Legal / Sub-processors

Authorized Sub-processors

Last updated 3 October 2026.

Overview

Under Article 28 of the GDPR and our Data Processing Agreement, SafeGrd engages third-party service providers (“Sub-processors”) to run our service, store backups for customers who choose SafeGrd-hosted storage, run restore drills for customers who choose to run them on SafeGrd, and deliver account email.

SafeGrd reviews a Sub-processor's security and privacy practices before engaging it: its security certifications, its confidentiality obligations and its data protection terms, which must be no less protective than our own.

What Sub-processors Can See

Customer backup contents (database tables, files and mailbox messages) are compressed and encrypted on the customer’s own host before they leave it. Our object storage provider stores hosted backups only as that ciphertext.

With a SafeGrd-managed key, the default for each host, SafeGrd keeps that host’s Age private key, and any database or mailbox credential the customer asks us to hold, sealed: encrypted before it is written to our database, which runs on servers we rent from DigitalOcean. We release them only to the organization’s enrolled hosts, and the key also to a drill the organization runs on SafeGrd. For a host with a customer-managed key the private key never leaves that host.

For a surface with a SafeGrd-managed key, an organization can choose to run its restore drills on SafeGrd instead of on its own hosts. Each of those drills runs on a virtual machine of its own at Fly.io. The machine downloads one snapshot from SafeGrd-hosted storage, decrypts it with the key SafeGrd releases to that drill alone, restores it into a temporary database or reads it in memory, checks it, and reports the result. It runs nothing for any other organization or drill, and it is destroyed with its storage when the drill ends or reaches its time limit. Every key release to a drill is recorded in the organization’s key access record. The restored data never reaches our control plane.

An organization can also have SafeGrd take a database’s backups from a connection string it gives us to hold. Each of those backups runs on a virtual machine of its own at Fly.io, which is given the connection string for that backup alone, connects to the database, dumps it, encrypts it to the organization’s key and writes it to SafeGrd-hosted storage. The machine is never given the key, and it is destroyed when the backup ends. Every release of the connection string is recorded in the organization’s key access record. The dump never reaches our control plane.

The other Sub-processors process account data and technical metadata.

Current Sub-processors

Sub-processor Role / Activity Location Safeguards
DigitalOcean, LLC Cloud hosting infrastructure and managed data storage. United States EU–US Data Privacy Framework; Standard Contractual Clauses (SCCs)
Backblaze, Inc. Object storage for SafeGrd-hosted backups, as client-side encrypted ciphertext under compliance-mode object lock. Used only for customers who choose hosted storage. United States Standard Contractual Clauses (SCCs)
Fly.io, Inc. Compute for restore drills an organization runs on SafeGrd: one virtual machine per drill, in Ashburn, Virginia, destroyed when the drill ends. Used only for surfaces with a SafeGrd-managed key whose snapshot is in SafeGrd-hosted storage and whose surface is set to drill on SafeGrd. United States Standard Contractual Clauses (SCCs)
Mailtrap (Railsware Products Studio LLC) Delivery of account email: verification codes, password resets, invitations and backup alerts. United States Standard Contractual Clauses (SCCs)
Google LLC Website analytics on the public landing, documentation and legal pages, only for visitors who consent. Never loaded in the console or on sign-in and account pages. United States EU–US Data Privacy Framework; Standard Contractual Clauses (SCCs)

Independent Controllers

These are not Sub-processors: they decide how they use the data they receive, under their own privacy notices.

Company Role Location
Paddle.com Market Ltd Merchant of Record: sells the subscription, takes payment, and handles invoicing and tax. Paddle collects payment details itself. United Kingdom

Sub-processor Changes and Notification

SafeGrd maintains an up-to-date record of all Sub-processors on this page. When we plan to engage a new Sub-processor or replace an existing one, we will notify registered administrators by email at least thirty (30) days before granting that Sub-processor access to any Personal Data.

Customers with an active subscription may object to any new Sub-processor on reasonable data protection grounds by emailing support@safegrd.dev within thirty (30) days of receiving notification.