SUBPROCESSORS

1ProNAS Service Providers

This list identifies external providers used or planned for controlled production. It must be updated before each material provider change.

Controlled-production policy draft dated 3 August 2026. Final legal review and jurisdiction-specific amendments are required before unrestricted paid commercial launch.

Current and planned providers

ProviderPurposeData involved
MailtrapTransactional OTP, alert and support email deliveryEmail address, sender/recipient details and message content
StripeCheckout, subscriptions, invoices and Customer PortalBilling identity, customer/subscription identifiers and payment information handled by Stripe
CloudflareDNS, CDN, WAF, TLS edge and DDoS protectionNetwork requests, IP addresses, headers and security events
Tokyo infrastructure providerPrimary APAC application, API, database and cache hostingEncrypted application, account, operational and tenant data
German infrastructure providerRecovery environment and encrypted backup storageEncrypted backups and recovery copies
GitHubPrivate source control and release workflowSource code, issues and non-secret development records

Provider controls

Provider access must be limited to what is necessary. Secrets must remain outside Git. Contracts, data-processing terms, regions, retention, breach notification and deletion capabilities should be reviewed before unrestricted commercial launch.

AI providers

Kimi or another external AI provider is not enabled for customer operational data by default. Documentation-only assistance may be activated separately. Client file content, metadata or operational context must not be sent to an AI provider without an approved purpose, tenant setting and documented data treatment.

Changes

Material provider changes should be published on this page before or promptly after activation, subject to emergency security requirements. Clients requiring advance notice should use a written enterprise agreement.