Skip to main content

Subprocessors

Last updated: July 28, 2026

A subprocessor is a third party we use to process personal data on your behalf. This page is the authoritative list, and it is the list our Privacy Policy and our Data Processing Agreement point to. We keep it in sync with the code: an automated test in our repository fails the build if a new outbound destination is added without appearing here, so this page cannot quietly fall behind what the software actually does.

When we add or replace a subprocessor, we update this page and notify customers under the change-notice term of the Data Processing Agreement, which carries a right to object.

1. Subprocessors

  • VercelApplication hosting and content delivery. Receives: Request data, IP addresses, and session cookies in transit through the edge. Reached as our deployment target rather than through an API call, so it has no host literal or SDK in the codebase.
  • NeonManaged Postgres hosting — the primary database. Receives: All tenant business data. The connection string is supplied at runtime (DATABASE_URL), so the host is deliberately not a literal in source; the Postgres driver is the egress signal.
  • CloudflareObject storage (R2) for software downloads, knowledge artifacts, evidence files, and exports; and Turnstile bot challenge on account signup. Receives: Stored files and their metadata; and, for Turnstile, the visitor's IP address and browser challenge signal. R2 is an S3-compatible endpoint supplied at runtime (S3_ENDPOINT), so the AWS S3 client is the egress signal rather than a host literal. Turnstile is env-gated: with no key configured, no challenge is issued and no visitor data reaches Cloudflare for that purpose.
  • StripePayment processing, subscriptions, and metered billing. Receives: Billing contact, tokenized payment method, and usage counts. Full card numbers never reach our servers..
  • ResendTransactional and outreach email delivery. Receives: Recipient email address and message body.
  • TwilioSMS / text-message delivery (A2P 10DLC). Receives: Recipient phone number and message body.
  • AnthropicAi model processing. Receives: The prompts behind Ai features, which can include Customer Content. The endpoint our model router treats as no-training-certified, and the only one it will use for content classified as restricted or regulated. Processing is in the United States.
  • Zhipu Ai / z.aiAi model processing for lower-sensitivity tasks. Receives: Prompts that are not classified restricted or regulated. Processing is in China — a transfer of data outside the United States and the EEA. The model router never sends restricted or regulated content here.
  • MongoDBText embeddings (Voyage models) that power search and cited answers. Receives: Document and chunk text submitted for vector retrieval.
  • Amazon Web Services (KMS)Encryption key management for the credential vault. Receives: Key material only — data-encryption keys are wrapped and unwrapped; no Customer Content is sent.
  • Have I Been PwnedCredential-exposure checks in CyberVault. Receives: The full email address of each member of an organization that uses the feature. Only runs when an API key is configured. Breach names returned are stored; the email address is never sent to a model.
  • InngestDurable background job, workflow, and cron execution. Receives: Event metadata and job payloads.
  • SentryError monitoring. Receives: Error context and request metadata. Enabled only when a DSN is configured.

2. Systems you connect yourself

These are not our subprocessors. They are your own systems, which you authorize us to read on your instruction — they remain your processors, under your agreements with them. We list them because our software talks to them on your behalf and you should be able to see that.

  • Google Drivedrive.readonly (a Google-designated sensitive scope). Read-only. The OAuth token is held in the credential vault; disconnecting purges the synced corpus.
  • Microsoft 365 / OneDriveFiles.Read.All + offline_access. Read-only, with the same purge-on-disconnect behaviour.
  • SlackBot read scopes. Read-only, with the same purge-on-disconnect behaviour.

3. Cross-border processing

Ai processing for content classified as restricted or regulated stays with Anthropic, in the United States. Lower-sensitivity Ai requests may be routed to Zhipu Ai / z.ai, which processes in China a transfer of data outside the United States and the EEA that you should account for in your own transfer assessment. Our model router never sends restricted or regulated content to that provider.

4. Questions and objections

To ask about a specific vendor, request our Data Processing Agreement, or object to a proposed change, reach us through the contact form. Our security and processing posture — including the controls that are not yet in force — is on the Trust & Security page.

Questions about these documents? Reach us through the contact form — we respond to legal and privacy inquiries within two business days.