Monverdo · Security and data
Who else is involved
A subprocessor is any company Monverdo uses that could come into contact with personal data.
The list
How this list is maintained
A provider is added here before it starts handling any data, never afterwards. The date at the top is the date the list was last checked against reality, not the date the page was last edited.
Anyone on the waitlist is notified of a material change to this list. Business customers under a data-processing agreement receive 30 days’ notice of a new subprocessor, with the ability to object before any data reaches it.
Regions in detail, account structures, plan tiers, software versions and internal tooling. Naming a vendor is transparency. Publishing a map of the configuration is a gift to anyone attacking it.
Each provider that handles personal data does so under a written agreement meeting POPIA operator requirements and, where relevant, GDPR Article 28.
Why this list is short
Monverdo is still in development. There is no product database, no hosting for user records, no payment processing and no error monitoring, because there is nothing yet to host, charge for or monitor.
This list will grow substantially, most of it arriving with the release that introduces accounts. Hosting, a database, payments, transactional email and error monitoring all become subprocessors at that point. Each will be added here before it goes live.
A short list today is a statement about how far the product has come, not a claim about how carefully it is being built. The security page is explicit about which protections are designed but not yet running.
If you intend to use Monverdo with client data, you become the responsible party and Monverdo becomes the operator. A data-processing agreement covers that relationship. Request one at legal@monverdo.com.