — and will not be enabled before 1 October 2026. The 30 days' notice and right to object in section 6 of the DPA apply. Plausible remains in place; this does not replace it.
GitHub
- Legal entity
- GitHub, Inc. (US) — Microsoft subsidiary
- Role
- Source code hosting, issue tracking, CI/CD via GitHub Actions, container registry.
- Processing location
- US.
- Data categories
- Glassbreak's own source code and CI metadata. No Customer Data is sent to GitHub. Public-disclosure security reports may be filed here at the reporter's request.
1Password
- Legal entity
- AgileBits Inc. (Canada)
- Role
- Internal secrets management for Glassbreak staff (infrastructure credentials, signing keys).
- Processing location
- AWS (US/EU).
- Data categories
- Glassbreak operational credentials only. No Customer Data. Listed for completeness — relevant to security posture, not to customer data processing.
3. International data transfers
Where personal data originating in the EEA, the United Kingdom, or Switzerland is transferred to a country that has not been the subject of an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) Module 2, the UK International Data Transfer Addendum (UK IDTA), and the Swiss FADP addendum, as applicable. The current SCC module is the 2021 Commission Implementing Decision (EU) 2021/914.
Customers subject to strict data residency requirements may access the Service via the glassbreak.cloud door, which routes directly to the EU (Scaleway, fr-par) box. Because the two boxes form a single replicated cluster — data is replicated to both boxes, and the primary writer may run on the AWS (US) box — writes may transit to, and are stored on, the US box. Full EU-only data residency, with writes isolated to the EU, is delivered by our Enterprise EU data-residency zone, which is currently in rollout. See /technology/distributed for the box architecture.
4. Change log
We update this page whenever a sub-processor is added, removed, or has its role materially changed. The change log is append-only: removed sub-processors stay in the history with the date of removal. Customers with an executed DPA receive notice by email at least 30 days before any material change takes effect.
- 2026-08-31 — PostHog added as a PLANNED business sub-processor for the public marketing site only, with 30 days' advance notice: it will not be switched on before 1 October 2026, and until then the tracker ships dark (no project key in the bundle). Purpose: per-page conversion and referral attribution that the Plausible setup cannot give us per visit. The configuration is deliberately narrow and is enforced in code and tests rather than by policy alone — PostHog EU Cloud (Frankfurt); cookieless mode with no cookies, no device storage and no persistent identifier; no session recording, heatmaps, autocapture, surveys, feature flags or error capture; no runtime loading of code or configuration from PostHog; every event relayed through our own api.{door} proxy with the IP truncated to a /24 (IPv6 /48) and non-campaign query parameters stripped; Global Privacy Control and Do Not Track honoured by not loading the tracker at all. It is never loaded on the secure application (app.{door}), where Customer Data is decrypted — a test fails the web build if the secure app ever references it. No Customer Data and no account identifiers are involved. Plausible stays.
- 2026-08-13 — Microsoft Azure moved from planned to IMMINENT: the Japan (Tokyo) data-residency vertical is being provisioned. It processes no Customer Data yet, and this entry will move to fully active at or before the moment it does. Unlike the AWS and Scaleway boxes, which form one replicated cluster, the Tokyo vertical runs hard-disconnected — data entered through it stays in Japan and is not replicated to the US or EU boxes. The region was changed from Singapore to Tokyo before any provisioning carried Customer Data: Japan holds a European Commission adequacy decision and Singapore does not, so the Tokyo siting removes the need for standard contractual clauses and a transfer risk assessment on EEA data routed to this vertical.
- 2026-08-12 — Backblaze is now ACTIVE. The first off-box backup completed on 13 August 2026 (a full backup plus the continuous write-ahead-log stream), so the encrypted repository is held off-box from that date. Previously recorded as ONBOARDING — configured but NOT yet in service, holding no data: off-box immutable backup storage (B2 with Object Lock, 30-day default retention) in EU Central (Amsterdam) for the encrypted PostgreSQL backup repository. The repository is encrypted on the box before upload with a key Backblaze never receives; Backblaze also applies its own SSE-B2 at-rest encryption with a key it manages, which guards against media loss rather than against Backblaze. An earlier version of this entry described Backblaze as ACTIVE and said this closed the off-box backup gap. It did not: the off-box repository was still being built at that point and the backup repository remained on the box. Corrected here rather than left to stand, and this entry will move to active only once a backup has demonstrably landed off-box.
- 2026-08-12 — Tailscale added as an infrastructure sub-processor. The production boxes expose no public SSH, so Tailscale is the ONLY administrative path to systems holding Customer Data — it processes none of that data itself, but omitting the control path from a list meant to describe how the Service is operated was a gap. DNS and domain registration providers (deSEC, Gandi, Porkbun, DNSimple, Scaleway) are now listed with an explicit position: authoritative DNS answers resolvers rather than end users, so they see no Customer Data — stated deliberately rather than left to inference. Google Cloud and IBM Cloud added as CANDIDATES (nothing processed, no account in place) for advance visibility; a candidate that later begins processing is a material change of role and still carries the 30 days notice and right to object.
- 2026-08-10 — Call-relay disclosure corrected. The TURN vendors that carry relayed call media — Twilio (already listed for SMS/voice), Cloudflare, Metered, and Xirsys — are now listed individually, along with the public STUN endpoints used for NAT discovery. Cloudflare had been recorded as removed in May 2026; it was subsequently re-onboarded in a narrower TURN/STUN-only role when multi-vendor call relay shipped, and that change was not reflected here at the time. No new category of data was ever sent to these vendors beyond the relayed (end-to-end encrypted) media and participant IP addresses now described above. The planned Azure box is confirmed as a data-residency vertical rather than a location-TBD third box.
- 2026-07-10 — Updated to the single-box architecture: Neon (managed Postgres) removed — each box now runs its own in-box PostgreSQL kept in sync by native streaming replication. Postmark removed; transactional email is now Amazon SES (AWS box) and Scaleway TEM. Grafana Cloud (observability, telemetry hosted in Australia) and Twilio (SMS/voice notifications) added. Planned third cloud changed from Fly.io/GCP to Microsoft Azure.
- 2026-05-26 — Initial publication of this standalone sub-processor list. Bunny CDN and Cloudflare removed (no longer in use).
5. Contact
Questions or objections about a specific sub-processor: legal@glassbreak.io. General privacy enquiries: privacy@glassbreak.io.
This page is part of Glassbreak's Terms and Conditions and Privacy Policy by reference. It is provided for transparency and does not constitute legal advice.