Subprocessors
These third parties process data on behalf of Proveground. GDPR Article 28 + Article 33.
Proveground Sub-Processor Registry
Version: 1.2 Last Updated: August 1, 2026 Last Reviewed: August 1, 2026 Document Owner: Privacy & Security Team Contact: privacy@proveground.com
1. Purpose
This registry documents all third-party sub-processors that process personal data on behalf of Proveground (Street2Ivy, Inc.) in connection with the Proveground platform. This registry is maintained in compliance with our Data Processing Agreements (DPAs) with institutional clients and applicable data protection regulations including FERPA, CCPA/CPRA, and GDPR.
2. Sub-Processor Registry
| # | Vendor | Legal Entity | Purpose | Data Categories Processed | Data Region | DPA Status | Security Certifications | Date Added |
|---|---|---|---|---|---|---|---|---|
| 1 | Amazon Web Services (AWS) | Amazon Web Services, Inc. | Application hosting (Elastic Beanstalk), compute, RDS PostgreSQL, S3 object storage, CloudFront CDN, KMS, Secrets Manager, CloudWatch logging | All application data (student PII, academic records, application data, AI conversations, audit logs), encrypted at rest via KMS/AES-256 and in transit via TLS 1.2+ | us-east-2 (Ohio); CloudFront edge locations (global) | AWS DPA (standard) | SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, FedRAMP High, PCI DSS, HIPAA | Feb 2024 |
| 2 | Anthropic | Anthropic PBC | AI processing — career coaching, resume review, match insights, portfolio intelligence, listing optimization | Student profiles, skills, project descriptions, conversation content, academic context | United States | Custom DPA executed | SOC 2 Type II | Mar 2024 |
| 3 | Cloudinary | Cloudinary Ltd. | Media storage and transformation — profile photos, portfolio images, uploaded documents | Uploaded images, documents, videos, file metadata | US-East-1 (AWS) | Cloudinary DPA (standard) | SOC 2 Type II, ISO 27001 | Feb 2024 |
| 4 | Sentry | Functional Software, Inc. | Application error monitoring and performance tracking | Error stack traces, request metadata, browser/OS info (PII scrubbed by policy) | US (GCP us-central1) | Sentry DPA (standard) | SOC 2 Type II | Feb 2024 |
| 5 | Redis Labs | Redis Ltd. | In-memory caching — session management, rate limiting, account lockout tracking | Session tokens, rate limit counters, lockout state (no direct PII) | US-East-1 (AWS) | Redis Enterprise Cloud DPA | SOC 2 Type II, ISO 27001 | Feb 2024 |
| 6 | GitHub | GitHub, Inc. (Microsoft Corporation) | Source code repository, CI/CD pipeline | Application source code only — no customer data stored in GitHub | United States | GitHub DPA (standard) | SOC 1/2, ISO 27001, FedRAMP | Feb 2024 |
| 7 | Slack | Salesforce, Inc. (via Slack Technologies, LLC) | Engineering operational alerting — cost-circuit alarms, propose_new_component feature-request notifications, deployment + security signal routing via SLACK_DEPLOY_WEBHOOK_URL | Operational metadata only — tenant subdomain, user IDs, aggregate event counts, proposal name + purpose text. No student PII, no credentials, no transcript content. Outbound webhook only; Slack does not receive customer data. | US (Salesforce infrastructure) | Salesforce DPA (standard — covers Slack) | SOC 2 Type II, ISO 27001, FedRAMP Moderate | Apr 2026 |
| 8 | Amazon SES | Amazon Web Services, Inc. | Transactional email delivery — account verification, password reset, MFA codes, invitations, application and messaging notifications, endorsement requests | Recipient email addresses and message contents | us-east-2 (Ohio) | Covered by the AWS DPA already in force — no separate agreement | SOC 2 Type II, ISO 27001, HIPAA-eligible | Apr 2026 |
| 9 | Stripe | Stripe, Inc. | Payment processing — subscription billing and one-time purchases | Purchaser email address (student or institutional billing contact), organization name, plan and subscription metadata. Card data is entered directly into Stripe-hosted Checkout and never transits Proveground systems. | United States | Stripe DPA (standard) | PCI DSS Level 1, SOC 1/2 Type II, ISO 27001 | Apr 2026 |
| 10 | Splunk | Splunk LLC (Cisco Systems, Inc.) | SIEM — audit log aggregation, retention, and security monitoring | Audit event payloads: event type, pseudonymous user ID, tenant ID, timestamp, request metadata. No credentials or transcript content. | United States | Splunk DPA (standard) | SOC 2 Type II, ISO 27001 | Apr 2026 |
| 11 | Microsoft 365 | Microsoft Corporation | Workforce identity provider, email, and document collaboration | Workforce identifiers and internal documents. No student, applicant, or institutional customer data. | United States | Microsoft Product Terms DPA | SOC 1, SOC 2, ISO 27001 | Jul 2026 |
| 12 | Drata | Drata Inc. | GRC platform — continuous SOC 2 control monitoring and evidence collection | Control telemetry, sub-processor registry contents, personnel compliance metadata. No institutional or applicant data. | United States | Drata DPA (standard) | SOC 2 Type II | Apr 2026 |
2.1 Internal-Only Third Parties (Not Sub-Processors)
The following vendors support Proveground's internal operations and do not process student, applicant, or institutional customer data:
- Snyk — dependency and container vulnerability scanning against the application repository, integrated through Drata. Receives source code only.
- 1Password — workforce credential management. Verified by the Drata Agent on workforce devices.
3. Privacy Policy Links
| Vendor | Privacy Policy | DPA / Data Terms |
|---|---|---|
| AWS | https://aws.amazon.com/privacy/ | https://d1.awsstatic.com/legal/aws-dpa/aws-dpa.pdf |
| Anthropic | https://www.anthropic.com/privacy | Custom DPA (on file) |
| Slack / Salesforce | https://slack.com/trust/privacy/privacy-policy | https://slack.com/trust/compliance/slack-data-processing-addendum |
| Cloudinary | https://cloudinary.com/privacy | https://cloudinary.com/dmca |
| Sentry | https://sentry.io/privacy/ | https://sentry.io/legal/dpa/ |
| Redis Labs | https://redis.com/legal/privacy-policy/ | https://redis.com/legal/cloud-tos/ |
| GitHub | https://docs.github.com/en/site-policy/privacy-policies | https://github.com/customer-terms/github-data-protection-agreement |
| Amazon SES | https://aws.amazon.com/privacy/ | Covered by the AWS DPA |
| Stripe | https://stripe.com/privacy | Standard DPA (on file) |
| Splunk | https://www.splunk.com/en_us/legal/privacy-policy.html | Standard DPA (on file) |
| Microsoft 365 | https://privacy.microsoft.com/privacystatement | Standard DPA (on file) |
| Drata | https://drata.com/privacy | Standard DPA (on file) |
4. Change Notification Process
Adding a New Sub-Processor
- Proveground evaluates the sub-processor's security posture (certifications, DPA terms, data handling practices)
- A DPA is executed with the new sub-processor before any data processing begins
- This registry is updated with the new sub-processor details
- All institutional clients with active DPAs are notified via email at least 14 calendar days before the new sub-processor begins processing data
- The notification includes: sub-processor name, purpose, data categories, region, and effective date
Removing a Sub-Processor
- Data processing with the sub-processor is terminated
- Confirmation of data deletion/return is obtained from the sub-processor
- This registry is updated
- Clients are notified of the removal within 30 days
5. Objection Procedure
Institutional clients may object to a new sub-processor within 14 calendar days of receiving the change notification:
- Submit objection in writing to privacy@proveground.com
- Proveground will work with the client to address concerns, which may include:
- Providing additional information about the sub-processor's security controls
- Implementing additional contractual safeguards
- Offering an alternative processing arrangement
- If the objection cannot be resolved within 30 days, either party may terminate the affected services with 60 days' written notice
- No new sub-processor will process data for an objecting client until the objection is resolved
6. Annual Review Process
- Frequency: This registry is reviewed quarterly and updated as needed
- Scope: Review includes verification of DPA status, certification currency, and data handling practices
- Responsible party: Privacy & Security Team
- Audit rights: Institutional clients may request evidence of sub-processor compliance as part of their audit rights under the DPA
7. Version History
| Version | Date | Changes | Author |
|---|---|---|---|
| 1.0 | April 12, 2026 | Initial registry publication | Privacy & Security Team |
| 1.1 | April 22, 2026 | Removed Section 4 (Data Flow Summary) — redundant with Section 2 table; kept maintenance surface in sync on one canonical source. | Privacy & Security Team |
| 1.2 | August 1, 2026 | Removed the previously listed hosting sub-processor — decommissioned, data destruction confirmed; removal processed under §4. Corrected the primary data region to us-east-2 (Ohio); the prior entry incorrectly listed Virginia (US-East-1) as the region. Added Amazon SES, Stripe, Splunk, Microsoft 365 and Drata, which were processing data without being listed. Added §2.1 internal-only third parties (Snyk, 1Password). Aligned this registry with the institutional Appendix A so both state the same vendors and the same data categories. Sub-processor addition notice stated consistently as 14 calendar days. | Privacy & Security Team |
For questions about this registry or our sub-processor management practices, contact privacy@proveground.com.
Last updated: August 31, 2026
Changes: we notify registered users at least 14 days before adding a new subprocessor at support@proveground.com.
Last updated: February 23, 2026