Processors supporting MandateShield
| Provider | Purpose | Data | Regions / safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Application delivery, edge security and D1 database hosting | Account, contract, request, API metadata, evidence and security data | Global network; configured service regions. Provider terms and applicable transfer safeguards. |
| OpenAI, L.L.C. and applicable affiliates | ChatGPT sign-in and hosted application distribution | Sign-in identity and application request context | United States and other documented service regions. Provider terms and applicable transfer safeguards. |
This list identifies operational roles based on the deployed architecture; the exact contracting entity and transfer terms are controlled by the applicable provider account and agreement. The list is corrected when verified facts change.
Independent or customer-directed recipients
| Recipient | Purpose | Role |
|---|---|---|
| Stripe group entities | Checkout, subscriptions, invoices, tax and payment administration | Processor and/or independent controller depending on the Stripe function |
| Customer-selected payment, RPC and provider endpoints | Customer-directed provider verification and reconciliation | Independent recipient selected and configured by Customer |
| GitHub, Inc. | Public repository and exact-commit binding for optional Proof Network publication | Independent public service used by proof publishers |
Changes and objections
Customer gives general authorization for the listed subprocessors under the DPA. Where practicable, this page will be updated before a new provider begins materially different processing. A Customer may object on reasonable data-protection grounds through the legal contact in the Legal Notice. If no practical resolution exists, Customer may stop the affected service.