Procore Subprocessors List (October 2026): Changes and History

Procore names 35 subprocessors on its published list. Read from the vendor's own page and re-checked daily.

Last checked October 1, 2026 Official source ↗

Procore subprocessors (October 2026)

# Subprocessor Purpose Location Data
1 Amazon Web Services Infrastructure Cloud Hosting S3 Buckets for storage are available to be used in the following regions: United States (default) International Customers, based on region or account configuration: Australia, New Zealand, Brazil, Canada, France, Germany, Hong Kong, Ireland, Italy, Korea, Singapore, South Africa, Sweden, Bahrain, United Kingdom i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, other Personal Data that Customer or its Authorized Users elect to submit to the Services
2 Amplitude, Inc. Procore Internal Product Analytics United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
3 Anthropic, PBC Access to internal systems via MCPs: Databricks, Honeycomb, Salesforce United States i.e.: Authorized User Identifiers, Employment Data, Internet/Network Activity, etc.
4 Anysphere, Inc. (d/b/a Cursor) Access to internal systems via MCPs: Databricks, Honeycomb, Salesforce United States i.e.: Authorized User Identifiers, Employment Data, Internet/Network Activity, etc.
5 Auth0, Inc. (a subsidiary of Okta, Inc.) Product Authentication for Customers using MFA services United States i.e.: Authorized User Identifiers, Internet and Network Activity Data
6 Braze, Inc Product messaging and notifications United States i.e.: Authorized User Identifiers, Internet and Network Activity Data, message content
7 Catamorphic, Co. (d/b/a LaunchDarkly) Procore Feature Management United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
8 Cloudflare, Inc. Content Delivery Network and web application firewall United States* i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, other Personal Data that Customer or its Authorized Users elect to submit to the Services
9 Confluent, Inc. Data Streaming platform United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, and other data other Personal Data that Customer or its Authorized Users elect to submit to the Services
10 DataBricks, Inc. Data Analytics Reporting United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data, and other data other Personal Data that Customer or its Authorized Users elect to submit to the Services
11 Datagrid AI (a wholly owned subsidiary of Procore) Hosting of and support for certain AI/ML functionality United States i.e.: Authorized User Identifiers, Employment Data, Internet/Network Activity, etc.
12 DataDog, Inc. Cloud service observations and monitoring. Error reporting, crash analytics and mobile application processing. United States i.e.: Authorized User Identifiers, Internet and Network Activity Data
13 Ecrion Software Inc. PDF Template Processing United States i.e.: Authorized User Identifiers
14 Google, LLC Firebase Cloud Messaging: required to send push notifications in Android Speech-to Text: speech to text transcription to facilitate field completion in Android United States** i.e.: Ephemeral storage of push notification content i.e.: User recorded speech to text transcription
15 Hound Technology, Inc. (d/b/a Honeycomb) Cloud service observations/monitoring, Error reporting, crash analytics United States i.e.: Authorized User Identifiers, Internet and Network Activity Data
16 Microsoft Corporation Hosting of and support for OpenAI functionality on Azure infrastructure United States (default) International Customers, based on region or account configuration: United Kingdom i.e.: Authorized User Identifiers, other Personal Data that Customer or its Authorized Users elect to submit to the Services
17 Pendo.io, Inc. In platform usage analytics and messaging United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
18 Proofpoint, Inc. Email protection and filtering United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
19 SmartBear Software, Inc. (d/b/a BugSnag) Procore Internal Error Message Logging United States i.e.: Authorized User Identifiers, Internet and Network Activity Data and Identifiers based on error
20 Salesforce, Inc. Customer Account Management, Data Visualization Reporting, SQL United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
21 Snowflake Inc. Data Warehouse United States i.e.: Authorized User Identifiers, Internet and Network Activity Data, Employment Data
22 Stream.io, Inc. (d/b/a Getstream.io) Electronic communications United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
23 Sumo Logic, Inc. Application and System log aggregation United States i.e.: Authorized User Identifiers
24 Twilio Inc. Transactional and Marketing Email United States i.e.: Authorized Users Email Identifiers
25 Boomi, LP Integration Infrastructure United Kingdom i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
26 hh2 Cloud Services, LLC Sage ERP Connections N, A i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
27 Nice Systems, Inc. (d/b/a CXone) Self-Service training center United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
28 SkillJar CRM of training data United States i.e.: Authorized User Identifiers, Employment Data, Internet and Network Activity Data
29 Alloy Labs, Inc. Compliance workflow engine, case management, and fraud monitoring functionality. N, A i.e.: Authorized User Identifiers, Payments-Related Data
30 GIACT Systems, LLC Bank Account Verification N, A i.e.: Bank Account Data
31 Middesk, Inc. Business Entity Verification N, A i.e.: Business Identifiers, data required for financial regulatory compliance
32 Modern Treasury Corporation Direct Bank Integration/Treasury Management System N, A i.e.: Authorized User Identifiers, Internet and Network Activity Data
33 Moxo, Inc. Cloud-based Business Interaction Management N, A i.e.: Authorized User Identifiers, data required for financial regulatory compliance
34 Socure Inc. Verification of Individuals Associated with the Business N, A i.e.: Authorized User Identifiers, data required for financial regulatory compliance
35 VeryGood Security, Inc. Payment Card Management and Storage N, A i.e.: Payment Card Numbers

Get an email when Procore changes its subprocessors

ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.

Track Procore free

Key DPA terms at Procore

What Procore's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?

Breach notification

Without undue delay, with no set deadline

“Procore shall notify Customer without undue delay and otherwise respond as described in 6.3.1 below.”
DPA, www.procore.com ↗
Notice of a new subprocessor

10 days ahead

“If Customer does not object to a new Subprocessor's engagement within ten (10) days of notice by Procore, that new Subprocessor shall be deemed accepted.”
DPA, www.procore.com ↗
Transfers outside the EU

Standard contractual clauses and the EU–US Data Privacy Framework

“Procore complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK-US Data Bridge Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.”
“For the purpose of international transfers of Personal Data from Brazil, the EU SCCs will be used for transfers to non-adequate countries as per GDPR.”
DPA, www.procore.com ↗
Customer data after the contract ends

Deleted or returned when the contract ends

“Upon termination or expiration of the Agreement, Procore shall (at Customer's written request) anonymize all Customer Personal Data in its possession or control.”
DPA, www.procore.com ↗
Audit rights

Through certifications and audit reports only

“Upon request, Procore shall, no more than once per calendar year make available for Customer's review, a summary copy of an audit report(s) ("Report") that reflects such compliance, a request may be made by emailing [email protected].”
DPA, www.procore.com ↗

Certifications at Procore

What Procore's trust page lists, with the text each one comes from. SOC 2 Type I or Type II: what's the difference?

SOC 2 Type II

Active

“SOC 2 (Type 2)”
Trust page, www.procore.com ↗
ISO 27001

Active

“ISO 27001:2022”
Trust page, www.procore.com ↗
FedRAMP

Active

“FedRAMP® FAQs”
Trust page, www.procore.com ↗

Documents we track for Procore

AI terms
checked September 30, 2026 www.procore.com ↗
DPA
checked September 30, 2026 www.procore.com ↗
Privacy policy
checked September 30, 2026 www.procore.com ↗
Subprocessor list
checked October 1, 2026 www.procore.com ↗
Terms of service
checked September 30, 2026 www.procore.com ↗
Trust page
checked September 30, 2026 www.procore.com ↗

Change history

Tracking since October 1, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.

Procore subprocessors FAQ

How many subprocessors does Procore use?
Procore lists 35 subprocessors on its published list, including Amazon Web Services, Amplitude, Inc., Anthropic, PBC, Anysphere, Inc. (d/b/a Cursor), and Auth0, Inc. (a subsidiary of Okta, Inc.) and 30 more.
Where does Procore process customer data?
The subprocessors named by Procore are located in United States, A, N, United Kingdom, Bahrain, and Brazil and 17 other locations, as stated on its list.
How quickly does Procore report a personal data breach to customers?
According to its DPA, Procore reports a personal data breach to customers without undue delay, with no set deadline: “Procore shall notify Customer without undue delay and otherwise respond as described in 6.3.1 below.”
How much notice does Procore give before adding a subprocessor?
Procore's DPA gives 10 days' notice of a new subprocessor, the time customers have to object: “If Customer does not object to a new Subprocessor's engagement within ten (10) days of notice by Procore, that new Subprocessor shall be deemed accepted.”
How does Procore transfer personal data outside the EU?
Procore's DPA relies on standard contractual clauses and the EU–US Data Privacy Framework: “Procore complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK-US Data Bridge Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.”
Does Procore have a SOC 2 Type II report?
Yes. Procore's trust page lists a SOC 2 Type II report: “SOC 2 (Type 2)”
Which security certifications does Procore list?
Procore's trust page lists SOC 2 Type II, ISO 27001, and FedRAMP.
When was Procore's subprocessor list last checked?
ClauseTrail last checked Procore's subprocessor list on October 1, 2026. Lists are re-checked daily.
How do I find out when Procore adds or removes a subprocessor?
ClauseTrail monitors Procore's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.