Subprocessors

Arodus uses the subprocessors below to run the service. Every one that handles customer data is also a vendor in Arodus's own workspace, monitored on the same daily cycle as yours. We email subscribers 30 days before adding a subprocessor that handles customer data, as set out in our Data Processing Addendum.

Last updated October 2, 2026. To get change notices, email security@arodus.com with "Subscribe" in the subject.

Current subprocessors

Arodus subprocessors, what each does, the customer data it handles, and where
SubprocessorWhat it does for ArodusCustomer data it handlesLocation
Amazon Web Services, Inc.Hosting, database, storage, queues, sign-in (Amazon Cognito), transactional email (Amazon SES), monitoringAll customer data stored or processed by ArodusUnited States (us-east-1)
Amazon Web Services, Inc. (Amazon Bedrock, Anthropic Claude models)AI processing of public records, and drafting research summaries for vendors that need manual reviewBusiness name and website domain of a vendor a customer added that isn't yet in the Arodus catalogUnited States
Statsig, Inc.Feature flags, product analytics and performance tracesPseudonymous user ID, email domain, and request metadata (route, status and timing)United States
Google LLCSign in with Google; Google Workspace (email used by the Arodus review team); Google Chat (internal operations alerts)Name and email at sign-in; vendor names in review emails; addresses of undeliverable platform emails in alertsUnited States
Microsoft CorporationSign in with Microsoft (Entra ID)Name and email at sign-inUnited States
Stripe, Inc.Subscription billing and paymentsBilling name, email and payment card details. Card numbers are held by StripeUnited States

Integrations you connect

These are systems a customer chooses to connect. Arodus reads from them.

IntegrationWhat Arodus reads
Intuit QuickBooks OnlineAccounts payable and your company profile. See the Trust page.
Oracle NetSuiteAccounts payable and your company profile. See the Trust page.

Public sources Arodus queries

To research a vendor, Arodus queries public sources such as SEC EDGAR, GLEIF and the vendor's own website using that vendor's business name and domain. These queries carry nothing that identifies the customer who pays the vendor.

Change log

DateChange
October 2, 2026Statsig no longer receives search terms entered in the app.
October 2, 2026First published list.

Questions: security@arodus.com