Trust
Sub-processors
steepl uses the following sub-processors to deliver the service. We notify customers in writing at least 30 days before adding a new sub-processor that processes regulated customer data. Subscribe to our status page for change notifications.
| Vendor | Purpose | Data | Location | Certifications |
|---|---|---|---|---|
| Hetzner Online GmbH | Primary infrastructure hosting (compute, network, object storage) | All customer data at rest and in transit | Falkenstein, Germany (primary); Helsinki, Finland (standby) | ISO 27001, ISO 9001, ISO 14001 |
| Amazon Web Services — KMS | HSM-backed signing of period anchors; envelope-encryption KEK | Cryptographic key material only; no plaintext customer data | eu-central-1 (Frankfurt) primary; us-east-1 multi-region key replica | SOC 1/2/3, ISO 27001/17/18, FIPS 140-3 L3 HSM |
| Stripe, Inc. | Payment processing for giving and AP | Payment-method tokens, transaction metadata; no card data on our infrastructure | United States | PCI DSS Level 1, SOC 2 |
| Lob (CompanyCam DBA) | Paper check generation and mail-out (AP fallback rail) | Vendor name, address, check amount, memo | United States | SOC 2 |
| Vanta | SOC 2 evidence collection and continuous compliance monitoring | Infrastructure metadata, employee directory, system audit logs | United States | SOC 2, ISO 27001 |
| WorkOS | SAML/OIDC brokering and SCIM Directory Sync (Firm tier) | User authentication metadata, group membership | United States | SOC 2 Type II |
| Sentry | Application error monitoring | Stack traces, scrubbed request metadata; PII/PHI redacted | United States | SOC 2 Type II |
| Postmark (ActiveCampaign) | Transactional email (statements, receipts, system notifications) | Recipient email, statement attachment, message body | United States | SOC 2 |
| Atlassian Statuspage | Public status page hosting | Incident metadata only; no customer data | United States | SOC 2 |
Last reviewed 2026-05-20. Some sub-processors may be added or replaced as the product evolves; customers are notified per the policy above.