Government Cloud

Government Cloud Subprocessors

The provider register and processing rules for Pretorin's Government Cloud hosted service.

Register revision 5.1 · Reviewed October 5, 2026

This List identifies third parties Pretorin engages to process Customer Data or necessary Service Data in providing the Hosted Service under the Pretorin Master Software License and Services Agreement — Pretorin Government Cloud (MSLSA). It is the operational register referenced in MSLSA Section 2.6, subject to the MSLSA, applicable Order, and Data Processing Addendum (DPA). It does not authorize a new data category, location, model endpoint, or processing purpose. Capitalized terms have the MSLSA meanings.

1. Purpose and changes

1.1 Scope

Identify each provider’s actual legal identity, purpose, data categories, processing and access locations, and restrictions before it processes affected data. Where this List is the register attached to DPA Appendix B, complete all required identity, address, contact, processing, location, and further-subprocessor information. A provider name alone does not establish an approved authorization boundary or satisfy a transfer requirement.

1.2 Advance notice

Pretorin will give Customer’s notice and security contacts at least thirty days’ written notice before a new or replacement subprocessor begins processing Customer Data or Service Data, with the information reasonably needed to evaluate it. Updating this List alone does not constitute the required notice. An administrative correction that changes no processing, provider, or protection may be recorded without a new notice period.

1.3 Objection and resolution

Customer may object within fifteen days after notice on reasonable security, privacy, or controlled-data grounds. Pretorin will not begin the affected processing while a timely objection remains unresolved. The parties will seek a reasonable alternative in good faith. If they cannot agree within thirty days after the objection, either party may terminate the affected services with a refund of prepaid unused fees; termination extends to the affected Order if the services cannot reasonably be separated. Existing lawful services may continue during resolution.

1.4 Governing protections

The DPA, applicable Order, mandatory law, and binding flowdowns control where they require a longer objection period, specific authorization, or stricter protections. For DPA-covered personal data, DPA Section 3.4 controls, including its thirty-day objection period and related rights. No subprocessor may perform processing that cannot lawfully proceed. Pretorin remains responsible for its subprocessors as the MSLSA and DPA provide.

1.5 Controlled data

Classified information is prohibited. CUI, covered defense information, and export-controlled data may be processed only when expressly accepted in the Order, through identified permitted services and locations and subject to applicable requirements. A provider’s cloud authorization does not establish authorization of the Hosted Service. No entry is eligible for controlled data by implication.

2. Provider register

Microsoft Azure Government is the hosting platform for the Hosted Service. The particulars below summarize Pretorin’s reviewed deployment. The applicable Order and DPA control the customer-specific boundary and approvals.

Microsoft Azure Government

Legal identity and address
Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, United States. The applicable Microsoft purchasing agreement controls the contracting entity.
Provider contact
Azure Government support through Pretorin’s Microsoft account at portal.azure.us; contractual notices use the contacts in the applicable Microsoft agreement.
Service and purpose
Government cloud hosting: Azure Kubernetes Service and managed disks for application compute and persistence; virtual networking, private endpoints, firewall and VPN for connectivity; Container Registry, Key Vault, Azure Storage, DNS, Azure Monitor/Log Analytics, and Microsoft Entra ID for delivery, security, observability, and identity. Pretorin runs PostgreSQL and object storage within the cluster.
Data processed
Customer account information, compliance records, evidence, uploaded documents, and other Customer Data submitted to the Hosted Service; necessary Service Data such as authentication records, configuration, security logs, metrics, secrets, and backup/release metadata. Controlled data is permitted only when expressly accepted in the Order.
Storage and processing locations
Pretorin-configured application resources and storage are in US Gov Virginia. The reviewed Azure Storage accounts use zone redundancy within that region. No separate regional backup or recovery location is configured in the reviewed deployment inventory.
Support and access locations
Pretorin administrative access follows its authorized Government-tenant access paths. Microsoft support and personnel access are governed by the applicable Azure Government agreement and service commitments; individual support locations are not established by the Azure resource inventory.
Further subprocessors
Any Microsoft further subprocessors are governed by Microsoft’s applicable data-protection terms and service disclosures. This entry does not approve a separate provider engaged by Pretorin.Microsoft Service Trust Portal disclosures
Data boundary and eligibility
The Government Hosted Service uses Pretorin’s Azure Government tenant and a US Gov Virginia deployment. The applicable Order defines accepted data and the authorization boundary. Classified information is prohibited; Azure’s authorizations do not themselves authorize Pretorin’s Hosted Service.
Approval and transfers
Subject to the applicable Order, DPA Appendix B, and required notice or approval. This register alone does not authorize a new data category, processing location, model endpoint, or international transfer.

Additional providers

Each additional actual provider, including any Pretorin Model Service, support, or monitoring provider that processes covered data, requires its own verified entry. No additional Pretorin-engaged subprocessor is authorized by this register for the standard Government Hosted Service at this revision. A provider name or placeholder does not authorize processing.

Required for every additional provider entry

  • Legal identity and address
  • Provider contact
  • Service, purpose, and model endpoint if applicable
  • Data processed, retention, training, and controlled-data restrictions
  • Storage, processing, support access, and further-subprocessor locations
  • Order boundary, notice, approval, DPA, controls, and transfer mechanism

3. Models, integrations, and personnel

3.1 Model providers

No model provider or endpoint is included or approved by this List unless expressly identified in the Order. Record a provider engaged by Pretorin for a Pretorin Model Service in Section 2, including purpose, retention and training settings, data categories, and locations. Approved-boundary and controlled-data restrictions apply.

The reviewed Government subscription has no provisioned Azure OpenAI Government resource. A model provider must be added to this register and approved under the applicable Order before Pretorin enables it for covered data.

3.2 Customer-directed providers

A model or integration independently selected and contracted by Customer is not a Pretorin subprocessor solely because Customer directs a transmission to it. Actual engagement and processing roles govern; a provider engaged by Pretorin cannot be reclassified by label alone. Customer-directed transmissions still require approval under the Order and MSLSA.

3.3 Personnel

Pretorin employees acting under its authority are subject to its personnel controls. Contractors and other service providers must be listed when they are subprocessors under the applicable DPA or another governing requirement. Individual-contractor status does not itself exempt a processor from disclosure.

4. Register particulars

Applicable Order and boundary
The applicable Customer Order specifies the accepted service, data categories, and authorization boundary; this public List does not expand them.
Register revision and effective date
Revision 5.1; October 5, 2026.
DPA Appendix B reference
The applicable Customer DPA and Appendix B, where executed; customer-specific attachment identifiers remain in the signed agreement.
Customer notice and security contacts
The notice and security contacts designated in the applicable Customer Order or DPA.
Pretorin register contact
[email protected]