Sub-Processors
Last updated: July 2026
This page discloses every third party that may process customer data on SIP.IO’s behalf: what they do, what data they touch, and where. We keep this list short on purpose, we’d rather add a row when a real integration ships than pad it out for the sake of looking thorough. See the Trust Center for certifications, security controls, and data residency.
Notification policy. We’ll update this list, and notify customers by email, before a new sub-processor with material data access begins processing customer data. If you object on reasonable grounds, contact us during that window and we’ll work with you on alternatives.
1. Infrastructure & hosting
| Sub-processor | Purpose | Data accessed | Region |
|---|---|---|---|
| the edge platform, Inc. | Edge/hosting platform for the control plane, public API, dashboard, and this website: request routing, DDoS mitigation, TLS termination, plus the core data stores (SQL database, object storage, per-account stateful compute, streaming ingest). Also routes inbound email for the messaging product’s SMS-to-email forwarding feature. | Account, routing, and CDR data at rest; API/dashboard request traffic; call-event and CDR archive data; inbound message content for accounts that enable SMS-to-email forwarding. | Global anycast edge; core data stores replicate across the edge platform’s network. |
| Regional SIP & media node partners | Licensed colocation/bare-metal infrastructure hosting the SIP signaling and media (voice audio) layer in each region SIP.IO serves. Used solely for the realtime call path, never for data at rest. | RTP/SRTP voice streams in real time (not persisted at the node), SIP signaling. No account data, no CDRs, no recordings, no billing data. | In-region: today, EU and Israel; more regions planned as usage grows. |
2. Voice & number sourcing
| Sub-processor | Purpose | Data accessed | Region |
|---|---|---|---|
| the wholesale carrier (our termination and DID-sourcing partner, part of the same corporate family) | Default wholesale voice termination for outbound PSTN calls, and the source for phone numbers (DIDs) provisioned through SIP.IO. Each SIP.IO account maps to a verifiable subaccount, which is what enables STIR/SHAKEN call signing on outbound. | Call signaling metadata (from/to E.164, timestamps, duration, status) for calls routed via the wholesale default. RTP media transits in real time and isn’t stored by the carrier. | In-region per call. |
3. Billing & payments
Not applicable today. SIP.IO doesn’t process card payments through this website or the platform; accounts are billed directly by our team. This page will be updated the moment that changes.
4. Website communications
| Sub-processor | Purpose | Data accessed | Region |
|---|---|---|---|
| Amazon Web Services, Simple Email Service (SES) | Delivers the notification email generated when someone submits this website’s contact form. | The name, email address, company, and message text you submit in the form. | eu-west-1. |
What we mean by “customer data”
For this list, “customer data” means data SIP.IO processes on your behalf as a processor, not data we hold about you as a controller (your own name, business email, and login credentials for the dashboard, which are governed by our Privacy Policy). It includes:
- Account & routing data: your account configuration, numbers, users, devices, call flows.
- Communications metadata: call detail records (from/to E.164, timestamps, duration, status), message detail records.
- Communications content: call recordings (only if you enable recording), message bodies.
Change log
| Date | Change |
|---|---|
| 2026-07-05 | Amazon SES (website contact-form email) moved from planned to live. |
| 2026-07-02 | Initial publication of the sub-processor list. |