> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rootly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Subprocessors

> The third-party subprocessors Rootly uses to deliver its services, what each one is used for, and the categories of customer data each one processes.

## Overview

A **subprocessor** is a third party Rootly engages to process customer personal data in the course of delivering the Rootly platform. This page lists those subprocessors, grouped by the function they serve.

This list covers processing performed by Rootly. It does not cover integrations you connect yourself — see [Customer-enabled integrations](#customer-enabled-integrations) below for that distinction.

<Note>
  All subprocessors listed here are bound by data processing agreements. Data sent to subprocessors is used solely to provide Rootly services and is not used for model training.
</Note>

***

## Infrastructure

The platform Rootly runs on. All customer data at rest lives here.

| Subprocessor                                  | Purpose                                                                                                                                 | Data processed                                        |
| --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------- |
| [Amazon Web Services](https://aws.amazon.com) | Primary cloud infrastructure — compute, application databases, object storage, queuing, and event routing. Rootly runs entirely on AWS. | All customer data stored in Rootly, encrypted at rest |

***

## AI features

Applies to Rootly AI features. See [Data Privacy for AI](/ai/data-privacy-for-ai) for the full safeguards, retention terms, and bring-your-own-key options.

| Subprocessor                                         | Purpose                                                                                                         | Data processed                                    |
| ---------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- |
| [OpenAI](https://openai.com)                         | AI-powered incident summarization, catchup, and related generative features                                     | Incident content and redacted meeting transcripts |
| [Amazon Bedrock](https://aws.amazon.com/bedrock/)    | Hosted model inference for Rootly AI features                                                                   | Incident content submitted for AI processing      |
| [Recall.ai](https://recall.ai)                       | Meeting orchestration, recording capture, and platform connectivity for [AI Meeting Scribe](/ai/meeting-scribe) | Meeting audio/video streams, bot lifecycle events |
| [AssemblyAI](https://assemblyai.com) (via Recall.ai) | Speech-to-text transcription, summarization, PII redaction, and speaker identification                          | Meeting audio for transcription                   |

***

## Notifications and alerting

How Rootly reaches responders when they are paged.

| Subprocessor                                                                     | Purpose                                                              | Data processed                                |
| -------------------------------------------------------------------------------- | -------------------------------------------------------------------- | --------------------------------------------- |
| [Twilio](https://twilio.com)                                                     | SMS and voice call delivery for on-call paging and live call routing | Phone numbers, alert and notification content |
| [SendGrid](https://sendgrid.com)                                                 | Transactional and notification email delivery                        | Email addresses, notification content         |
| [Firebase Cloud Messaging](https://firebase.google.com/products/cloud-messaging) | Push notification delivery to Android devices                        | Device push tokens, notification content      |
| [Apple Push Notification service](https://developer.apple.com/notifications/)    | Push notification delivery to iOS devices                            | Device push tokens, notification content      |
| [Expo](https://expo.dev)                                                         | Mobile push notification routing for the Rootly mobile app           | Device push tokens, notification content      |
| [Svix](https://svix.com)                                                         | Outgoing webhook delivery and signature verification                 | Webhook payload content                       |

***

## Platform operations

Tooling Rootly uses to keep the service running and reliable. These process operational telemetry, which can incidentally contain user identifiers.

| Subprocessor                             | Purpose                                                                       | Data processed                                                                |
| ---------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- |
| [Datadog](https://datadoghq.com)         | Application performance monitoring, logging, and infrastructure observability | Application logs and telemetry, which may include user and team identifiers   |
| [Sentry](https://sentry.io)              | Application error and exception tracking                                      | Error traces and request context, which may include user and team identifiers |
| [LaunchDarkly](https://launchdarkly.com) | Feature flag evaluation and progressive rollout targeting                     | Team and user identifiers used as targeting keys                              |

***

## Business operations and analytics

Internal tooling Rootly personnel use to support accounts, troubleshoot issues, and analyze product usage.

| Subprocessor                       | Purpose                                                                                                                                                                         | Data processed                                                                                                 |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| [Metabase](https://metabase.com)   | Business intelligence. Rootly personnel run read-only queries against production application data to support customer accounts, troubleshoot issues, and analyze product usage. | User profile data (names, email addresses, phone numbers), incident and alert records, and associated metadata |
| [Snowflake](https://snowflake.com) | Data warehouse for aggregated product usage and account health analytics                                                                                                        | Product usage metrics and account metadata                                                                     |
| [Stripe](https://stripe.com)       | Subscription billing and payment processing                                                                                                                                     | Billing contact details and payment metadata                                                                   |

***

## Customer-enabled integrations

Rootly connects to a wide range of third-party tools — Slack, Microsoft Teams, Jira, PagerDuty, GitHub, Datadog as an alert source, and [many others](/integrations).

These are **not** Rootly subprocessors. You enable them, you control the credentials, and data flows to them at your direction under your own agreement with that vendor. Rootly acts on your instruction to send data to a destination you chose.

The distinction matters for your own DPA: the vendors listed above process your data because Rootly engaged them. Integration vendors process your data because you did.

***

## Changes to this list

<Info>
  Rootly maintains a data processing agreement covering the processors listed here. To request the current DPA, or to ask about notification of changes to this list, contact your account team or [security@rootly.com](mailto:security@rootly.com).
</Info>

Additional compliance artifacts — SOC 2 Type II report, penetration test results, and security policies — are available through the [Rootly Trust Center](https://security.rootly.com).
