> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Subprocessors

> The companies that process data on Kiste's behalf, and how changes are announced.

The binding, current list is at **[kiste.run/subprocessors](https://kiste.run/subprocessors)**
and in Annex 3 of the [data processing agreement](https://kiste.run/dpa). This page summarises it.

| Company | What for | What it can see |
| --- | --- | --- |
| Cloudflare, Inc. (USA) | The kiste.run edge and control plane (Workers), the account database (D1), downloads and encrypted backups (R2), the tunnel to the compute server, access control, DNS, DDoS protection, rate limiting, TURN relay | Account data, request metadata including IP addresses, encrypted backup objects (no key), encrypted traffic in transit |
| Stripe (Stripe Payments Europe, Ltd., Ireland, with Stripe, Inc., USA) | Payments, checkout, customer portal, invoices | E-mail address, account id, payment method, invoices. Never the contents of Kisten. Stripe acts as an independent controller for payment processing and its own legal duties, so it is named separately. |

## Changes

A new subprocessor is announced **30 days** before it first receives personal data, as set out in
the data processing agreement.

## Providers that receive no customer data

Kiste also uses tools to build and operate the service: GitHub for source code and CI, a password
manager for operator secrets, and AI coding agents that help the operator with engineering work.
None of them is given customer personal data. Review evidence in repositories is redacted, and
logs identify accounts only by a random id. If that ever changes, the provider is added to the
list above under the 30-day rule first.

## Related topics

- [Security and trust](https://docs.kiste.run/security.md)
- [Isolation](https://docs.kiste.run/security/isolation.md)
- [Network](https://docs.kiste.run/security/network.md)
- [Encryption](https://docs.kiste.run/security/encryption.md)
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
- [Data location](https://docs.kiste.run/security/data-location.md)
- [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
- [Export and deletion](https://docs.kiste.run/security/account-data.md)
- [Incidents and status](https://docs.kiste.run/security/incidents-status.md)
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- [Compliance](https://docs.kiste.run/security/compliance.md)
- Previous: [Data location](https://docs.kiste.run/security/data-location.md)
- Next: [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
