Sub-processors
Effective 26 August 2026. Last updated 26 August 2026. This page lists every third party Tasirio uses that may handle data you give us, or data about the people in your organisation.
Who we are
The contracting party is Smartware Holdings, Inc., a Wyoming corporation, doing business as "Tasirio". Office: 4637 Indian Rock Drive, Fort Worth, TX 76244, United States.
What this page covers
A sub-processor is a third party we use that may handle data you give us, or data about the people in your organisation. This page lists all of them. It also lists the providers that only touch our own business records, so you can see the whole picture and check that the first list is short.
Two things it does not cover:
- Systems you connect to Tasirio — Microsoft 365, AWS, Salesforce, your ERP and so on. We read from those. We are not their processor and they are not ours.
- Destinations you configure yourself — your security-monitoring platform, your ticketing system, your chat webhook, your own cloud key vault. See "Places we send data at your instruction" below.
Where everything runs
All customer data at rest is held in Microsoft Azure, East US 2, United States. Every resource in our Azure estate that holds customer data is in that region. A small number of the Azure services we use are not region-scoped by design; none of them processes customer data.
We operate in one region and offer no other data-residency option. There is no EU, UK or Canadian hosting option today, and we do not offer one on request.
One qualification, because it is real: transactional email and text messages are processed in the European Union by our email provider, so an alert email leaves the United States. You choose who receives alerts, and you can turn alerting off. Everything else stays in East US 2.
Part A — Sub-processors that may process customer data
| Provider | What it does for us | What it receives | Where it processes |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation) | All hosting: application servers, the database, the secrets vault, evidence storage, and application logs. | Everything Tasirio holds: your connector settings, the permission metadata we collect from your systems, findings, the activity log, evidence packs, and your user records. Finding detail is encrypted by the application before it is written, under a key held only in Azure Key Vault. Connector credentials are held in the vault and referenced — never stored in the database. | United States — East US 2 |
| Brevo (Sendinblue SAS) | Transactional email, and text messages where enabled. | Recipient names and email addresses, your organisation's name, and the content of the message. Alert emails include the severity, title and affected resource name of each finding in the digest. A text message carries a headline only — never a resource name or a finding title. Evidence packs are never attached to email. | European Union |
| Microsoft Azure OpenAI | Optional AI features inside the product: explaining findings and drafting remediation steps. | Finding types, severities and counts, and the question a user types. Prompts are redacted before they are sent — identifiers are removed or replaced. This runs on Tasirio’s own Azure OpenAI resource in East US 2, inside the same Azure subscription as the rest of the service, so no separate AI vendor receives your data. Microsoft does not use content submitted to Azure OpenAI to train its models. No document, file, message, email, calendar or record content is ever sent. Customer content is not used to train any model. If you do not use the AI features, nothing is sent at all. | United States |
Notes to the table
- The AI features are optional. They can be left unused, and nothing reaches the model provider unless someone in your organisation uses them.
- Text messaging is off by default and is enabled only if you ask for it. We list the channel because the capability exists and Brevo would receive the message if it were enabled.
- Email leaves the United States. Brevo processes in the European Union, so alert emails — which carry a finding's severity, title and affected resource name — are transferred from the United States to the European Union. Our Data Processing Addendum covers the transfer.
Part B — Providers that touch only Tasirio's own business records
These do not receive your permission metadata or your findings. One of them does receive a list of which of your systems we are connected to, and we would rather say so than let it read as a blanket "nothing from your systems".
| Provider | What it does for us | What it receives | Where it processes |
|---|---|---|---|
| Intuit — QuickBooks Online | Invoicing. Tasirio's own business records. | Your legal name, billing email and address, purchase-order number, payment terms, and invoice lines that name the connectors you have licensed — that is, which of your systems Tasirio is connected to. No permission metadata, no findings, no evidence. | United States |
| hCaptcha (Intuition Machines, Inc.) | Blocks bots on our public demo, assessment and booking forms. | The challenge token and the website visitor's IP address. Nothing from your Tasirio account, and no customer data. | United States |
Not sub-processors
GitHub
Hosts our source code. It holds no customer data. The sample connector responses committed to the repository record field names, types and count ranges only, and an automated check in our build rejects any that contain identifiers, quoted values or token-shaped strings.
Places we send data at your instruction
You choose these destinations and you control them. We transmit your own findings to them, and in the case of ticketing we create and update records in them, because you configured it. We are not the controller of what happens next.
- Security monitoring — Splunk, Microsoft Sentinel, or a webhook you name. Receives findings, including the affected resource and description.
- Ticketing — Slack, Jira, ServiceNow, Zendesk, Syncro, or a webhook you name. We create tickets there, update their status, and add comments, using credentials you supply. Note that ServiceNow and Zendesk can also be systems we govern; where the same system is both, we read it as a governed system and write to it as your ticket destination.
- Alert webhooks — your Slack or Teams channel. Receives severity, title and resource.
- Your own key vault — Azure Key Vault, AWS Secrets Manager, Google Secret Manager, or Oracle Vault, if you choose to hold your connector credentials yourself. You can rotate or revoke that key at any time, and doing so makes the stored secrets unusable to us.
- Your own AI assistant — the "copy this prompt" feature. You paste it; we do not send it. The resource name is removed by default.
What we do not use
No analytics, no advertising pixels, no session recording, and no error-monitoring service. There is nothing watching you use the product. The signed-in Tasirio application makes no third-party requests at all. On our public marketing pages the only third-party requests are the bot-protection widget listed above and web fonts, which are not loaded inside the application.
Before we add a new one
We will tell you before a new sub-processor starts handling your data — not after.
- We give 30 days' notice before a new or replacement sub-processor begins processing customer data.
- You may object in writing on reasonable data-protection grounds within that 30-day notice period. We will work with you to resolve it. If we cannot, you may stop using the affected part of the service without penalty for the rest of your term; and where the sub-processor cannot be separated from the service, you may end the agreement and receive a pro-rata refund of prepaid fees for the unused period.
- Notice goes by email to the contacts your administrators have listed in the product, and to anyone subscribed below. This page is updated at the same time, and the change is recorded in the history at the bottom.
- If a sub-processor has to be replaced urgently — it shuts down, or it presents a security risk — we will make the change and tell you as soon as we can, with the reason. Your objection right then runs from that notice.
How to get the notice
Email privacy@tasirio.com with the subject "subprocessor notice" and the address you want it sent to. We will add it to the list and confirm. The list is maintained by hand, so please tell us if your notification address changes.
Change history
| Date | Change |
|---|---|
| 26 August 2026 | First published. |
Every addition, removal, or change of purpose or location will be added here, and prior versions stay available on request.
Keeping this page true
This list is short on purpose. A list nobody updates is worse than no list at all, so this page, the sub-processor annex to our Data Processing Addendum, and the list served inside the product are kept identical.
Questions about anything on this page: privacy@tasirio.com.
Related: Privacy Policy · Terms of Service · Data Processing Addendum · Sub-processors · Security & Trust