Legal
Data Processing Addendum
Last updated: 2026-05-06
This draft DPA describes Authwright's processing of customer data for workspace administration, domain diagnostics, billing, support, and security audit logging.
Roles
The customer is the controller for customer content. Authwright acts as processor for customer content and as controller for account, billing, and security data.
Security measures
- Registrar credentials are handled only through the broker boundary.
- Production secrets are stored in Azure Key Vault.
- Workspace authorization is enforced server-side for portal and MCP access.
Requests
Signed DPA requests can be sent to founder@authwright.com.