Skip to main content

Overview

A subprocessor is a third party Rootly engages to process customer personal data in the course of delivering the Rootly platform. This page lists those subprocessors, grouped by the function they serve. This list covers processing performed by Rootly. It does not cover integrations you connect yourself — see Customer-enabled integrations below for that distinction.
All subprocessors listed here are bound by data processing agreements. Data sent to subprocessors is used solely to provide Rootly services and is not used for model training.

Infrastructure

The platform Rootly runs on. All customer data at rest lives here.

AI features

Applies to Rootly AI features. See Data Privacy for AI for the full safeguards, retention terms, and bring-your-own-key options.

Notifications and alerting

How Rootly reaches responders when they are paged.

Platform operations

Tooling Rootly uses to keep the service running and reliable. These process operational telemetry, which can incidentally contain user identifiers.

Business operations and analytics

Internal tooling Rootly personnel use to support accounts, troubleshoot issues, and analyze product usage.

Customer-enabled integrations

Rootly connects to a wide range of third-party tools — Slack, Microsoft Teams, Jira, PagerDuty, GitHub, Datadog as an alert source, and many others. These are not Rootly subprocessors. You enable them, you control the credentials, and data flows to them at your direction under your own agreement with that vendor. Rootly acts on your instruction to send data to a destination you chose. The distinction matters for your own DPA: the vendors listed above process your data because Rootly engaged them. Integration vendors process your data because you did.

Changes to this list

Rootly maintains a data processing agreement covering the processors listed here. To request the current DPA, or to ask about notification of changes to this list, contact your account team or security@rootly.com.
Additional compliance artifacts — SOC 2 Type II report, penetration test results, and security policies — are available through the Rootly Trust Center.