Legal
Sub-processors
Every third party that touches customer data, and what each one does.
- Version
- draft-2026-09-09
- Bundle
- draft-2026-09-09
- Permanent
- this page
- Status
- Draft - not in force
This is a permanent, dated copy of Sub-processors version draft-2026-09-09. It is never edited. The version currently in effect is at /legal/subprocessors.
The list
These are the third parties that process, or are contracted to process, data on behalf of FortressFlag LLC’s customers. It is transcribed from our internal record of processing activities and is the complete set — there is no separate “affiliates” or “infrastructure” list somewhere else.
| Sub-processor | What it processes | Purpose | Status |
|---|---|---|---|
| Amazon Web Services | Control-plane compute, the database, backups, secrets, and encryption keys — therefore all account data and all customer configuration — and, once email delivery is enabled, outbound transactional email through Amazon SES | Hosting the control plane; transactional email | Planned. No account exists yet and nothing is deployed. |
| Amazon CloudFront or Cloudflare | Feature-flag configuration delivered to customers’ applications | Data-plane delivery at the edge | Planned. By design the delivered payloads contain no personal data. |
| GitHub | Source code and continuous integration. No customer data. | Development and change management | In use. |
| Stripe | The purchasing owner’s email address, the organisation’s name and URL slug, and monthly device counts. Never device identifiers, flag configuration, or end-user data. Cardholder data is entered on Stripe’s own hosted pages and never reaches our systems. | Billing and payments | In use, test mode only. |
Notice of changes
Before a new or replacement sub-processor begins processing customer data we give notice in the product — a notice every member of an organisation sees when they sign in — and the objection process in section 3.5 of the Data Processing Agreement applies.
Notice is given in the product on purpose. It is the one channel every member of an organisation reliably has: a notice shown at sign-in cannot bounce, go to spam, or reach only a stale contact address.
What is deliberately not on this list
- Your identity provider. If your organisation uses SAML single sign-on or SCIM provisioning, that identity provider is your processor, not ours. We store its public metadata — an entity identifier, a sign-in URL and a signing certificate — and never act on its behalf.
- Analytics, advertising, session recording, customer messaging, support desks, error tracking. None are in use, in the marketing site or in the dashboard — support is handled inside the product by FortressFlag itself, with no third-party help desk. Adding one would be a sub-processor decision and would appear here first.
All five documents, and their versions, are listed at /legal.