Sub-processors
Version 2026-09-27 · Last updated 27 September 2026
These are the companies that receive personal data when SKE runs, and what each one gets. Most work for SKE under a contract. Cloudflare also uses Turnstile data for its own bot detection, and Bunny Fonts works under its own terms. The last column shows which ones process Customer Personal Data under the Data Processing Agreement. Owners of an organization get an email at least 30 days before a new one of those starts, and can object through our contact form.
| Company | What it does for SKE | Data it processes | Where | Processes Customer Personal Data |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Runs the SKE API on AWS Lambda and its background jobs on Amazon SQS, keeps its logs in Amazon CloudWatch, and stores caught-email attachments in Amazon S3 | Everything the SKE API handles, background jobs (which can hold alert text) for up to 14 days, SKE’s logs, and attachment files | EU (Frankfurt, Germany) | Yes |
| Our database provider | Runs SKE’s database and its backups | Everything SKE stores, including caught emails and SMS, SES delivery events and environment variables | — | Yes |
| Cloudflare, Inc. | Hosts ske.io, app.ske.io and the CLI downloads, sits in front of the SKE API at api.ske.io, runs the Turnstile bot check, forwards emails sent to SKE’s support address to support staff, and passes email replies to support tickets to the SKE API | Everything sent to and from the SKE API, emails sent to SKE’s support address, email replies to support tickets, the IP address, browser and page of each visit, Turnstile browser signals, and the visitor’s IP address, which the SKE API sends to check a Turnstile answer | Global network, United States | Yes |
| Bunny Fonts (BunnyWay d.o.o., Slovenia) | Serves the fonts on the page where people approve an MCP client, under its own terms | IP address and browser of that page’s visitors | Global network | No |
Customers’ own cloud providers (AWS, Google Cloud), the alert destinations customers set up (Slack, Discord, Microsoft Teams, Telegram, webhooks and email addresses), and the MCP clients and tools customers connect with their own sign-in or API tokens aren’t SKE’s sub-processors. SKE sends data to them on the customer’s instructions. The customer chooses them, and any transfer safeguards they need.
Versions
- 2026-09-27Current