Subprocessors

These third parties process data on behalf of Proveground. GDPR Article 28 + Article 33.

Proveground Sub-Processor Registry

Version: 1.2 Last Updated: August 1, 2026 Last Reviewed: August 1, 2026 Document Owner: Privacy & Security Team Contact: privacy@proveground.com


1. Purpose

This registry documents all third-party sub-processors that process personal data on behalf of Proveground (Street2Ivy, Inc.) in connection with the Proveground platform. This registry is maintained in compliance with our Data Processing Agreements (DPAs) with institutional clients and applicable data protection regulations including FERPA, CCPA/CPRA, and GDPR.


2. Sub-Processor Registry

#VendorLegal EntityPurposeData Categories ProcessedData RegionDPA StatusSecurity CertificationsDate Added
1Amazon Web Services (AWS)Amazon Web Services, Inc.Application hosting (Elastic Beanstalk), compute, RDS PostgreSQL, S3 object storage, CloudFront CDN, KMS, Secrets Manager, CloudWatch loggingAll application data (student PII, academic records, application data, AI conversations, audit logs), encrypted at rest via KMS/AES-256 and in transit via TLS 1.2+us-east-2 (Ohio); CloudFront edge locations (global)AWS DPA (standard)SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, FedRAMP High, PCI DSS, HIPAAFeb 2024
2AnthropicAnthropic PBCAI processing — career coaching, resume review, match insights, portfolio intelligence, listing optimizationStudent profiles, skills, project descriptions, conversation content, academic contextUnited StatesCustom DPA executedSOC 2 Type IIMar 2024
3CloudinaryCloudinary Ltd.Media storage and transformation — profile photos, portfolio images, uploaded documentsUploaded images, documents, videos, file metadataUS-East-1 (AWS)Cloudinary DPA (standard)SOC 2 Type II, ISO 27001Feb 2024
4SentryFunctional Software, Inc.Application error monitoring and performance trackingError stack traces, request metadata, browser/OS info (PII scrubbed by policy)US (GCP us-central1)Sentry DPA (standard)SOC 2 Type IIFeb 2024
5Redis LabsRedis Ltd.In-memory caching — session management, rate limiting, account lockout trackingSession tokens, rate limit counters, lockout state (no direct PII)US-East-1 (AWS)Redis Enterprise Cloud DPASOC 2 Type II, ISO 27001Feb 2024
6GitHubGitHub, Inc. (Microsoft Corporation)Source code repository, CI/CD pipelineApplication source code only — no customer data stored in GitHubUnited StatesGitHub DPA (standard)SOC 1/2, ISO 27001, FedRAMPFeb 2024
7SlackSalesforce, Inc. (via Slack Technologies, LLC)Engineering operational alerting — cost-circuit alarms, propose_new_component feature-request notifications, deployment + security signal routing via SLACK_DEPLOY_WEBHOOK_URLOperational metadata only — tenant subdomain, user IDs, aggregate event counts, proposal name + purpose text. No student PII, no credentials, no transcript content. Outbound webhook only; Slack does not receive customer data.US (Salesforce infrastructure)Salesforce DPA (standard — covers Slack)SOC 2 Type II, ISO 27001, FedRAMP ModerateApr 2026
8Amazon SESAmazon Web Services, Inc.Transactional email delivery — account verification, password reset, MFA codes, invitations, application and messaging notifications, endorsement requestsRecipient email addresses and message contentsus-east-2 (Ohio)Covered by the AWS DPA already in force — no separate agreementSOC 2 Type II, ISO 27001, HIPAA-eligibleApr 2026
9StripeStripe, Inc.Payment processing — subscription billing and one-time purchasesPurchaser email address (student or institutional billing contact), organization name, plan and subscription metadata. Card data is entered directly into Stripe-hosted Checkout and never transits Proveground systems.United StatesStripe DPA (standard)PCI DSS Level 1, SOC 1/2 Type II, ISO 27001Apr 2026
10SplunkSplunk LLC (Cisco Systems, Inc.)SIEM — audit log aggregation, retention, and security monitoringAudit event payloads: event type, pseudonymous user ID, tenant ID, timestamp, request metadata. No credentials or transcript content.United StatesSplunk DPA (standard)SOC 2 Type II, ISO 27001Apr 2026
11Microsoft 365Microsoft CorporationWorkforce identity provider, email, and document collaborationWorkforce identifiers and internal documents. No student, applicant, or institutional customer data.United StatesMicrosoft Product Terms DPASOC 1, SOC 2, ISO 27001Jul 2026
12DrataDrata Inc.GRC platform — continuous SOC 2 control monitoring and evidence collectionControl telemetry, sub-processor registry contents, personnel compliance metadata. No institutional or applicant data.United StatesDrata DPA (standard)SOC 2 Type IIApr 2026

2.1 Internal-Only Third Parties (Not Sub-Processors)

The following vendors support Proveground's internal operations and do not process student, applicant, or institutional customer data:

  • Snyk — dependency and container vulnerability scanning against the application repository, integrated through Drata. Receives source code only.
  • 1Password — workforce credential management. Verified by the Drata Agent on workforce devices.

3. Privacy Policy Links


4. Change Notification Process

Adding a New Sub-Processor

  1. Proveground evaluates the sub-processor's security posture (certifications, DPA terms, data handling practices)
  2. A DPA is executed with the new sub-processor before any data processing begins
  3. This registry is updated with the new sub-processor details
  4. All institutional clients with active DPAs are notified via email at least 14 calendar days before the new sub-processor begins processing data
  5. The notification includes: sub-processor name, purpose, data categories, region, and effective date

Removing a Sub-Processor

  1. Data processing with the sub-processor is terminated
  2. Confirmation of data deletion/return is obtained from the sub-processor
  3. This registry is updated
  4. Clients are notified of the removal within 30 days

5. Objection Procedure

Institutional clients may object to a new sub-processor within 14 calendar days of receiving the change notification:

  1. Submit objection in writing to privacy@proveground.com
  2. Proveground will work with the client to address concerns, which may include:
  • Providing additional information about the sub-processor's security controls
  • Implementing additional contractual safeguards
  • Offering an alternative processing arrangement
  1. If the objection cannot be resolved within 30 days, either party may terminate the affected services with 60 days' written notice
  2. No new sub-processor will process data for an objecting client until the objection is resolved

6. Annual Review Process

  • Frequency: This registry is reviewed quarterly and updated as needed
  • Scope: Review includes verification of DPA status, certification currency, and data handling practices
  • Responsible party: Privacy & Security Team
  • Audit rights: Institutional clients may request evidence of sub-processor compliance as part of their audit rights under the DPA

7. Version History

VersionDateChangesAuthor
1.0April 12, 2026Initial registry publicationPrivacy & Security Team
1.1April 22, 2026Removed Section 4 (Data Flow Summary) — redundant with Section 2 table; kept maintenance surface in sync on one canonical source.Privacy & Security Team
1.2August 1, 2026Removed the previously listed hosting sub-processor — decommissioned, data destruction confirmed; removal processed under §4. Corrected the primary data region to us-east-2 (Ohio); the prior entry incorrectly listed Virginia (US-East-1) as the region. Added Amazon SES, Stripe, Splunk, Microsoft 365 and Drata, which were processing data without being listed. Added §2.1 internal-only third parties (Snyk, 1Password). Aligned this registry with the institutional Appendix A so both state the same vendors and the same data categories. Sub-processor addition notice stated consistently as 14 calendar days.Privacy & Security Team

For questions about this registry or our sub-processor management practices, contact privacy@proveground.com.

Last updated: August 31, 2026

Changes: we notify registered users at least 14 days before adding a new subprocessor at support@proveground.com.

Last updated: February 23, 2026