MantisOps
MANTISOPS Managed IT Operations
Home

Sub-processors

Effective: June 3, 2026 · Last updated: August 19, 2026

MantisOps engages the following third-party service providers ("sub-processors") to deliver the Services. Each sub-processor is bound by contract to process customer data only as necessary to provide their service and in line with applicable data-protection law.

Notification of changes. We will notify you by email at least 30 days before adding a new sub-processor that processes customer-identifying data. This page is the authoritative source for the current list — bookmark it or subscribe at legal@mantisops.net.

Infrastructure

Sub-processorPurposeData locationPrivacy
Cloudflare, Inc. Application hosting / compute (Workers), database (D1), object storage (R2), key-value cache (KV), stateful coordination (Durable Objects), scheduled jobs (Workers Cron), DNS, CDN, DDoS protection — the entire MantisOps platform runs on Cloudflare Global (US + edge PoPs worldwide) Policy

Billing

Sub-processorPurposeData locationPrivacy
Stripe, Inc. Subscription billing, payment processing, customer portal US Policy

Communications

Sub-processorPurposeData locationPrivacy
Resend Transactional email delivery (activation, password reset, billing notifications) US Policy
Quo (formerly OpenPhone) Business phone / VoIP — sales & support calls, voicemail, SMS US Policy
Microsoft (Graph API) Administrative email send-as for support@mantisops.net US Policy
Slack Technologies, Inc. Internal alerting for new signups, subscription events, and critical errors. Customer-identifying data limited to email + company name on signup events. US Policy

AI-assisted support

Sub-processorPurposeData locationPrivacy
Anthropic, PBC AI-assisted support — triaging support requests and drafting replies. Processes the content of support tickets you send us; a MantisOps team member reviews every AI-drafted reply before it is sent, and the content is not used to train Anthropic’s models under our commercial terms. US Policy

Reference data (public APIs we query, no customer data sent)

SourcePurpose
NVD (NIST)CVE / vulnerability metadata for Mantis360 scans
EPSS (FIRST)Exploit Prediction Scoring System data
MSRCMicrosoft security update metadata
HIBP Pwned Passwords (k-anonymous)Password breach check on user signup (only first 5 hex chars of SHA-1 sent — your password never leaves the worker)
api.qrserver.comQR-code generation for MFA enrollment (TOTP secret never sent — only the otpauth:// URI)

Past sub-processors

None at this time.

← Back to MantisOps