Trust

Subprocessors

Tessera relies on two distinct categories of third party: a small number of named corporate service providers that support the control plane, and a rotating pool of independent storage providers that hold encrypted shards. Both are disclosed here.

Snapshot pending publication

The storage provider figures below are populated from the provider registry before general availability. Corporate subprocessor rows marked with a dash are pending confirmation. This page will not go live with unfilled values.

A subprocessor is any third party that processes data on our behalf in the course of delivering the service. We keep the list short by design: the fewer parties involved, the fewer parties you have to assess.

It is worth being precise about what each category can actually see. Corporate subprocessors support the control plane and may therefore process account identifiers and placement metadata. Storage providers hold encrypted shards and can see neither filenames, nor file boundaries, nor content — a single shard is not decryptable, and no provider holds more than one shard of a slab.

Corporate subprocessors

These parties support the Tessera control plane, billing, and communications. Each is bound by a data processing agreement and is assessed before onboarding.

SubprocessorPurposeData categoriesLocationAttestations
Amazon Web Services, Inc.Control-plane compute, managed networking, and encrypted backupsAccount identifiers, object placement metadata, request logsSOC 2 Type II, SOC 3, ISO/IEC 27001/27017/27018, PCI DSS, CSA STAR
Authoritative DNS and edge TLS termination for the public websiteIP addresses, request metadataGlobal anycast
Transactional email — account, security, and incident notificationsEmail address, message content
Payment processing and invoicingBilling name, billing address, payment instrument tokensPCI DSS Level 1
Application error and performance monitoring for the control planeStack traces, request identifiers, account identifiers

Attestations listed are those held by the subprocessor, not by Tessera.

Storage providers

Every object is split into 15 encrypted shards and distributed to 15 independent storage providers on the Sia network — separate businesses, on separate hardware, under separate legal ownership, in a spread of jurisdictions. This is what makes the durability and survivability properties possible, and it is also why the disclosure below is aggregate rather than nominal.

What a storage provider can access

  • One encrypted shard per slab. Not a file, not a fragment of readable content — ciphertext produced after erasure coding.
  • No filename, path, content type, or object size. Those fields do not exist in anything transmitted to a provider.
  • No account identity. Providers see a storage contract held by Tessera, not your account.
  • No path to reconstruction. Recovering any plaintext requires 10 shards from 10 different providers plus key material held by your client.

Distribution by jurisdiction

Aggregate composition of the provider pool at the date of this snapshot. Providers are continuously vetted, added, and retired based on measured availability, throughput, and contract performance, so this changes without notice.

JurisdictionProviders in poolShare of shards
Germany
Netherlands
France
Finland
United Kingdom
United States
Canada
Singapore
Other

Aggregate snapshot. Providers are continuously re-curated, so composition changes without notice. The exact provider set at any moment is available to customers on request under NDA.

Why individual providers are not named here

Three reasons, in order of how much we expect you to care about them. First, the set is not stable: shards move as providers are retired and replaced, so a published list would be wrong within days and would give you false precision about where your data sits. Second, provider selection is the part of Tessera that is genuinely difficult — publishing a live roster hands that work to anyone who wants it. Third, naming a provider tells you nothing actionable about your risk, because no individual provider can affect the confidentiality or availability of your data.

If your compliance programme requires the current provider set — or a pool constrained to specific jurisdictions — we provide both. The former is available under NDA on request; the latter is an Enterprise configuration.

Change notification

We will notify customers at least 30 days before adding or replacing a corporate subprocessor that processes personal data, giving you time to object. Changes to the storage provider pool are continuous and operational in nature and are not individually notified — that rotation is a durability mechanism, not a change of service.

To be notified of subprocessor changes, or to raise an objection, contact privacy@PLACEHOLDER_DOMAIN.example.

Security & compliance Vulnerability disclosure