Skip to main content

Subprocessors

Effective Date: August 26, 2026

Klyverity uses certain third-party subprocessors to assist in providing our services. This page lists all subprocessors we currently engage to process customer data. We are committed to providing at least 30 days advance notice before adding any new subprocessors or making material changes to our existing subprocessors.

Current Subprocessors

SubprocessorPurposeData ProcessedLocation
Amazon Web Services (AWS)Cloud infrastructure, document storage (S3), database hosting (RDS), secrets management, serverless compute (Lambda). HIPAA BAA in place.Application data, uploaded documents, database recordsUnited States (us-east-1)
CloudflareDNS and reverse proxy for the API domain (api.klyverity.com). Terminates TLS at its edge and forwards requests to our origin. The web application itself is served by Vercel and does not route through Cloudflare.API requests and responses in transit, including signer names, email addresses, document metadata, and IP addressesGlobal edge network; requests are handled by the point of presence nearest the requester
StripePayment processing and subscription managementBilling information, subscription data, payment method tokensUnited States
ResendTransactional email deliveryEmail addresses, email contentUnited States
SentryError tracking and application monitoringError reports, browser metadata, request URLsUnited States
VercelFrontend application hosting and CDNWeb traffic, user requests, IP addressesUnited States

Content Delivery Networks for Static Assets

The following public CDNs serve static library files directly to your browser. They are listed separately from the subprocessors above because we do not send them customer data and they never receive a document or anything in it. What they do receive is the metadata that any web request carries: IP address, browser user agent, the time of the request, and the site the request came from. This happens whenever a document is viewed or signed, including when the person signing is an external signer who has no account with us. Our referrer policy sends these CDNs only our domain, not the address of the page being viewed, so they do not learn which document is involved.

Content Delivery NetworkPurposeData ReceivedLocation
unpkg.comServes the PDF.js worker script (pdf.worker.min.mjs) that our in-browser document viewer runs.Request metadata only: IP address, user agent, request timing, and referring site (our domain). No document content and no account, signer, or document identifiers.Global CDN; requests are served by the point of presence nearest the requester
cdn.jsdelivr.netServes PDF.js character maps and standard font data used to render document text correctly.Request metadata only: IP address, user agent, request timing, and referring site (our domain). No document content and no account, signer, or document identifiers.Global CDN; requests are served by the point of presence nearest the requester

Subprocessor Updates

We will notify customers at least 30 days in advance before adding new subprocessors or making material changes to existing ones. To subscribe to updates about changes to our subprocessors, please email privacy@klyverity.com.

Data Processing Obligations

We ensure all subprocessors are bound by data processing obligations no less protective than those in our Data Processing Agreement. Each subprocessor is carefully vetted to maintain the security and privacy standards our customers expect.

If you have questions about our subprocessors, please contact us at privacy@klyverity.com.