Subprocessors
HumanAuth runs on a deliberately small set of third-party services. Each one processes personal data only to provide its part of the product to us. This page lists them, and exactly what each handles.
HumanAuth is pre-pilot and not yet SOC 2 certified. Our SOC 2 observation period is planned to begin once the first production pilots are live. The certifications listed against each subprocessor below are that provider's own — they do not describe HumanAuth's compliance.
-
Cloudflare, Inc.
Effectively the whole service runs here: compute, the primary database, the approval relay, object storage, request logs, and the web application firewall.
- Data processed
- Every category HumanAuth processes — account identifiers, device identifiers, request metadata, decision receipts, and free-text approval reasons.
- Certifications
- SOC 2 Type II, ISO 27001, ISO 27018, PCI DSS, FedRAMP Moderate, HIPAA-eligible.
-
WorkOS, Inc.
Handles sign-in, SSO / SAML, and directory sync. WorkOS performs the login itself; we store the account it returns.
- Data processed
- Email address, name, and organization membership.
- Certifications
- SOC 2 Type II, ISO 27001, HIPAA-ready, GDPR.
-
Tally BV
Hosts the form at humanauth.ai/access. Submissions are stored by Tally and forwarded to us over a signed webhook. It has no part in the product itself, only in asking for access to it.
- Data processed
- What the form asks for: work email, organisation, role, and a free-text description of what the visitor is building.
- Certifications
- Belgian company; form data encrypted in transit and at rest and stored in Europe. Tally publishes no SOC 2 or ISO 27001 certification.
-
Resend (Plus Five Five, Inc.)
Delivers the internal email that tells us someone asked for access. It carries what that person typed on the form; it is not used to email them, and there is no marketing list.
- Data processed
- Work email, organisation, role, and the free-text description from the access form.
- Certifications
- SOC 2 Type II, GDPR, DPA executed on sign-up; the sending region is pinned to Ireland, so this data stays in the EU. Resend states it holds no ISO 27001 certificate and is not HIPAA compliant.
-
Cal.com, Inc.
Hosts the booking page linked from the site. Used only to arrange a call; it sees nobody's approval traffic.
- Data processed
- Name, email address, and anything typed into the booking notes.
- Certifications
- SOC 2 Type II, GDPR.
-
Apple Push Notification service (APNs)
Delivers approval requests to iPhones and iPads. Routed through Expo's push service (see below).
- Data processed
- Device push token and an opaque alert payload — no personal data beyond whatever the integrator includes in an action label.
- Certifications
- Governed by Apple's developer terms and the APNs privacy practices.
-
Firebase Cloud Messaging (FCM) — Google LLC
Delivers approval requests to Android devices. Routed through Expo's push service (see below).
- Data processed
- Device push token and an opaque alert payload — the same minimization as APNs.
- Certifications
- Standard Google Cloud DPA, SOC 2 Type II, ISO 27001, ISO 27018.
Approval requests reach the mobile approver apps through the Expo push notification service, which relays each notification to Apple (APNs) or Google (FCM) for final delivery. Expo and the platform services handle the device push token and an opaque alert payload in transit; they do not receive your approval decisions or the receipts.
Your biometric — Face ID or Touch ID — never leaves your device. It unlocks an on-device signing key and is never sent to HumanAuth or any subprocessor. We also do not process payment card data, health data, government identifiers, or advertising identifiers. We use no third-party analytics, advertising, or session-replay tooling inside the product; if that ever changes, the provider will appear on this page first.
This is a living page. When we add a subprocessor or change the data an existing one handles, we update it here and, for customers under a Data Processing Addendum, give the advance notice their agreement requires.
For the full picture of what we collect and why, see our privacy policy. Questions about a subprocessor or data processing: [email protected]