Our guarantee
Every third-party service that processes our data is listed below, with what data it sees, where it's located, and its own compliance posture.
We use the following third-party services to operate Reclaim Protocol. Each subprocessor is contractually bound to the same data protection standards we uphold, and we maintain an up-to-date record of what data each one processes, where it is located, and their own compliance posture.
Cloud infrastructure (compute, storage, databases)
Data processed
Location
IN (ap-south-1), EU (eu-north-1)
Compliance
TEE confidential compute. Both TEE_K and TEE_A run as attested Docker images.
Data processed
Location
Prod cluster: IN (asia-south1) + US (us-central1). EU cluster: both in EU (europe-west).
Compliance
Admin authentication (Google OAuth)
Data processed
Location
US
Compliance
AI analysis for PII, security, and whitepaper checks
Data processed
Location
US
Compliance
Source code hosting and Dependabot supply-chain alerts
Data processed
Location
US
Compliance
Hosting for the Trust Portal (runs on Google Cloud Run under the hood)
Data processed
Location
GCP (asia-southeast1)
Compliance