Policies
Sub-processor list
A sub-processor is a third party that processes data on our behalf in order to deliver Cairn. This is the complete list, what each one is used for, and whether customer-submitted content can reach them.
Last updated 8 October 2026
Amazon Web Services
May process contentCloud hosting, database, and object storage for the Cairn application.
Holds SOC 1/2/3, ISO 27001, PCI DSS — opens Amazon Web Services’s trust page in a new tab
Render
May process contentApplication hosting for Cairn's web and webhook services.
Holds SOC 2 Type II — opens Render’s trust page in a new tab
Cloudflare
No customer contentDNS, TLS termination, CDN delivery, and bot protection on web forms.
Holds SOC 2 Type II, ISO 27001 — opens Cloudflare’s trust page in a new tab
Twilio SendGrid
May process contentDelivery of transactional email — prompts, confirmations, and notifications.
Holds SOC 2 Type II, ISO 27001, PCI DSS — opens Twilio SendGrid’s trust page in a new tab
Anthropic
May process contentLanguage model inference for interpreting answers and detecting conflicts. Used under terms that prohibit training on customer data.
Holds SOC 2 Type II, ISO 27001 — opens Anthropic’s trust page in a new tab
OpenAI
May process contentLanguage model inference, as an alternative provider. Used under terms that prohibit training on customer data.
Holds SOC 2 Type II, ISO 27001, ISO 42001 — opens OpenAI’s trust page in a new tab
Datadog
No customer contentOperational telemetry and alerting. Receives a typed, PII-free event schema — not the content of anyone's answers.
Holds SOC 2 Type II, ISO 27001 — opens Datadog’s trust page in a new tab
These attestations are theirs, not ours
Every certification above belongs to the provider named beside it. Cairn holds none of its own — see our security overview for where we actually stand. We list them because a reviewer needs to know the stack, not so we can borrow the badge.
Changes to this list
This page is the canonical list and carries the date it last changed. Customers on a signed agreement are notified before a new sub-processor starts handling their data, with enough notice to raise an objection.
Questions
For a DPA, a security questionnaire, or anything this page does not answer, ask us directly. How we handle personal data is set out in the privacy policy.