Anthropic Subprocessors List (September 2026): Changes and History

Anthropic names 20 subprocessors on its published list. Read from the vendor's own page and re-checked daily.

Last checked September 26, 2026 Official source ↗

Anthropic subprocessors (September 2026)

# Subprocessor Purpose Location
1 Google Cloud Platform Cloud infrastructure Worldwide
2 Amazon Web Services Cloud Infrastructure Worldwide
3 Microsoft Azure Cloud Infrastructure Worldwide
4 Cloudflare Traffic Routing (CDN) Worldwide (Local to Customer)
5 Stripe Billing United States
6 WorkOS Security, Single Sign-On United States
7 Intercom User support United States
8 Nutun User support South Africa
9 Boldr User support Canada
10 Twilio Analytics, email/SMS communications United States
11 Iterable Email communications United States
12 Functional Software, dba Sentry Error Handling, User Support United States
13 Sift Fraud and abuse detection United States
14 Arkose Labs Fraud and abuse detection United States
15 Brave Search Web Search United States
16 ElevenLabs Text to speech United States
17 Palantir Federal Cloud Service (PFCS) FedRAMP Cloud United States
18 TurboPuffer Web Search United States
19 Persona Fraud and abuse detection, identity verification United States
20 Yoti Fraud and abuse detection, identity verification United Kingdom

Get an email when Anthropic changes its subprocessors

ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.

Track Anthropic free

Key DPA terms at Anthropic

What Anthropic's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?

Breach notification

Within 48 hours

“Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach”
DPA, www.anthropic.com ↗
Notice of a new subprocessor

15 days ahead

“Customer may, on the basis of reasonable data privacy or data security concerns, object to Anthropic's use of such Subprocessor by providing Anthropic with written notice of the objection within fifteen (15) days of the date of such notice”
DPA, www.anthropic.com ↗
Transfers outside the EU

Standard contractual clauses

“The parties agree that, to the extent required by Applicable Data Protection Laws, the terms of the SCCs Module Two (controller to processor) and/or Module Three (processor to processor), as completed as described in Schedule 3 of this DPA, are hereby incorporated by reference”
DPA, www.anthropic.com ↗
Customer data after the contract ends

Deleted within 30 days of the contract ending

“Within thirty (30) days of the date of termination or expiration of the Agreement, Anthropic will:”
DPA, www.anthropic.com ↗
Audit rights

Once a year

“a similar Audit has not already been conducted less than twelve (12) months prior, unless there are indications of non-compliance and/or it is required by a supervisory authority or other regulatory authority responsible for the enforcement of Applicable Data Protection Laws”
DPA, www.anthropic.com ↗

Documents we track for Anthropic

DPA
checked September 26, 2026 www.anthropic.com ↗
Privacy policy
checked September 26, 2026 www.anthropic.com ↗
Subprocessor list
checked September 26, 2026 www.anthropic.com ↗
Terms of service
checked September 26, 2026 www.anthropic.com ↗

Change history

Tracking since September 26, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.

Anthropic subprocessors FAQ

How many subprocessors does Anthropic use?
Anthropic lists 20 subprocessors on its published list, including Google Cloud Platform, Amazon Web Services, Microsoft Azure, Cloudflare, and Stripe and 15 more.
Where does Anthropic process customer data?
The subprocessors named by Anthropic are located in United States, Worldwide, Canada, South Africa, United Kingdom, and Worldwide (Local to Customer), as stated on its list.
How quickly does Anthropic report a personal data breach to customers?
According to its DPA, Anthropic reports a personal data breach to customers within 48 hours: “Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach”
How much notice does Anthropic give before adding a subprocessor?
Anthropic's DPA gives 15 days' notice of a new subprocessor, the time customers have to object: “Customer may, on the basis of reasonable data privacy or data security concerns, object to Anthropic's use of such Subprocessor by providing Anthropic with written notice of the objection within fifteen (15) days of the date of such notice”
How does Anthropic transfer personal data outside the EU?
Anthropic's DPA relies on standard contractual clauses: “The parties agree that, to the extent required by Applicable Data Protection Laws, the terms of the SCCs Module Two (controller to processor) and/or Module Three (processor to processor), as completed as described in Schedule 3 of this DPA, are hereby incorporated by reference”
When was Anthropic's subprocessor list last checked?
ClauseTrail last checked Anthropic's subprocessor list on September 26, 2026. Lists are re-checked daily.
How do I find out when Anthropic adds or removes a subprocessor?
ClauseTrail monitors Anthropic's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.