1. OVERVIEW & SCOPE
To provide our secure file sharing and workspace services, Prudentbit Technologies (“Prudentbit”, “we”, or “us”) partners with select third-party service providers (“Sub-processors”).
This page fulfills our disclosure commitments under Section 4 of our Terms of Service (Schedule 2: Data Processing Agreement) and Section 4.1(c) of our Privacy Policy. Each sub-processor is bound by written contractual obligations to handle data strictly on our instructions and in compliance with applicable data protection laws.
2. SECURITY & ZERO-KNOWLEDGE ARCHITECTURE
ImmuneFiles is designed around end-to-end and client-side encryption. This architecture materially limits what our sub-processors can access:
- Encrypted Storage: Infrastructure providers host only encrypted binary blobs. Decryption keys are generated and held on user devices and are never shared with hosting vendors.
- In-house AI Processing: All sensitive data detection and masking models run directly on our own infrastructure. Customer files are never sent to third-party AI companies (e.g., OpenAI, Anthropic) or used to train external models.
- Bring Your Own Storage (BYOS): Organizations configured with BYOS store files directly within their own corporate cloud tenancies (such as AWS S3 or Azure), bypassing ImmuneFiles storage sub-processors entirely.
3. INFRASTRUCTURE & HOSTING SUB-PROCESSORS
These entities provide the primary cloud hosting, compute power, and physical infrastructure for running the ImmuneFiles platform.
| Provider | Purpose | Data Location |
|---|---|---|
Amazon Web Services (AWS) Amazon Web Services, Inc. | Cloud hosting, computing infrastructure, and encrypted object storage. Stores encrypted data blobs only. Plaintext files and decryption keys are never accessible. | India (Mumbai), US, EU (based on customer tenant region) |
NeevCloud NeevCloud Technologies Private Limited | Sovereign cloud compute and local Indian data residency hosting. Empaneled Indian data center hosting encrypted infrastructure. | India |
4. OPERATIONAL SERVICES
These vendors support ancillary application services, such as delivering email notifications and handling subscription payments. They never receive or store customer files.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
Amazon SES Amazon Web Services, Inc. | Transactional email delivery (account verification, security alerts, and share notifications). | Processes recipient email addresses and notification headers only. | India / United States |
Razorpay / Stripe Razorpay Software Pvt. Ltd. / Stripe, Inc. | Subscription billing and payment processing for commercial accounts. | Processes billing contact info and payment tokens. No customer file data. | India / United States |
Google Analytics Google LLC | Website traffic analytics on public marketing pages (www.immunefiles.com). | Used on public marketing pages only. Not present inside authenticated workspaces. | United States |
5. SECURITY STANDARDS & DUE DILIGENCE
Before onboarding any sub-processor, Prudentbit executes a formal security and compliance evaluation:
- Contractual Safeguards: All sub-processors must enter into a Data Processing Addendum (DPA) incorporating terms equivalent to our Customer DPA, including strict confidentiality and data minimization terms.
- Certifications: Infrastructure partners are expected to maintain recognized security standards, including ISO 27001, SOC 2 Type II, or equivalent independent accreditations.
- Periodic Reviews: We regularly assess our vendors' operational reliability and security postures.
6. UPDATES & CUSTOMER OBJECTIONS
In accordance with Clause 4.2 of our Data Processing Agreement, we provide account administrators with at least 30 days advance notice before engaging any new sub-processor to handle customer personal data.
Customers have the right to object to any new sub-processor on reasonable data protection grounds within the 30-day notice window by contacting contact@prudentbit.com. If an objection cannot be resolved amicably, customers may terminate the affected service pursuant to Section 4.3 of our DPA.
7. CONTACT
For inquiries or questions regarding our sub-processors and privacy practices, please contact: