Sub-processors
Sub-processors
AMT relies on vetted categories of sub-processors to deliver its services. Each category undergoes due diligence, is bound by data-protection terms, and is governed under our ISO 27001 supplier-management process.
Key facts
- Due diligence
- Pre-onboarding security review
- Contracts
- DP + confidentiality terms
- Hosting
- Customer data hosted in China
- Change notice
- Material changes notified
Sub-processor categories
The table lists, by category (redacted), the sub-processors AMT uses, their purpose and data location. A specific vendor list is available under NDA.
| Category | Purpose | Data location | Data involved |
|---|---|---|---|
| Cloud infrastructure | Compute / storage / network hosting | China | Customer business & carbon / ESG data |
| Database & storage | Managed database & object storage | China | Structured & file data |
| Email & notifications | Transactional email / SMS | China | Contact email / phone |
| Observability & monitoring | Logs, metrics and alerting | China | System logs (de-identified) |
| Customer-support tooling | Tickets and communication | China | Ticket content & contacts |
| Trusted Data Space | Key-node hash-proof records | China | Data hashes (not raw data) |
How we govern sub-processors
- Pre-onboarding due diligence
Each is assessed for security posture, data location and compliance before use.
- Data-protection terms
Data-protection and confidentiality terms bind each category’s processing scope.
- Within ISO 27001
Supplier management sits within the ISMS, with periodic review and monitoring.
- Change notification
Affected customers are notified in advance of new or replaced key sub-processors.

