This document is in draft and is pending review by counsel. It is published for transparency during Armada’s pre-launch period and does not yet constitute a binding agreement.
1. How to read this list
When an MSP uses Armada, the MSP’s client owns the Microsoft 365 tenant and is the controller. The MSP is a processor. Armada is a sub-processor. The vendors on this page are Armada’s own onward sub-processors — the companies we depend on that could, in principle, touch data.
The column that matters is what it can access. Because a scan is ephemeral — raw tenant telemetry is read into memory, evaluated, and discarded, and the storage layer has no table capable of holding it — most vendors below never touch client tenant data at all. We separate the two paths deliberately rather than presenting one undifferentiated list.
2. The list
| Vendor | What it does | Tenant data? | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosts this website (Cloudflare Pages) and serves DNS. As an edge provider it processes connection data, including IP addresses, to deliver and protect the site. | No | Global edge network; US-headquartered |
| FormSubmit (formsubmit.co) | Relays the contact form to our inbox. It receives the four fields you type and your submission metadata. | No | United States (unconfirmed) |
| Microsoft Corporation | Microsoft Graph (the source system a scan reads), Entra ID (the consent and token flow), Azure Functions (scan compute), Azure Table Storage (scores, statuses, hashes, signatures — never raw telemetry), Azure Monitor. | Yes | United States; region not yet selected |
| GitHub, Inc. (a Microsoft subsidiary) |
Private source-code hosting. Holds no customer data of any kind. | No | United States |
| Business email provider | Delivers and stores mail sent to hello@armada-solutions.com, including anything you submit through the contact form once it arrives. |
No | To be identified before launch |
3. Website vendors
Two vendors are involved in your visit to this site.
Cloudflare serves the pages. It sees the request — IP address, user agent, which page — as any host must in order to answer it. We have not enabled Cloudflare Web Analytics and keep no visitor analytics dashboard. Cloudflare may set a strictly functional security cookie when certain protection features are enabled; we do not read it and do not use it to identify anyone.
FormSubmit is involved only if you submit the contact form. It receives your name, company, approximate tenant count, and email address, and forwards them to our inbox. If you would rather not involve a third party, email hello@armada-solutions.com directly — it reaches the same place.
Nothing else on this site contacts an outside server. Fonts, the animation library, the stylesheet, and the scripts are all served from this domain. You can confirm that in your browser’s network panel: after the page loads, every request should point at armada-solutions.com.
4. Platform vendors — not live yet
Armada is pre-launch. There are no paying customers, no production deployment, and no live client-tenant scan has been run. The Microsoft row above describes the architecture the code targets, not a system currently processing anyone’s data.
We list it now because a sub-processor list that first appears on the day it becomes load-bearing is not worth much. Parts of it will change before launch — no Azure region is selected, and Azure Key Vault is designed but not implemented, so the signing key is currently generated by the application rather than held in a vault. This list is re-verified and re-issued before the first customer signature.
5. Sub-processors we removed
Two entries came off this list on 2026-07-29, before either was ever load-bearing.
- Google LLC — the site previously loaded its two typefaces from Google Fonts. Every visitor’s browser therefore made a request to Google, disclosing their IP address, purely to fetch a font. The font files are now served from this domain and Google receives nothing.
- cdnjs (Cloudflare) — the animation library was loaded from a public CDN. It is now served from this domain. Cloudflare remains our host; it is no longer a separate script origin.
We record removals rather than quietly deleting rows. A sub-processor list you can only read forwards tells you nothing about whether it is maintained.
6. What we have not done yet
Stating this plainly is more useful to you than omitting it.
- We have not executed data processing agreements with the vendors above. This is a pre-launch task.
- We have not implemented a transfer mechanism — Standard Contractual Clauses or equivalent — for personal data leaving the EU or UK.
- We have not confirmed FormSubmit’s processing location or its own sub-processors.
- We have not selected an Azure region, so we cannot yet tell you where platform data would be stored.
- We hold no SOC 2 report and have not completed a third-party penetration test.
If any of these is a blocker for your business, say so — it moves up the list, and knowing which ones matter to real MSPs is more useful to us than guessing.
7. Notice of changes
Adding a sub-processor is a material change to the Privacy Policy. When we add one, the version marker and date at the top of this page change, the previous entry stays visible in §5 if it was removed, and existing platform customers are notified by email at least 30 days before the change takes effect — enough time to object under the DPA.
8. Getting the DPA
The Data Processing Agreement is a three-party document: your client is the controller, you are the processor, and Armada is the sub-processor. It is not published here because it is a contract to be signed rather than a notice to be read. Request a copy at hello@armada-solutions.com and we will send the current draft, marked as a draft.