AuditBadger AuditBadger

Legal

Data processors

Reviewed subprocessors used by AuditBadger to provide hosted application, communication, security, AI, and electronic signature services.

8 listed

Hetzner

Primary application hosting and infrastructure services.

European Union
Last reviewed 2026-06-03
Safeguards
GDPR Data Processing Agreement, EU data center operations for selected EU locations, access controls, and infrastructure security controls.
Data categories
  • Account content and metadata stored or processed by hosted application servers
  • User identifiers and authentication/session metadata
  • Application logs and operational telemetry
  • Uploaded compliance, evidence, and document content
Review notes
Hetzner hosts AuditBadger application infrastructure and may store or process customer application content, metadata, logs, and uploaded documents on AuditBadger's behalf.

Ubicloud

Managed PostgreSQL database hosting for application data.

European Union
Last reviewed 2026-06-03
Safeguards
Data Processing Agreement available for EEA managed services, region-bound customer content hosting, and infrastructure subprocessor controls.
Data categories
  • Account records and tenant configuration
  • User profile and authentication metadata
  • Compliance, evidence, document, training, vendor, and integration records
  • Application audit logs and operational metadata
Review notes
Ubicloud hosts AuditBadger managed PostgreSQL databases and processes customer tenant records, user metadata, audit logs, and compliance data on AuditBadger's behalf.

Mailgun

Outbound transactional email delivery.

European Union
Last reviewed 2026-06-03
Safeguards
GDPR-oriented processor terms, EU region message processing, TLS-supported email transport, and delivery platform security controls.
Data categories
  • Recipient email addresses
  • Sender and reply-to addresses
  • Email subject lines and message bodies
  • Delivery, suppression, and event metadata
Review notes
Mailgun receives outbound email content and recipient metadata generated by AuditBadger transactional and notification workflows.

Cloudflare

DNS hosting and protective network services for application domains.

Global network, with optional data localization controls depending on enabled Cloudflare services.
Last reviewed 2026-06-03
Safeguards
Cloudflare Data Processing Addendum, subprocessor obligations, security controls, transport encryption, and configurable data localization features where enabled.
Data categories
  • Domain names and DNS configuration
  • Technical request metadata and IP addresses where proxy or security features are enabled
  • Security logs and routing metadata
Review notes
Cloudflare provides DNS and protective network services for AuditBadger domains and may process technical request metadata where proxy or security services are enabled.

Anthropic

Large language model processing for AI-assisted compliance, training, document, and evidence workflows.

United States
Last reviewed 2026-06-03
Safeguards
Anthropic commercial Data Processing Addendum with SCCs, API data handling and retention commitments, and no model training on retained API data without express permission.
Data categories
  • Prompt inputs and context selected for AI workflows
  • Generated AI responses
  • Compliance, evidence, training, vendor, and document text supplied to AI workflows
  • Uploaded document text and extracted evidence content supplied to AI workflows
  • Account and user metadata included in prompts
Review notes
Anthropic receives prompt inputs, selected customer context, uploaded document text, evidence text, and generated outputs for AuditBadger AI-assisted workflows. AuditBadger has configured the provider relationship so API data is not used for model training where the applicable Anthropic commercial terms provide that control.

SignWell

Embedded electronic signature workflow and signed DPA audit trail.

United States
Last reviewed 2026-06-03
Safeguards
Encrypted document storage, e-signature audit trail, and contractual security commitments.
Data categories
  • Company legal name
  • Signer name
  • Signer title
  • Signer email
  • Generated Data Processing Agreement PDF
Review notes
SignWell receives generated DPA PDFs and signer metadata to provide embedded electronic signature, completion status, and signed-document audit trail services.

Linear

Customer-directed Linear integration for syncing AuditBadger compliance action items to Linear issues and collecting completed Linear issue metadata as change-management evidence.

Customer-selected Linear workspace. Linear supports United States or European Union workspace data regions; account and usage metadata may be processed in the United States under Linear's DPA.
Last reviewed 2026-06-03
Safeguards
Customer-controlled OAuth app authorization with read/write scopes, tenant-scoped credentials, signed webhook routing tokens, Linear-Signature verification, timestamp checks, token revocation on disconnect, and AuditBadger access controls for imported metadata.
Data categories
  • user identity
  • account metadata
  • action item titles, descriptions, due dates, labels, and AuditBadger links
  • Linear issue, team, status, assignee, creator, completion, attachment, and pull request metadata
Review notes
AuditBadger sends selected action-item titles, descriptions, due dates, labels, and AuditBadger links to Linear when a customer enables ticket sync; it also reads Linear issue and assignee metadata for evidence collection and status refresh. Because the connection is customer-authorized and points to the customer's Linear workspace, this remains a customer-directed integration review candidate rather than an automatically included AuditBadger DPA subprocessor.

Shortcut

Customer-directed Shortcut integration for syncing AuditBadger compliance action items to Shortcut stories and collecting completed Shortcut story metadata as change-management evidence.

Customer-selected Shortcut workspace; Shortcut service locations and subprocessors follow the customer's Shortcut agreement.
Last reviewed 2026-06-03
Safeguards
Customer-controlled API token authorization, tenant-scoped credentials, signed webhook routing tokens, Shortcut-Signature verification, timestamp checks, token removal on disconnect, and AuditBadger access controls for imported metadata.
Data categories
  • user identity
  • account metadata
  • action item titles, descriptions, deadlines, labels, and AuditBadger links
  • Shortcut story, workflow, team, owner, requester, completion, and pull request metadata
Review notes
AuditBadger sends selected action-item data to Shortcut only after the customer configures the integration, and reads Shortcut story metadata back for evidence collection. Because the connection is customer-authorized and points to the customer's Shortcut workspace, this remains a customer-directed integration review candidate rather than an automatically included AuditBadger DPA subprocessor.