Sub-processors
Last updated 11 August 2026. Every third party that processes customer data on behalf of Promatics Informatics LLC in the course of providing Attergo.
| Category | What it does | Can it reach protected health information | Where |
|---|---|---|---|
| Cloud infrastructure | Compute, managed database and object storage for the production environment. | Yes. Encrypted at rest and in transit; the provider holds no application credentials. | United States |
| Clearinghouse | Transmits 837P claims and returns 277 acknowledgements and 835 remittances on the customer's behalf. | Yes, and necessarily. A medical claim is protected health information by definition. | United States |
| Transactional email | Delivers account, security and notification email. | No. By design no message we send contains a patient name, date of birth, prescription number or any re-identifying value. | United States |
| Uptime monitoring and log storage | Receives heartbeat signals from our scheduled checks, and a stream of application log lines for search during an investigation. | No, and it is enforced rather than intended. Every line passes a field-registry redactor and then an assertion that no protected field survived with a value; a line that fails is dropped rather than sent. | United States |
| Website analytics | Measures which pages visitors read on the public marketing site, and which lead to a demo request. | No, and it cannot. The tag loads on the marketing site only and is absent from every authenticated page of the application. | United States |
| Off-site backup storage | Receives the nightly encrypted database dump and object archive, so a copy survives the loss of the primary host. | Yes, as ciphertext only. The artifact is encrypted with AES-256-GCM before it is written to any disk and the key never leaves our infrastructure, so the party holds bytes it cannot open. | United States |
| Malware scanning (not a sub-processor) | Uploaded documents are scanned on our own infrastructure. Signature updates are downloaded to us; no customer file is ever transmitted to the scanner vendor or to anyone else. | No third party receives anything. The scan happens in a container on the same host as the application. | Our own infrastructure |
| Language model inference (optional) | Rewrites the sentences of the monthly narrative report so it reads as prose. Every figure in the report is computed by the platform; the model is asked to rephrase and never to calculate, and a deployment may run with no model at all, in which case the report is produced from the figures alone and says so. | No, and it is enforced rather than intended. The request carries section headings, metric names, units and integers. Before it is sent it is refused outright if it contains an email address, a social security number, or a run of seven or more digits, which is what a prescriber, drug or member identifier looks like and what a formatted money figure is not. A refused request is not trimmed and re-sent; nothing is sent. | Determined by the provider a deployment selects, and outside the United States for the option evaluated so far. No provider is selected on the production deployment as of 2026-08-11, so nothing is sent to anyone yet. Permitted as a Tier 2 party under section 3 of our vendor management policy, which requires US-only processing of parties that can reach protected health information, and this one cannot. |
Categories rather than vendor names, because a named vendor on a public page is a starting point for someone attacking our customers. The specific entities, their certifications and their agreements are provided in full under the business associate agreement and any mutual non-disclosure agreement, before you sign anything.
How this list changes
We notify customers at least thirty days before adding a sub-processor that can reach protected health information, in writing, to the contact on the account. A customer who objects on reasonable security grounds within that window may terminate the affected services without penalty and takes a complete export with them.
Replacing a sub-processor in a category that cannot reach protected health information is not notified individually, but this page is updated and the date at the top changes.
How each sub-processor is bound
No sub-processor receives customer data before it is engaged under a written agreement imposing obligations no weaker than those we owe you: confidentiality, purpose limitation, security measures appropriate to the data, breach notification to us without undue delay, and deletion or return of data at termination. Where a sub-processor can reach protected health information, that agreement carries the business associate terms HIPAA requires, and no protected health information is routed to it until that agreement is signed.
What is not on this list, deliberately
There is no advertising network, no data broker and no model provider. No customer data of any kind is used to train a model for a third party, and no third-party script of any kind loads on an authenticated page of the application.
The public marketing site runs Google Analytics, recorded in the table above and described in the privacy policy. It processes visitor telemetry only, and it reaches no customer data, no protected health information and no part of the application. Anything added to this page arrives here before it carries a single byte.
Questions
Write to privacy@attergo.com for privacy and sub-processor questions, or security@attergo.com for security correspondence.