Subprocessors
Updated September 7, 2026
Every third party that processes data on Token Watch’s behalf, and what each one receives.
Always in use
| Subprocessor | Purpose | What it receives | Location |
|---|---|---|---|
| Microsoft Azure |
Hosting: App Service, Azure Functions, Azure SQL Database. | Everything Token Watch stores. This is the primary processor. | United States EU available for enterprise |
| Microsoft Entra ID |
Identity. Sign-in, admin consent, and the Graph API itself. | User sign-ins, which already take place in your own tenant. | Your tenant’s own region |
| Mailtrap | Delivery of report and alert emails. | The recipient addresses you configured, and the report contents: App Registration names and credential expiry dates. | United States |
| Grafana Labs Grafana Cloud (Loki) |
Application logs, for debugging and security monitoring. | Structured application logs: timestamps, request paths, tenant ids, and error traces. Not the credential inventory. | United States |
Billing, depending on how you bought
| Subprocessor | Purpose | What it receives |
|---|---|---|
| Paddle | Merchant of record for subscriptions bought directly from us. Handles payment, invoicing and tax. | Billing details. Card numbers go to Paddle only; Token Watch holds the customer and subscription identifiers Paddle issues. |
| Microsoft Commercial Marketplace |
Reseller for subscriptions bought through Microsoft Marketplace. Billing runs through your existing Microsoft or Azure billing account. | The billing relationship, on Microsoft’s side. Token Watch holds the marketplace subscription and plan identifiers. |
Free-plan customers have neither; no payment provider is involved.
Optional destinations
Delivery targets you configure. They are not subprocessors in the strict sense, but they are listed because alert data can reach them.
| Destination | When it is used | What it receives |
|---|---|---|
| Slack | If you configure a Slack incoming webhook. | The report: App Registration names and credential expiry dates. |
| Microsoft Teams | If you configure a Teams / Power Automate workflow URL. | The same report, as an Adaptive Card. |
| Azure DevOps | If you connect an Azure DevOps project. | A work item per expiring credential, in your own Azure DevOps organisation. |
| Your own endpoint | If you configure the signed JSON webhook. | The report as JSON, signed with your tenant’s HMAC secret, delivered to the URL you configure. |
Not in use
No advertising networks, cross-site tracking, data brokers, or AI and machine-learning services. Tenant data is not used for training and is not shared with any third party for their own purposes.
There is also no analytics vendor, no error-tracking service, no CDN in front of the application, and no queue or cache holding customer data outside the database. The tables above are complete.
Related
- Architecture, hosting and encryption — where each of these sits in the flow.
- Security contact and legal documents — data processing paperwork.
- Privacy policy — the legal statement on third-party sharing.
Token Watch