BACK TO ALL POSTS
strategy

Only 19 of 54 Martech Vendors Publish a Sub-Processor List Where a Crawler Can Read It

Dev Anand

AI Tool Reviews & Automation Safety · 2026-08-16 · 8 min read

Part of: Research
Only 19 of 54 Martech Vendors Publish a Sub-Processor List Where a Crawler Can Read It

Key Takeaways

  • 19 of 54 martech vendors (35%) publish a dedicated sub-processor list at a standard, crawlable HTML address, naming three or more real providers.
  • 35 (65%) do not at any of roughly 60 probed paths; several publish the information in a trust portal, a client-rendered page or a DPA PDF instead.
  • The 19 include Klaviyo, ActiveCampaign, Mailchimp, Outreach, ZoomInfo, Amplitude, Mixpanel, Semrush, Hootsuite, Sprout Social and Qualified.
  • The 35 include HubSpot, Salesforce, Zoho CRM, Braze, Iterable, Salesloft, Clay, Apollo, Ahrefs, PostHog and every AI SDR platform except Qualified.
  • Writesonic's DPA names 24 recognisable providers, the most detailed in the corpus; Semrush's list names five.

Only 19 of 54 Martech Vendors Publish a Sub-Processor List Where a Crawler Can Read It

By Dev Anand, AI Tooling & Automation Safety. Last updated: 2026-08-16

The AI-training audit we ran on these same vendors kept turning up one sentence: "our third-party AI providers are contractually prohibited from training on your data." Which providers? That question has a document, and we went to see how many vendors publish it in the open.

How many martech vendors publish a crawlable sub-processor list?

We used the same 54-vendor corpus as our other research audits. For each, we probed roughly sixty paths where sub-processor lists conventionally live (/legal/subprocessors, /subprocessors, /company/legal/subprocessors, /legal/dpa, /subprocessor-list, trust.<domain>/subprocessors and variants across the origin and its trust, legal, security and privacy subdomains). A page counted only if it was a dedicated sub-processor or DPA page, by URL or heading, and its served text named at least three recognisable providers (AWS, Google Cloud, Azure, Cloudflare, OpenAI, Twilio, SendGrid, Snowflake and so on). That rule excludes DPA boilerplate that promises a list without giving one, and it excludes a privacy policy or AI policy that happens to name a few providers, which is why the count is stricter than a first pass suggested. The same corpus is the one we used for the AI training-data audit.

Result Vendors Share
Dedicated, crawlable sub-processor list naming 3+ providers 19 35.2%
Not found at standard paths, or found but not crawlable 35 64.8%

Just over a third. For a document that every vendor in the corpus almost certainly maintains, that is a small number, and it is a number about findability and machine-readability rather than existence.

Who publishes one, and how detailed is it?

The nineteen, with the count of recognisable providers we detected on the page: Writesonic 24 (in its DPA), Sprout Social 16, Qualified 16, Klaviyo 15, Outreach 14, ZoomInfo 14, Jasper 14, Amplitude 12, Mixpanel 12, ActiveCampaign 11, Hootsuite 11, Pipedrive 10, Copper 10, Mailchimp 10, Customer.io 8, HockeyStack 7 (in its DPA), Vidyard 7, Demio 7, Semrush 5.

Writesonic's is the standout, and it connects to a finding from the training-data audit: Writesonic is also one of the six vendors that commits in a legal document not to train on customer data, and its sub-processor list names the model providers it uses. The two documents together let a customer see exactly which AI vendors receive their prompts and on what terms. That is what disclosure is supposed to look like.

Semrush's list, at five named providers, is the thinnest dedicated page in the set. Apollo and Lusha, whose whole business is moving contact data between systems, each name a few providers in an AI policy or privacy notice but publish no dedicated list we could find, and are counted as not found.

Want to put this into practice?

Reachium automates LinkedIn outreach, content publishing, and inbox management in one platform.

Start Free →

Who does not, and where is the list instead?

Thirty-five vendors have no crawlable dedicated list at a standard path. Some almost certainly have no public list. Others definitely publish one, somewhere else or in some other form, and it is worth being precise about the pattern.

HubSpot's sub-processor information sits in its trust center, a client-rendered portal. Salesforce's lives in its data processing addendum, a PDF linked from a legal index. Braze is the sharpest case: it publishes a dedicated page at /company/legal/subprocessors that returns 290KB of HTML containing not one provider name, because the list renders in the browser; a crawler, or our probe, receives an empty shell. Iterable's security page hands off to a trust-center portal that behaves the same way, and Loom's data is covered by Atlassian's sub-processor list on atlassian.com, a different domain from the one we probed. Our probe reads served HTML at addresses; it does not run JavaScript, log into portals or open PDFs, and we did not want to guess our way into claiming vendors "have no list" when they have one behind glass.

So the honest framing is this: for 35 of 54 vendors, a procurement reviewer or a crawler starting from the domain cannot read the sub-processor list at any conventional address. Whether that is because it does not exist, is in a portal, or is on a page that only a browser can render, the practical effect on a buyer doing due diligence at speed is the same. It is the same served-versus-rendered gap we found on pricing pages, now on a compliance document.

The 35 also include every AI SDR platform in the corpus except Qualified (11x, Artisan, Regie.ai, AiSDR and Relevance AI have none we could find), which matters because those are the products most likely to be routing customer conversations through third-party LLMs.

Why does a public sub-processor list matter more now?

Two reasons. The first is old: GDPR Article 28 requires a processor to inform the controller of its sub-processors and give it a chance to object, and a public, dated list is the cleanest way to meet that duty. The second is new. Every martech vendor now runs some customer data through a foundation-model provider, and the sub-processor list is the only public document that names which one. Our training-data audit found six vendors addressing "only third-party providers" in their AI terms without saying who the providers are. The sub-processor list is where that gap should close, and for two thirds of the corpus a crawler cannot find it.

There is also the martech stack argument we keep making: every additional tool is another sub-processor list nobody has read. If the list is not crawlable, it will not get read.

What are the limits of this audit?

The probe reads served HTML at roughly 60 conventional paths per vendor. It does not run JavaScript, open trust portals (SafeBase, Vanta, Drata, Conveyor), read PDFs, or log in. Vendors known to publish sub-processor information by those routes are on the "not found" list on purpose and are named as such above. The dedicated-page rule excludes privacy or AI policies that name a few providers in passing; the three-provider threshold excludes pages that mention sub-processors without listing them. A first pass with a looser rule counted 20; the stricter rule reported here counts 19, and both numbers are in the data file. Snapshot of 2026-08-16.

Want to put this into practice?

Reachium automates LinkedIn outreach, content publishing, and inbox management in one platform.

Start Free →

FAQ

How many martech vendors publish a sub-processor list?

19 of 54 in this audit (35%) publish a dedicated one at a standard, crawlable HTML address naming three or more recognisable providers. The other 35 either publish it in a portal, PDF or client-rendered page our probe did not read, or do not publish one.

Which martech vendors publish a public sub-processor list?

Pipedrive, Copper, Klaviyo, ActiveCampaign, Customer.io, Mailchimp, Outreach, ZoomInfo, Semrush, Mixpanel, Amplitude, HockeyStack, Jasper, Writesonic, Hootsuite, Sprout Social, Demio, Qualified and Vidyard.

Do HubSpot and Salesforce publish sub-processor lists?

Both publish sub-processor information, HubSpot in its trust center and Salesforce in its DPA PDF; neither is at a standard crawlable HTML address our probe reads, so both are recorded as "not found at standard paths." Braze publishes a dedicated page whose content renders only in a browser and is recorded the same way.

What is a sub-processor list?

A document in which a data processor names the third parties (cloud hosts, email relays, analytics tools, AI model providers) that will process customer data on its behalf. GDPR Article 28 requires processors to inform controllers of these.

Why does a sub-processor list matter for AI features?

It is the only public document that names which foundation-model provider receives a customer's data. Several vendors' AI terms address "third-party providers" without naming them; the sub-processor list is where that should be resolved.

Sources


GTMStack publishes original audits of the AI marketing stack. If you want the next one when it lands, the newsletter is the place to get it.

Want to automate what you just learned?

Reachium turns these strategies into automated LinkedIn campaigns that book meetings on autopilot.

Try Reachium Free

MORE FROM GTMSTACK