Current provider register
This register covers the application and its supporting services. Encryption of vault fields does not make account details, network metadata or support messages anonymous.
| Provider | Role and data | Location and reference |
|---|---|---|
| Hetzner Online GmbH | Hosts the application, encrypted vault database and routine server backups. Infrastructure and authorised support operations. | Selected host: Helsinki, Finland (EU). Provider based in Germany. Data protection and DPA |
| Cloudflare, Inc. | DNS, TLS/network delivery, tunnel and abuse protection. Processes requests and connection/security metadata. Encrypted vault payloads remain encrypted at the application-content layer. | Global network; processing may occur outside the EEA. An EU host does not regionalise Cloudflare automatically. GDPR and international processing |
| Resend, Inc. | Transactional email delivery: recipient address, message content, timestamps and delivery information. No master passwords or decrypted vault exports are intentionally sent in service messages. | Sending domain configured for Ireland (eu-west-1). Other processing may occur internationally. GDPR, regions and DPA |
| MXroute LLC | Domain mailboxes and support correspondence. Receives the information you put in an email. | US-based provider; support mail is not described as EU-only. Do not email live secrets. Provider terms and privacy information |
Vaultwarden is software used in our hosting environment, not a separate company receiving your vault. We do not send vault data to GitHub CI or to an analytics service.
Organisation contracts and transfers
For a confirmed organisation DPA, the written confirmation identifies the authorised provider list and the applicable processing/transfer arrangements. Request the relevant evidence before onboarding an organisation that requires it. This public list does not itself prove that your organisation has concluded a DPA or that every provider processes only in the EU.
International processing that requires transfer safeguards must have its applicable mechanism confirmed with the relevant provider. Where your requirements demand that every support, mail and network operation remain in the EEA, discuss them with us before using the service; that restriction is not offered by the current beta configuration.
Changes and questions
Material provider changes are reflected here. For organisations with an active DPA, the notice and objection process in that agreement applies. Contact [email protected] for information or to raise a specific data-protection concern.