Procore Subprocessors List (October 2026): Changes and History
Procore names 35 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Procore subprocessors (October 2026)
| # | Subprocessor | Purpose | Location | Data |
|---|---|---|---|---|
| 1 | Amazon Web Services | Infrastructure Cloud Hosting | S3 Buckets for storage are available to be used in the following regions: United States (default) International Customers, based on region or account configuration: Australia, New Zealand, Brazil, Canada, France, Germany, Hong Kong, Ireland, Italy, Korea, Singapore, South Africa, Sweden, Bahrain, United Kingdom | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, other Personal Data that Customer or its Authorized Users elect to submit to the Services |
| 2 | Amplitude, Inc. | Procore Internal Product Analytics | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 3 | Anthropic, PBC | Access to internal systems via MCPs: Databricks, Honeycomb, Salesforce | United States | i.e.: Authorized User Identifiers, Employment Data, Internet/Network Activity, etc. |
| 4 | Anysphere, Inc. (d/b/a Cursor) | Access to internal systems via MCPs: Databricks, Honeycomb, Salesforce | United States | i.e.: Authorized User Identifiers, Employment Data, Internet/Network Activity, etc. |
| 5 | Auth0, Inc. (a subsidiary of Okta, Inc.) | Product Authentication for Customers using MFA services | United States | i.e.: Authorized User Identifiers, Internet and Network Activity Data |
| 6 | Braze, Inc | Product messaging and notifications | United States | i.e.: Authorized User Identifiers, Internet and Network Activity Data, message content |
| 7 | Catamorphic, Co. (d/b/a LaunchDarkly) | Procore Feature Management | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 8 | Cloudflare, Inc. | Content Delivery Network and web application firewall | United States* | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, other Personal Data that Customer or its Authorized Users elect to submit to the Services |
| 9 | Confluent, Inc. | Data Streaming platform | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, and other data other Personal Data that Customer or its Authorized Users elect to submit to the Services |
| 10 | DataBricks, Inc. | Data Analytics Reporting | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, and other data other Personal Data that Customer or its Authorized Users elect to submit to the Services |
| 11 | Datagrid AI (a wholly owned subsidiary of Procore) | Hosting of and support for certain AI/ML functionality | United States | i.e.: Authorized User Identifiers, Employment Data, Internet/Network Activity, etc. |
| 12 | DataDog, Inc. | Cloud service observations and monitoring. Error reporting, crash analytics and mobile application processing. | United States | i.e.: Authorized User Identifiers, Internet and Network Activity Data |
| 13 | Ecrion Software Inc. | PDF Template Processing | United States | i.e.: Authorized User Identifiers |
| 14 | Google, LLC | Firebase Cloud Messaging: required to send push notifications in Android Speech-to Text: speech to text transcription to facilitate field completion in Android | United States** | i.e.: Ephemeral storage of push notification content i.e.: User recorded speech to text transcription |
| 15 | Hound Technology, Inc. (d/b/a Honeycomb) | Cloud service observations/monitoring, Error reporting, crash analytics | United States | i.e.: Authorized User Identifiers, Internet and Network Activity Data |
| 16 | Microsoft Corporation | Hosting of and support for OpenAI functionality on Azure infrastructure | United States (default) International Customers, based on region or account configuration: United Kingdom | i.e.: Authorized User Identifiers, other Personal Data that Customer or its Authorized Users elect to submit to the Services |
| 17 | Pendo.io, Inc. | In platform usage analytics and messaging | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 18 | Proofpoint, Inc. | Email protection and filtering | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 19 | SmartBear Software, Inc. (d/b/a BugSnag) | Procore Internal Error Message Logging | United States | i.e.: Authorized User Identifiers, Internet and Network Activity Data and Identifiers based on error |
| 20 | Salesforce, Inc. | Customer Account Management, Data Visualization Reporting, SQL | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 21 | Snowflake Inc. | Data Warehouse | United States | i.e.: Authorized User Identifiers, Internet and Network Activity Data, Employment Data |
| 22 | Stream.io, Inc. (d/b/a Getstream.io) | Electronic communications | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 23 | Sumo Logic, Inc. | Application and System log aggregation | United States | i.e.: Authorized User Identifiers |
| 24 | Twilio Inc. | Transactional and Marketing Email | United States | i.e.: Authorized Users Email Identifiers |
| 25 | Boomi, LP | Integration Infrastructure | United Kingdom | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 26 | hh2 Cloud Services, LLC | Sage ERP Connections | N, A | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 27 | Nice Systems, Inc. (d/b/a CXone) | Self-Service training center | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 28 | SkillJar | CRM of training data | United States | i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data |
| 29 | Alloy Labs, Inc. | Compliance workflow engine, case management, and fraud monitoring functionality. | N, A | i.e.: Authorized User Identifiers, Payments-Related Data |
| 30 | GIACT Systems, LLC | Bank Account Verification | N, A | i.e.: Bank Account Data |
| 31 | Middesk, Inc. | Business Entity Verification | N, A | i.e.: Business Identifiers, data required for financial regulatory compliance |
| 32 | Modern Treasury Corporation | Direct Bank Integration/Treasury Management System | N, A | i.e.: Authorized User Identifiers, Internet and Network Activity Data |
| 33 | Moxo, Inc. | Cloud-based Business Interaction Management | N, A | i.e.: Authorized User Identifiers, data required for financial regulatory compliance |
| 34 | Socure Inc. | Verification of Individuals Associated with the Business | N, A | i.e.: Authorized User Identifiers, data required for financial regulatory compliance |
| 35 | VeryGood Security, Inc. | Payment Card Management and Storage | N, A | i.e.: Payment Card Numbers |
Get an email when Procore changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Procore
What Procore's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“Procore shall notify Customer without undue delay and otherwise respond as described in 6.3.1 below.”
DPA, www.procore.com ↗ - Notice of a new subprocessor
-
10 days ahead
“If Customer does not object to a new Subprocessor's engagement within ten (10) days of notice by Procore, that new Subprocessor shall be deemed accepted.”
DPA, www.procore.com ↗ - Transfers outside the EU
-
Standard contractual clauses and the EU–US Data Privacy Framework
“Procore complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK-US Data Bridge Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.”
“For the purpose of international transfers of Personal Data from Brazil, the EU SCCs will be used for transfers to non-adequate countries as per GDPR.”
DPA, www.procore.com ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“Upon termination or expiration of the Agreement, Procore shall (at Customer's written request) anonymize all Customer Personal Data in its possession or control.”
DPA, www.procore.com ↗ - Audit rights
-
Through certifications and audit reports only
“Upon request, Procore shall, no more than once per calendar year make available for Customer's review, a summary copy of an audit report(s) ("Report") that reflects such compliance, a request may be made by emailing [email protected].”
DPA, www.procore.com ↗
Certifications at Procore
What Procore's trust page lists, with the text each one comes from. SOC 2 Type I or Type II: what's the difference?
- SOC 2 Type II
-
Active
“SOC 2 (Type 2)”
Trust page, www.procore.com ↗ - ISO 27001
-
Active
“ISO 27001:2022”
Trust page, www.procore.com ↗ - FedRAMP
-
Active
“FedRAMP® FAQs”
Trust page, www.procore.com ↗
Documents we track for Procore
- AI terms
- checked September 30, 2026 www.procore.com ↗
- DPA
- checked September 30, 2026 www.procore.com ↗
- Privacy policy
- checked September 30, 2026 www.procore.com ↗
- Subprocessor list
- checked October 1, 2026 www.procore.com ↗
- Terms of service
- checked September 30, 2026 www.procore.com ↗
- Trust page
- checked September 30, 2026 www.procore.com ↗
Change history
Tracking since October 1, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Procore subprocessors FAQ
- How many subprocessors does Procore use?
- Procore lists 35 subprocessors on its published list, including Amazon Web Services, Amplitude, Inc., Anthropic, PBC, Anysphere, Inc. (d/b/a Cursor), and Auth0, Inc. (a subsidiary of Okta, Inc.) and 30 more.
- Where does Procore process customer data?
- The subprocessors named by Procore are located in United States, A, N, United Kingdom, Bahrain, and Brazil and 17 other locations, as stated on its list.
- How quickly does Procore report a personal data breach to customers?
- According to its DPA, Procore reports a personal data breach to customers without undue delay, with no set deadline: “Procore shall notify Customer without undue delay and otherwise respond as described in 6.3.1 below.”
- How much notice does Procore give before adding a subprocessor?
- Procore's DPA gives 10 days' notice of a new subprocessor, the time customers have to object: “If Customer does not object to a new Subprocessor's engagement within ten (10) days of notice by Procore, that new Subprocessor shall be deemed accepted.”
- How does Procore transfer personal data outside the EU?
- Procore's DPA relies on standard contractual clauses and the EU–US Data Privacy Framework: “Procore complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK-US Data Bridge Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.”
- Does Procore have a SOC 2 Type II report?
- Yes. Procore's trust page lists a SOC 2 Type II report: “SOC 2 (Type 2)”
- Which security certifications does Procore list?
- Procore's trust page lists SOC 2 Type II, ISO 27001, and FedRAMP.
- When was Procore's subprocessor list last checked?
- ClauseTrail last checked Procore's subprocessor list on October 1, 2026. Lists are re-checked daily.
- How do I find out when Procore adds or removes a subprocessor?
- ClauseTrail monitors Procore's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.