SECURITY // LEVEL 5 SECURITY LIST

Authorized Subprocessors

This register details the authorized third-party subprocessors who process personal data on behalf of Consent Shield operators under strict Data Processing Addendum (DPA) mandates.

Before onboarding any infrastructure or analytics partner, Consent Shield executes a exhaustive compliance vetting protocol. We evaluate transfer mechanism security, cryptographic protection at rest, geographic routing isolation, and operational standard compliance (ISO 27001, SOC 2 Type II).

[REG_03]

Current Approved Subprocessors

Entity Name Jurisdiction & Location Processing Purpose Data Elements Transferred
Amazon Web Services, Inc. United States / EU Regions Secure Cloud Hosting & Core Enclave Execution Encrypted Telemetry Logs, IP Coordinates, Session Identifiers
Google Cloud Platform (GCP) United States / EU Regions Analytical Compute, BigQuery Storage & ML Processing Aggregated Tracking Metrics, Risk Scores, System Logs
Cloudflare, Inc. Global CDN / US & EU Points DDoS Protection, Web Application Firewall & Edge Cache Routing Network Headers, IP Address, TLS Cipher Metadata
Stripe, Inc. United States Payment Processing & Invoice Lifecycle Infrastructure Credit Card Tokens, Corporate Address, Invoice Identifiers
Twilio, Inc. (SendGrid) United States System Notification SMTP & Authentication Routing Operator Email Addresses, Dynamic OTP Tokens, Security Digests
Datadog, Inc. United States / EU (Isolated) Core Network Monitoring, Logs, & Application APM Metrics System Latency Reports, Infrastructure Logs (Anonymized)

DPA Mandates & Geographic Restrictions

Under our standard Operator Data Processing Addendum, EU sovereign customers can enforce strict regional localization configurations. When active, our model isolates AWS/GCP routing exclusively to Dublin (eu-west-1) and Frankfurt (eu-central-1) regions, with no secondary replication or transit permitted outside European Union borders.