Sub-processors
Last Updated: October 10, 2026
SutramX, operated by QuantumPlug Technologies LLP, uses the providers below to run the service. Each receives personal data only as needed for the purpose listed, under a written contract. This list forms part of our Data Processing Addendum and is also summarised in our Privacy Policy.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting of the application, API, database, monitoring workers, the marketing website, our internal admin console and the Frankfurt checker; outgoing email (Amazon SES) for transactional, alert and newsletter emails, and the delivery reports it returns (delivered, bounced, marked as spam); encrypted database backups; operational logs (kept 14 days) | Germany (eu-central-1, Frankfurt); backups and operational logs in the USA (us-east-1, N. Virginia) |
| Hostinger | Hosting of the Arizona and Mumbai checkers; outgoing email (SMTP) for transactional and alert emails | Checkers in the USA (Arizona) and India (Mumbai); email per provider |
| Cloudflare | DNS, network security, and content delivery for our websites and API; cookieless page-load measurement on the marketing website (Cloudflare Web Analytics) | Global edge network |
| Cloudflare R2 | Temporary storage of data exports you request (deleted after 7 days) | Global (Cloudflare R2) |
| Dodo Payments | USD payments; acts as merchant of record | Per provider |
| Razorpay | INR payments, including UPI autopay | India |
| Google Web Risk | Screening monitor target URLs for known malicious sites; receives only the scheme, host and path, never the query string, credentials, headers or bodies | United States |
| Globalping (jsDelivr) | Last-mile checks on plans that include them: measures your monitored host from home and mobile networks; receives only the host name, port and path, never headers, credentials or bodies | Global (probe network) |
| Google Analytics (Google) | Visitor analytics for the marketing website sutramx.com, only if you accept analytics cookies; not used in the SutramX dashboard or apps | United States |
| PostHog | Product analytics for the marketing website and the SutramX dashboard, only if you accept analytics cookies: page views, feature usage and session recordings with everything you type hidden; linked to your user ID, never your name or email; not used on public status pages or in the mobile app | United States |
| Twilio | SMS and voice call alerts, and WhatsApp alerts sent through Twilio | United States |
| Meta (WhatsApp Business Platform) | WhatsApp alerts sent through the WhatsApp Cloud API | Global |
| Microsoft (Azure Bot Service) | Delivering alerts through the SutramX app for Microsoft Teams, when a customer adds it to Teams: receives the alert text and the Teams conversation it goes to | Global (Microsoft cloud) |
| Google (Google Chat API) | Delivering alerts through the SutramX app for Google Chat, when a customer adds it to a Chat space: receives the alert text and the space it goes to | Global (Google cloud) |
| Telegram | Telegram alerts sent through the SutramX Telegram bot | Global |
| OpenAI (OpenAI API) | Drafting AI incident summaries, postmortems and status page updates, from redacted incident facts (no alert recipients, names, request headers or bodies, or full monitored URLs): on request, and automatically for incidents open more than 5 minutes on plans that include AI incident summaries. OpenAI does not use API data to train its models. | United States |
| Sentry | Error diagnostics for the API; error reports are scrubbed of credentials and request bodies | United States |
| Expo (Expo push notification service) | Delivering push alerts to the SutramX mobile app, through Apple Push Notification service and Firebase Cloud Messaging; receives the device push token and the alert text | United States |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Delivering encrypted browser push alerts you turn on | Per browser vendor |
Services you connect
When you connect a third-party service yourself, such as Slack, Discord, Microsoft Teams and Google Chat incoming webhooks, Mattermost, PagerDuty, Opsgenie, GitHub, custom webhooks, and Google or GitHub sign-in, we send it data on your instruction. Those services act under their own terms with you and are not SutramX sub-processors.
Changes to this list
Before we add or replace a sub-processor, we update this page with a new date and email workspace owners at least 30 days in advance (except where an urgent change is needed to keep the service secure or running, in which case we notify as soon as we can). You can object as described in section 6 of the Data Processing Addendum. To ask about this list, email support@sutramx.com.