Subprocessors
Third-party service providers that Tendera uses to deliver the platform. This list is the source of truth referenced by our Master Services Agreement and Business Associate Agreement.
Last updated: August 27, 2026What is a subprocessor? A vendor that receives customer data (including PHI) in the course of helping us provide the Tendera service. Every subprocessor is covered by an executed Business Associate Agreement (BAA) with Diana Software LLC before it handles PHI, or has an active BAA request in progress and does not yet receive PHI-bearing data.
Scope. This list covers vendors that touch customer data. Vendors that do not touch customer data (our bank, DNS registrar, source control, etc.) are listed separately below for transparency but are not subprocessors.
| Vendor | Purpose | Data category | BAA status | Location |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting: application compute (ECS Fargate), database (RDS MySQL, encrypted at rest), session store (ElastiCache Redis), object storage (S3), logging (CloudWatch), container registry (ECR), and outbound transactional email (SES). | All customer data, including PHI. Encrypted at rest and in transit. | Signed | United States (us-east-1) |
| Sentry | Application error monitoring for the Tendera web and API tiers. Captures uncaught exceptions with stack traces plus limited request metadata (URL, method, user agent). | Error events + stack traces + limited request metadata. PHI excluded via server-side scrubbing configuration. | Under review | United States |
| Plaid | Bank account verification and ACH transfer authorization for customers that use billing integrations. Only reached when a customer explicitly opts in to connect a bank account. | Financial account identifiers for the customer's payers. No PHI transits Plaid. | Requested | United States |
The following vendors are part of Diana Software LLC's business operations but do not receive customer data or PHI. We list them so customers can see we have accounted for them.
- Mercury — Business banking. Handles Diana Software LLC's own accounts payable and receivable. Does not receive customer data.
- IONOS — Domain name registrar for tendera.care. Resolves DNS; does not process customer data.
- GitHub — Source control and CI/CD (GitHub Actions). Stores application source code; does not receive customer data or PHI.
Anthropic (Claude Code) is a developer tool used by Diana Software LLC engineering. Claude Code is not embedded in the Tendera runtime; production AI features run on AWS Bedrock, which is covered by our AWS Business Associate Agreement.
When an engineer uses Claude Code to run operational commands against production infrastructure (for example, applying a database migration), those commands execute under Diana Software's own AWS credentials, are reviewed turn-by-turn by the operator, and are recorded in AWS infrastructure logs. Prompts and command output may transit Anthropic's platform in the ordinary course of Claude Code use; developer-directed queries are scoped to schema, deployment, and diagnostic activity rather than to resident-chart review.
When we add a new subprocessor that will handle customer data or PHI, we will update this page and notify customers with active subscriptions by email at least 30 days before the new subprocessor goes live. During that window, customers may object in writing; if we cannot resolve the objection, the customer may terminate the affected subscription for cause under the Master Services Agreement.
To be notified of changes, ensure your account's admin contact email is current, or email privacy@tendera.care to be added to a change-notification list.