Subprocessors
Last updated [DATE - SET AT PUBLICATION]
A subprocessor is a company Marshal uses to help run the service, which may process customer data in the process. This page is referenced by the data processing addendum and forms part of it. [COUNTRY OF PROCESSING AND ENTITY DETAILS FOR EACH ROW - COMPANY TO CONFIRM AND ADD BEFORE PUBLICATION.]
Always engaged
| Subprocessor | What it is used for | What it receives | When |
|---|---|---|---|
| Amazon Web Services | Hosting for the Marshal application, and storage for onboarding templates and uploaded avatars. | All customer data held by the service, in transit and at rest. | Always. |
| [HOSTING PROVIDER FOR THE DATABASE, ANALYTICS STORE, AND CACHE - COMPANY TO CONFIRM] | Running the primary database, the analytics store that holds billing, Kubernetes usage, and uptime results, and the cache. | All customer data held by the service. If these run on Marshal's own AWS infrastructure rather than a managed vendor, this row is removed instead of completed. | Always. |
| Stripe | Taking payment for paid plans and holding the subscription record. | Billing contact and payment details entered on Stripe's own hosted checkout, and an identifier for the organization. Marshal never receives or stores card details, and stores no Stripe customer or subscription identifier. | Only for organizations on a paid plan. |
| Anthropic | The AI assistant that answers questions about an organization's own data. | The user's question and conversation history, plus excerpts of that organization's data: cost totals, recommendations with dollar estimates, resource names, types, regions and states, monitor names, states and expiry dates with redacted error text, incident titles, security finding titles and the resources they concern, cloud change records including the identity that made a change, and the organization's plan. Never credentials, never device telemetry. | When someone in the organization uses the AI assistant or an AI-generated explanation. |
| OpenAI | Incident summaries, postmortem drafts, written insights, and the embeddings behind search over an organization's own findings. | The same categories as above, limited to what the specific feature needs. Text indexed for search is restricted to an allowlist of resource shape and size fields, never addresses, IP ranges, URLs, or free-form descriptions. | When one of those features runs. Without a configured key these features are unavailable rather than degraded silently. |
Engaged only when a customer turns the feature on
| Subprocessor | What it is used for | What it receives | When |
|---|---|---|---|
| Resend | Delivering alert, report, verification, and password reset emails. | Recipient email address, subject, and message body. Alert bodies can include a monitored address, an error message, a computer's name and its reported issue, or spend figures. | Only where Marshal is configured to send email through Resend. A customer-run SMTP server can be used instead, in which case no third-party email provider is involved and the customer's own mail provider handles the message. |
| Slack | Delivering alerts and approval messages into a channel, and receiving approvals sent back from Slack. | Alert titles and bodies, and the approval message for a proposed infrastructure change. | Only if the organization connects a Slack webhook. |
| Google Cloud | Reading billing export tables that a customer grants Marshal's service account access to. | The customer's own Google Cloud billing export data. Marshal stores only the project and table identifiers for the connection. | Only if the organization connects a Google Cloud account. |
Not subprocessors
Datadog and Sentry can be connected as sources. In that case Marshal reads from the customer's own account at the customer's instruction; it does not send customer data to them, so they are not subprocessors of Marshal. The same is true of the customer's own cloud provider accounts and their own SMTP server.
Changes to this list
Marshal will give at least [SUBPROCESSOR CHANGE NOTICE PERIOD - COMPANY TO CONFIRM] notice before a new subprocessor begins processing customer personal data, by [NOTICE MECHANISM - COMPANY TO CONFIRM]. Customers may object on reasonable data protection grounds, as set out in section 9 of the data processing addendum.