Trust Center
Sub-processors
Last updated: May 9, 2026 · Version 1.0
These are the third-party service providers we use to deliver McPortal. Each processes only the minimum data needed to perform its function. Customers who sign our DPA authorize the list below at signature.
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Neon ↗ | Serverless Postgres — primary database | All customer and user data, including encrypted OAuth tokens | United States |
| Cloudflare ↗ | Workers runtime for the MCP server endpoint and TLS termination | OAuth tokens (decrypted in memory only during a tool call), tool-call payloads in transit | Global edge network |
| Vercel ↗ | Hosting for the web dashboard | Request logs, browser session data | United States |
| Stripe ↗ | Subscription billing and payments | Billing email, customer ID, subscription status. Card data is collected directly by Stripe and never touches McPortal. | United States |
| Resend ↗ | Transactional email — sign-in links, invitations, billing notices | Email address, magic-link tokens | United States |
| Google ↗ | Identity provider for Google sign-in (only if a user chooses Google sign-in) | Email, name, profile photo URL | Global |
Notice of changes
We will give at least 30 days’ prior notice before adding a new sub-processor or materially changing how an existing one processes customer personal data. Customers under our DPA may object during the notice period; if we cannot accommodate the objection, you may terminate the affected portion of the service.
To receive change notices by email, subscribe at trust@orchestrategies.com. We also update the “last updated” date and version on this page with every change.
What we do not consider sub-processors
- Integrations you connect (Slack, GitHub, Google Workspace, Microsoft 365, Jira, Linear, Asana, Monday.com, Dropbox, etc.). These are independent third-party services that you, as the controller, instruct us to access on your behalf. They are not sub-processors of McPortal.
- LLM providers called by your end users (Anthropic, OpenAI, etc.). McPortal does not invoke LLMs on your behalf; the model client your team uses calls McPortal.
Related
- Data Processing Agreement — incorporates this list as Annex III.
- Security — technical and organizational measures.
- Privacy policy — what we collect and why.