Discovery queue open Typical turnaround: one working day The register Method Talk to a reviewer
subprocessor.org
Six sources. One reviewed list. Re-checked daily.See how the work flows →
Same engine, different job to be done.Compare the tiers →
We publish observations and dated records, never legal conclusions.Read the method →
Free to read. No account.Open the register →
start your discovery

Give us the domain.
We’ll do the looking.

One field, no account, nothing installed. We read your legal pages, your DNS and mail records, your response headers, your consent tooling and any list you already keep — then a named reviewer works through the result before you see it.

Rather talk it through first? Book fifteen minutes with a reviewer

Google sign-in when you’re ready Nothing published without your approval The list is yours either way
What happens next
from the moment you submit
queue open
1 The crawl startsusually inside a minute, always the same six sources now
2 First results landdeclared entities from your legal pages, then everything observed ~1 hour
3 A reviewer works through itmerging duplicates, deciding scope, checking each source resolves same day
4 We send it to youwith the name of the person who checked it 1 working day
No card, no call, no commitment
Whether you continue is a decision you make after you’ve seen the work.
where we look, and what each place tells us

Six sources, because no single one is complete.

A legal page that hasn’t been touched in two years will not tell you what your engineering team switched on last quarter. Reading them separately is the point.

01 — legal surface

Your published pages

Sub-processor page, privacy notice, DPA and any annex. Read as structured entities, not scraped text.

Tells us what you currently claim
Misses anything adopted since it was last edited
02 — mail and dns

MX, SPF, CNAME chain

Who actually carries your email, and which infrastructure sits in front of your domain.

Tells us mail, workspace and CDN providers
Misses anything that never touches DNS
03 — response headers

Content-Security-Policy

A CSP frequently enumerates every third-party endpoint your product talks to. It is the most under-used source in this whole business.

Tells us in-product third parties
Misses anything called server-side
04 — consent tooling

Your vendor manifest

OneTrust, Cookiebot and similar publish a per-domain vendor list. If you run one, you have already done part of this work.

Tells us declared website vendors
Misses product-side processing
05 — what you send

Spreadsheets and exports

A vendor list, a procurement export, a CSV someone maintains. Send it in any shape and we will reconcile it against everything we find.

Tells us internal systems with no public trace
Misses whatever nobody wrote down
06 — contracts

DPAs and order forms

Optional, and the one that earns its keep later: we extract each notification clause so your objection windows come from your own contracts rather than a standard assumption.

Tells us your real notice periods
Misses nothing — but a human confirms every clause
what lands in your inbox

Two columns, presented straight.

What your own pages declare, beside what we actually observed. They answer different questions and we do not pretend otherwise — the judgement stays with you.

Declared

named on your legal surface · 12 entities

Amazon Web Services/legal/subprocessors
Stripe/legal/subprocessors
Twilio SendGrid/legal/subprocessors
Zendesk/legal/subprocessors
SnowflakeDPA §9
Cloudflare/privacy

Observed

detected on your public surface · 9 services

CloudflareDNSinfrastructure
StripeCSP headerproduct data
IntercomCSP headerproduct data
Google WorkspaceMX recordproduct data
Google Analyticsscript tagwebsite
OneTrustconsent manifestwebsite
This is not a scorecard, and we will never publish it as one. A sub-processor list covers third parties processing customer data inside your product, under your DPA. A technology scan sees what your website loads, which sits under your privacy notice and cookie rules. A service can legitimately appear in one column and not the other. We label what we found and where we found it; deciding which obligation applies is your call, with your counsel.

The part no scan can reach

Payroll, HR, data warehouses, anything internal. Paste them in and they are reconciled with everything else rather than living in a separate spreadsheet.

a boundary worth stating

Your domain and someone else’s are treated differently.

We built this to be useful without being a weapon.

  • Your own domain, verifiedYou can publish the result — on the register, your own site, or both.
  • A domain you don’t controlStays private to your account. It is never published and never shown to that company.
  • No accusations, everWe do not write “undisclosed” and we do not claim anyone is in breach. We record what we read and the date we read it.
  • Corrections are welcomeEvery register page carries a way to correct it, and every correction is logged rather than silently applied.
and then

Discovery is the start of the job, not the whole of it.

after you approve

It gets published, properly

At your address or ours, with the source behind every entity and a dated history from day one.

See what you end up with →
every morning after

We re-read the whole stack

Changes come to you with the evidence attached, held until you decide. Your customers hear it from you.

How upkeep works →
when you want it

The same engine, aimed outward

Every vendor discovery found can be watched daily, with objection windows read from your own contracts.

See monitoring →

Send the domain. See what we come back with.

Free, no account to start, and a named reviewer either way.