Pactlyra Request early access

Subprocessor List

The companies that may process information while Pactlyra operates the production service, and what each one does.

Active providers

ProviderPurposeInformation potentially processed
RailwayHosts the Pactlyra web service, API, worker and private ClamAV malware scannerCustomer content and operational data handled by those services
NeonManaged PostgreSQL database and production snapshotsAccounts, workspaces, documents, transactions, evidence metadata, tickets, usage and configuration
ClerkCustomer identity, authentication, session and abuse protectionCustomer name, email, identity-provider references, session and security metadata
GoogleOptional Google OAuth identity connection chosen by a customerGoogle account identity and OAuth security metadata; not customer documents
Microsoft 365 and Microsoft GraphTransactional email and delivery statusRecipient address, sender, subject, message content, signing link and delivery metadata; not document bytes or field values
StripeSubscription checkout, billing portal, invoices and payment processingBilling contact, plan, amount, tax and payment information; Pactlyra receives references and status rather than complete card details
CloudflareAuthoritative DNS and enabled domain, edge or security functionsDNS information and request metadata only where traffic passes through an enabled Cloudflare function

The ClamAV scanner runs inside Pactlyra's Railway project and is not a separate SaaS recipient. GitHub supports development and source control and is not intended to receive production customer documents. Zorsen supplies approved public-site metadata and operational quality reporting; Pactlyra does not send it document content, signer data, credentials or private workspace data.

Customer-directed destinations

A customer may configure its own webhook endpoint or storage destination. Pactlyra sends only the information described by that feature and the customer's instruction. Those destinations are controlled by the customer and are not Pactlyra subprocessors for another customer.

Changes and diligence

Pactlyra evaluates a provider's role, access, security and contractual terms before giving it production data. Locations and transfer safeguards depend on the applicable provider agreement and customer order. Customers needing a data-processing agreement, region commitment, advance change notice or provider-specific evidence should contact [email protected] before subscribing to an enterprise scope.

Material additions that expand access to customer content will be posted here before use where reasonably practicable. Emergency security replacements may be made first and documented promptly afterwards.

Effective and last updated 2026-09-21. These pages describe Pactlyra's current production practices. Contact [email protected] with questions or rights requests.