Legal & Compliance
Transparency is the foundation of trust. Review our legal documents, data processing agreements, and compliance commitments.
Who processes your data when you use FortisEU
Every third party that touches tenant data, named and scoped. No NDA, no form. Procurement and MSSP teams can pull this directly into a DPA cascade.
30 days advance notice
We will publicly update this list at least 30 days before adding a new sub-processor. Tenants on Business and Enterprise plans receive an email notification at the same time.
Subscribe to changelog notifications via the trust center to receive sub-processor updates by email.
Current list
| Sub-processor | Role | Data category | Processing region | DPA / SCC | Status |
|---|---|---|---|---|---|
Mistral AI SAS Paris, France | AI inference | ASK assistant prompts and embedding-generation inputs (no training; tenant-data isolation per ADR) | France (EU) | View DPA | Active |
Scaleway SAS Paris, France | Primary infrastructure | Tenant data at rest (PostgreSQL / Supabase), object storage, Valkey cache, compute | Paris-2 (FR), with EU-only failover | View DPA | Active |
Brevo SAS (formerly Sendinblue) Paris, France | Transactional email | Recipient email address, message subject and body, delivery and engagement events | France (EU) | View DPA | Active |
Keycloak (self-hosted on Scaleway) Paris, France | Identity broker / SSO (SAML, OIDC) | Authentication identifiers, SSO assertions, session metadata | Paris-2 (FR) | Self-hosted on Scaleway SAS — DPA covered by host agreementView host DPA | Active |
Grafana LGTM (self-hosted on Scaleway) Paris, France | Observability (logs, metrics, traces) | Operational telemetry, structured logs, OpenTelemetry traces (no tenant payloads) | Paris-2 (FR) | Self-hosted on Scaleway SAS — DPA covered by host agreementView host DPA | Active |
- Role
- AI inference
- Data category
- ASK assistant prompts and embedding-generation inputs (no training; tenant-data isolation per ADR)
- Processing region
- France (EU)
- DPA / SCC
- View DPA
- Role
- Primary infrastructure
- Data category
- Tenant data at rest (PostgreSQL / Supabase), object storage, Valkey cache, compute
- Processing region
- Paris-2 (FR), with EU-only failover
- DPA / SCC
- View DPA
- Role
- Transactional email
- Data category
- Recipient email address, message subject and body, delivery and engagement events
- Processing region
- France (EU)
- DPA / SCC
- View DPA
- Role
- Identity broker / SSO (SAML, OIDC)
- Data category
- Authentication identifiers, SSO assertions, session metadata
- Processing region
- Paris-2 (FR)
- DPA / SCC
- Self-hosted on Scaleway SAS — DPA covered by host agreementView host DPA
- Role
- Observability (logs, metrics, traces)
- Data category
- Operational telemetry, structured logs, OpenTelemetry traces (no tenant payloads)
- Processing region
- Paris-2 (FR)
- DPA / SCC
- Self-hosted on Scaleway SAS — DPA covered by host agreementView host DPA
Procurement next steps
Data processing agreement
Read our standard DPA, including SCC annexes and sub-processor flowdown clauses.
Open DPATrust center
Live status, SBOMs, AI registry, security overview, and changelog. One URL for procurement.
Open trust centerQuestions?
For audit-grade entity details, signed sub-processor lists, or MSSP cascade letters, contact the legal team.
Contact legal (legal@fortiseu.com)List version: 2026-05-09