Trust
Subprocessors
Tessera relies on two distinct categories of third party: a small number of named corporate service providers that support the control plane, and a rotating pool of independent storage providers that hold encrypted shards. Both are disclosed here.
Snapshot pending publication
A subprocessor is any third party that processes data on our behalf in the course of delivering the service. We keep the list short by design: the fewer parties involved, the fewer parties you have to assess.
It is worth being precise about what each category can actually see. Corporate subprocessors support the control plane and may therefore process account identifiers and placement metadata. Storage providers hold encrypted shards and can see neither filenames, nor file boundaries, nor content — a single shard is not decryptable, and no provider holds more than one shard of a slab.
Corporate subprocessors
These parties support the Tessera control plane, billing, and communications. Each is bound by a data processing agreement and is assessed before onboarding.
| Subprocessor | Purpose | Data categories | Location | Attestations |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Control-plane compute, managed networking, and encrypted backups | Account identifiers, object placement metadata, request logs | — | SOC 2 Type II, SOC 3, ISO/IEC 27001/27017/27018, PCI DSS, CSA STAR |
| — | Authoritative DNS and edge TLS termination for the public website | IP addresses, request metadata | Global anycast | — |
| — | Transactional email — account, security, and incident notifications | Email address, message content | — | — |
| — | Payment processing and invoicing | Billing name, billing address, payment instrument tokens | — | PCI DSS Level 1 |
| — | Application error and performance monitoring for the control plane | Stack traces, request identifiers, account identifiers | — | — |
Attestations listed are those held by the subprocessor, not by Tessera.
Storage providers
Every object is split into 15 encrypted shards and distributed to 15 independent storage providers on the Sia network — separate businesses, on separate hardware, under separate legal ownership, in a spread of jurisdictions. This is what makes the durability and survivability properties possible, and it is also why the disclosure below is aggregate rather than nominal.
What a storage provider can access
- One encrypted shard per slab. Not a file, not a fragment of readable content — ciphertext produced after erasure coding.
- No filename, path, content type, or object size. Those fields do not exist in anything transmitted to a provider.
- No account identity. Providers see a storage contract held by Tessera, not your account.
- No path to reconstruction. Recovering any plaintext requires 10 shards from 10 different providers plus key material held by your client.
Distribution by jurisdiction
Aggregate composition of the provider pool at the date of this snapshot. Providers are continuously vetted, added, and retired based on measured availability, throughput, and contract performance, so this changes without notice.
| Jurisdiction | Providers in pool | Share of shards |
|---|---|---|
| Germany | — | — |
| Netherlands | — | — |
| France | — | — |
| Finland | — | — |
| United Kingdom | — | — |
| United States | — | — |
| Canada | — | — |
| Singapore | — | — |
| Other | — | — |
Aggregate snapshot. Providers are continuously re-curated, so composition changes without notice. The exact provider set at any moment is available to customers on request under NDA.
Why individual providers are not named here
Three reasons, in order of how much we expect you to care about them. First, the set is not stable: shards move as providers are retired and replaced, so a published list would be wrong within days and would give you false precision about where your data sits. Second, provider selection is the part of Tessera that is genuinely difficult — publishing a live roster hands that work to anyone who wants it. Third, naming a provider tells you nothing actionable about your risk, because no individual provider can affect the confidentiality or availability of your data.
If your compliance programme requires the current provider set — or a pool constrained to specific jurisdictions — we provide both. The former is available under NDA on request; the latter is an Enterprise configuration.
Change notification
We will notify customers at least 30 days before adding or replacing a corporate subprocessor that processes personal data, giving you time to object. Changes to the storage provider pool are continuous and operational in nature and are not individually notified — that rotation is a durability mechanism, not a change of service.
To be notified of subprocessor changes, or to raise an objection, contact privacy@PLACEHOLDER_DOMAIN.example.