Only 19 of 54 Martech Vendors Publish a Sub-Processor List Where a Crawler Can Read It
By Dev Anand, AI Tooling & Automation Safety. Last updated: 2026-08-16
The AI-training audit we ran on these same vendors kept turning up one sentence: "our third-party AI providers are contractually prohibited from training on your data." Which providers? That question has a document, and we went to see how many vendors publish it in the open.
How many martech vendors publish a crawlable sub-processor list?
We used the same 54-vendor corpus as our other research audits. For each, we probed roughly sixty paths where sub-processor lists conventionally live (/legal/subprocessors, /subprocessors, /company/legal/subprocessors, /legal/dpa, /subprocessor-list, trust.<domain>/subprocessors and variants across the origin and its trust, legal, security and privacy subdomains). A page counted only if it was a dedicated sub-processor or DPA page, by URL or heading, and its served text named at least three recognisable providers (AWS, Google Cloud, Azure, Cloudflare, OpenAI, Twilio, SendGrid, Snowflake and so on). That rule excludes DPA boilerplate that promises a list without giving one, and it excludes a privacy policy or AI policy that happens to name a few providers, which is why the count is stricter than a first pass suggested. The same corpus is the one we used for the AI training-data audit.
| Result | Vendors | Share |
|---|---|---|
| Dedicated, crawlable sub-processor list naming 3+ providers | 19 | 35.2% |
| Not found at standard paths, or found but not crawlable | 35 | 64.8% |
Just over a third. For a document that every vendor in the corpus almost certainly maintains, that is a small number, and it is a number about findability and machine-readability rather than existence.
Who publishes one, and how detailed is it?
The nineteen, with the count of recognisable providers we detected on the page: Writesonic 24 (in its DPA), Sprout Social 16, Qualified 16, Klaviyo 15, Outreach 14, ZoomInfo 14, Jasper 14, Amplitude 12, Mixpanel 12, ActiveCampaign 11, Hootsuite 11, Pipedrive 10, Copper 10, Mailchimp 10, Customer.io 8, HockeyStack 7 (in its DPA), Vidyard 7, Demio 7, Semrush 5.
Writesonic's is the standout, and it connects to a finding from the training-data audit: Writesonic is also one of the six vendors that commits in a legal document not to train on customer data, and its sub-processor list names the model providers it uses. The two documents together let a customer see exactly which AI vendors receive their prompts and on what terms. That is what disclosure is supposed to look like.
Semrush's list, at five named providers, is the thinnest dedicated page in the set. Apollo and Lusha, whose whole business is moving contact data between systems, each name a few providers in an AI policy or privacy notice but publish no dedicated list we could find, and are counted as not found.
Want to put this into practice?
Reachium automates LinkedIn outreach, content publishing, and inbox management in one platform.
Start Free →Who does not, and where is the list instead?
Thirty-five vendors have no crawlable dedicated list at a standard path. Some almost certainly have no public list. Others definitely publish one, somewhere else or in some other form, and it is worth being precise about the pattern.
HubSpot's sub-processor information sits in its trust center, a client-rendered portal. Salesforce's lives in its data processing addendum, a PDF linked from a legal index. Braze is the sharpest case: it publishes a dedicated page at /company/legal/subprocessors that returns 290KB of HTML containing not one provider name, because the list renders in the browser; a crawler, or our probe, receives an empty shell. Iterable's security page hands off to a trust-center portal that behaves the same way, and Loom's data is covered by Atlassian's sub-processor list on atlassian.com, a different domain from the one we probed. Our probe reads served HTML at addresses; it does not run JavaScript, log into portals or open PDFs, and we did not want to guess our way into claiming vendors "have no list" when they have one behind glass.
So the honest framing is this: for 35 of 54 vendors, a procurement reviewer or a crawler starting from the domain cannot read the sub-processor list at any conventional address. Whether that is because it does not exist, is in a portal, or is on a page that only a browser can render, the practical effect on a buyer doing due diligence at speed is the same. It is the same served-versus-rendered gap we found on pricing pages, now on a compliance document.
The 35 also include every AI SDR platform in the corpus except Qualified (11x, Artisan, Regie.ai, AiSDR and Relevance AI have none we could find), which matters because those are the products most likely to be routing customer conversations through third-party LLMs.
Why does a public sub-processor list matter more now?
Two reasons. The first is old: GDPR Article 28 requires a processor to inform the controller of its sub-processors and give it a chance to object, and a public, dated list is the cleanest way to meet that duty. The second is new. Every martech vendor now runs some customer data through a foundation-model provider, and the sub-processor list is the only public document that names which one. Our training-data audit found six vendors addressing "only third-party providers" in their AI terms without saying who the providers are. The sub-processor list is where that gap should close, and for two thirds of the corpus a crawler cannot find it.
There is also the martech stack argument we keep making: every additional tool is another sub-processor list nobody has read. If the list is not crawlable, it will not get read.
What are the limits of this audit?
The probe reads served HTML at roughly 60 conventional paths per vendor. It does not run JavaScript, open trust portals (SafeBase, Vanta, Drata, Conveyor), read PDFs, or log in. Vendors known to publish sub-processor information by those routes are on the "not found" list on purpose and are named as such above. The dedicated-page rule excludes privacy or AI policies that name a few providers in passing; the three-provider threshold excludes pages that mention sub-processors without listing them. A first pass with a looser rule counted 20; the stricter rule reported here counts 19, and both numbers are in the data file. Snapshot of 2026-08-16.
Want to put this into practice?
Reachium automates LinkedIn outreach, content publishing, and inbox management in one platform.
Start Free →FAQ
How many martech vendors publish a sub-processor list?
19 of 54 in this audit (35%) publish a dedicated one at a standard, crawlable HTML address naming three or more recognisable providers. The other 35 either publish it in a portal, PDF or client-rendered page our probe did not read, or do not publish one.
Which martech vendors publish a public sub-processor list?
Pipedrive, Copper, Klaviyo, ActiveCampaign, Customer.io, Mailchimp, Outreach, ZoomInfo, Semrush, Mixpanel, Amplitude, HockeyStack, Jasper, Writesonic, Hootsuite, Sprout Social, Demio, Qualified and Vidyard.
Do HubSpot and Salesforce publish sub-processor lists?
Both publish sub-processor information, HubSpot in its trust center and Salesforce in its DPA PDF; neither is at a standard crawlable HTML address our probe reads, so both are recorded as "not found at standard paths." Braze publishes a dedicated page whose content renders only in a browser and is recorded the same way.
What is a sub-processor list?
A document in which a data processor names the third parties (cloud hosts, email relays, analytics tools, AI model providers) that will process customer data on its behalf. GDPR Article 28 requires processors to inform controllers of these.
Why does a sub-processor list matter for AI features?
It is the only public document that names which foundation-model provider receives a customer's data. Several vendors' AI terms address "third-party providers" without naming them; the sub-processor list is where that should be resolved.
Sources
- GDPR Article 28: Processor
- Klaviyo sub-processors
- ActiveCampaign sub-processors
- Braze sub-processors (client-rendered)
- HubSpot Trust Center
GTMStack publishes original audits of the AI marketing stack. If you want the next one when it lands, the newsletter is the place to get it.
