> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rootly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Subprocessors

> The third-party subprocessors Rootly uses to deliver its services, what each one is used for, what data it processes, and where that data is located.

## Overview

A **subprocessor** is a third party Rootly engages to process customer personal data in the course of delivering the Rootly platform. This page lists those subprocessors, grouped by the function they serve, and includes the Authorized Sub-Processors listed in Rootly's U.S. Data Processing Addendum (September 2026).

This list covers processing performed by Rootly. It does not cover integrations you connect yourself — see [Customer-enabled integrations](#customer-enabled-integrations) below for that distinction.

<Note>
  All subprocessors listed here are bound by data processing agreements. Data sent to subprocessors is used solely to provide Rootly services and is not used for model training.
</Note>

***

## Infrastructure

Core infrastructure that Rootly runs on, including hosting, networking, and data transit.

| Subprocessor | Purpose | Data processed | Data location |
| - | - | - | - |
| [Amazon Web Services](https://aws.amazon.com) (Amazon Web Services, Inc.) | Hosting. Rootly's primary cloud infrastructure: compute, application databases, object storage, queuing, and event routing. | All customer data stored in Rootly, encrypted at rest | US |
| [Google Cloud](https://cloud.google.com) (Google, Inc.) | Hosting | Customer data processed by the hosted services | US |
| [Microsoft Azure](https://azure.microsoft.com) (Microsoft Corporation) | Hosting | Customer data processed by the hosted services | US |
| [Cloudflare](https://cloudflare.com) (Cloudflare Inc.) | Content delivery network, edge networking, and web application firewall | HTTP request data and tenant identifiers | US |
| [ClickHouse Cloud](https://clickhouse.com/cloud) | Columnar analytics database for AI evaluation and product analytics | AI evaluation datasets and product usage metrics | — |
| [QuotaGuard](https://www.quotaguard.com) | Static IP proxy for outbound integration traffic | HTTP request payloads transiting to customer-connected integrations | — |

***

## AI Features

Applies to Rootly AI features. See [Data Privacy for AI](/ai/data-privacy-for-ai) for the full safeguards, retention terms, and bring-your-own-key options.

| Subprocessor | Purpose | Data processed | Data location |
| - | - | - | - |
| [OpenAI](https://openai.com) (OpenAI, Inc.) | AI functionality: LLM inference for summarization, catchup, and generative features | Incident content submitted for AI processing | US |
| [Anthropic](https://anthropic.com) (Anthropic, PBC) | AI functionality: LLM inference for summarization, catchup, and generative features | Incident content submitted for AI processing | US |
| [Braintrust](https://braintrust.dev) (Braintrust Data, Inc.) | AI functionality: LLM request routing, tracing, and evaluation | Incident content and other data submitted for AI processing | US |
| [Recall.ai](https://recall.ai) (Hyperdoc Inc.) | Meeting transcription: meeting orchestration, recording capture, and platform connectivity for [AI Meeting Scribe](/ai/meeting-scribe) | Meeting audio/video streams, bot lifecycle events | US |

***

## Notifications and Alerting

How Rootly reaches responders when they are paged.

| Subprocessor | Purpose | Data processed | Data location |
| - | - | - | - |
| [Twilio](https://twilio.com) (Twilio, Inc.) | In-app calling and SMS for on-call paging and live call routing | Phone numbers, alert and notification content | US |
| [SendGrid](https://sendgrid.com) (SendGrid Inc., a Twilio subsidiary) | Email delivery for transactional and notification email | Email addresses, notification content | US |
| [Mailgun](https://mailgun.com) (Mailgun Technologies, Inc.) | Transactional email delivery | Email addresses, notification content | US |

***

## Platform Operations

Tooling Rootly uses to keep the service running and reliable. These process operational telemetry, which can incidentally contain user identifiers.

| Subprocessor | Purpose | Data processed | Data location |
| - | - | - | - |
| [Datadog](https://datadoghq.com) (Datadog, Inc.) | Monitoring: application performance, logging, and infrastructure observability | Application logs and telemetry, which may include user and team identifiers | US |
| [Sentry](https://sentry.io) (Functional Software, Inc.) | Monitoring: application error and exception tracking | Error traces and request context, which may include user and team identifiers | US |
| [pganalyze](https://pganalyze.com) (Duboce Labs Inc.) | Monitoring: database performance and query analytics | Database query patterns and telemetry, which may include user and team identifiers | US |
| [LaunchDarkly](https://launchdarkly.com) (Catamorphic Co.) | Feature management: feature flag evaluation and progressive rollout targeting | Team and user identifiers used as targeting keys | US |

***

## Business Operations and Analytics

Internal tooling Rootly personnel use to support accounts, troubleshoot issues, and analyze product usage.

| Subprocessor | Purpose | Data processed | Data location |
| - | - | - | - |
| [Segment](https://segment.com) (Segment.io, Inc.) | Analytics: customer data platform for product analytics event routing | User profile data, product usage events | US (Oregon) |
| [PostHog](https://posthog.com) (PostHog, Inc.) | Analytics: product analytics and user behavior tracking | User and team identifiers, product usage events | US |
| [Oliv.ai](https://oliv.ai) | Analytics: product and customer analytics | User profile data and product usage metrics | US |
| [HubSpot](https://hubspot.com) (HubSpot, Inc.) | Emails: CRM and customer communication | User profile data and account metadata | US |
| [Pylon](https://usepylon.com) (Pylon Labs, Inc.) | Customer support platform | User profile data, support ticket content | US |
| [Linear](https://linear.app) (Linear Orbit, Inc.) | Support ticket tracking | User profile data, support ticket content | US |
| [Metabase](https://metabase.com) (Metabase, Inc.) | Business intelligence. Rootly personnel run read-only queries against production application data to support customer accounts, troubleshoot issues, and analyze product usage. | User profile data (names, email addresses, phone numbers), incident and alert records, and associated metadata | US |
| [Snowflake](https://snowflake.com) (Snowflake, Inc.) | Data warehouse for aggregated product usage and account health analytics | Product usage metrics and account metadata | US |
| [Stripe](https://stripe.com) (Stripe, Inc.) | Payment processing and subscription billing | Billing contact details and payment metadata | US |

***

## Communication and Support

How Rootly personnel communicate internally and with customers.

| Subprocessor | Purpose | Data processed | Data location |
| - | - | - | - |
| [Slack](https://slack.com) (Slack Technologies, LLC) | Communication: internal team communication and incident coordination | User identifiers, message content | US |
| [Intercom](https://intercom.com) (Intercom, Inc.) | Live chat and customer support | User profile data, support conversation content | AWS us-east-1 |

***

## Customer-Enabled Integrations

Rootly connects to a wide range of third-party tools — Microsoft Teams, Jira, PagerDuty, GitHub, Datadog as an alert source, and [many others](/integrations/overview).

These are **not** Rootly subprocessors. You enable them, you control the credentials, and data flows to them at your direction under your own agreement with that vendor. Rootly acts on your instruction to send data to a destination you chose.

The distinction matters for your own DPA: the vendors listed above process your data because Rootly engaged them. Integration vendors process your data because you did.

***

## Changes to This List

At least 10 days before Rootly lets a new subprocessor access or process personal data, Rootly adds it to this list and notifies customers by email. You can object in writing within 10 days of that notice, on reasonable grounds relating to data protection. The full terms are in Section 4 of the Data Processing Addendum.

<Info>
  To request the current Data Processing Addendum, contact your account team or [security@rootly.com](mailto:security@rootly.com).
</Info>

Additional compliance artifacts — SOC 2 Type II report, penetration test results, and security policies — are available through the [Rootly Trust Center](https://security.rootly.com).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.