1. Overview
This page lists the third-party services ("subprocessors") that SpiceFactory uses at the company level. These are services we rely on for our day-to-day operations — separate from project-specific infrastructure that varies by engagement.
We evaluate each subprocessor's security posture before engagement and conduct ongoing reviews. All subprocessors are contractually bound by data processing agreements where applicable.
Project-specific infrastructure (cloud hosting, CI/CD, monitoring) varies by engagement and is documented in each project's security plan. Common platforms include Google Cloud, AWS, and Azure — selected based on partner requirements.
2. Current Subprocessor List
This list is now operated from the SpiceFactory compliance register. The register is the source of truth for which third parties process SpiceFactory or partner data, the engagement classes each is cleared for (all engagements, non-PHI, PHI-allowed, FDA Part 11), BAA / SOC report status, and the lifecycle (added / retired) date for every entry.
For the current state, request access via
security@spicefactory.co or your partner-portal link. Approved partners receive a snapshot with the changelog for their reporting period.
3. Change Notification
SpiceFactory reviews our subprocessor list quarterly. When we add or change a studio-level subprocessor:
- The register entry is updated at least 30 days before the change takes effect, and the immutable audit log records the change.
- We notify affected partners via their designated security contact.
- Partners may raise objections within 30 days of notification.
For project-specific infrastructure changes, notification is handled through the project's change management process.
To receive proactive notifications, contact security@spicefactory.co.