SERVICE PROVIDERSEverything Vallum runs on.
Vallum sits in front of your application, so our dependencies become yours. This is the complete list of third-party providers and subprocessors behind the service, what each one supplies, and where each publishes its own status — review it once during procurement, then bookmark the status links for the day you need them.
1 provider in the traffic path4 totalLast reviewed August 11, 2026
SUPPLIES- Proxy edge and management API (containers)
- Managed PostgreSQL 16 — policy, tenants, audit trail
- Managed Key Value (Redis) — sessions, fingerprints, rate limits
- Demo origin used by the public product demo
- Region
- Virginia, United States (us-east)
- In use since
- 2026
- Data handled
- Request metadata, session and fingerprint state, tenant configuration, and the audit trail.
SUPPORTINGSupporting services
These providers sit beside the traffic path. If one of them is down you may not be able to sign in to the console or book a call, but protected traffic keeps flowing to your origin under the policy already deployed.
SUPPLIES- Customer console and staff surface
- Marketing site and documentation
- TLS termination and edge caching for those surfaces
- Region
- Global edge network, United States primary region
- In use since
- 2026
- Data handled
- Console session cookies, request logs for the console and website, and form submissions in transit.
SUPPLIES- Console and staff authentication
- Organizations, roles, and owner sign-up links
- Authentication email delivery
- Region
- United States
- In use since
- 2026
- Data handled
- Names, work email addresses, organization membership, and session records for console users.
SUPPLIES- Booking embed on the Book a call page
- Region
- United States and European Union
- In use since
- 2026
- Data handled
- Name, email, and meeting details supplied by someone booking a call.
How this list changes
A provider is added here before it carries production traffic, and customers on a paid plan are notified at least thirty days before a new subprocessor begins handling their data — enough time to raise an objection under your agreement. Removals are published in the same place.
Availability commitments, credits, and how downtime is measured live in the Service Level Agreement. How data is handled is described in the Privacy Policy.