Every party that touches your traffic.
Model providers and infrastructure vendors we rely on. New subprocessors are announced 30 days before activation via RSS and email — object during that window and we'll pause activation for your tenant.
This page is app-owned editable content and reflects the current subprocessor list. Certifications are those the subprocessor publicly claims. Per-tenant provider allow-lists (in your policy) can exclude any of them from your traffic.
Model providers
| Subprocessor | Purpose | Region | Certifications |
|---|---|---|---|
| OpenAI | Model inference (GPT family) | US, EU (Azure) | SOC 2 Type II, GDPR DPA, HIPAA BAA (Azure) |
| Anthropic | Model inference (Claude family) | US, EU | SOC 2 Type II, GDPR DPA, HIPAA BAA |
| Google Cloud (Vertex AI) | Gemini + hosted third-party models | US, EU, UK, IN, SG, JP, BR | SOC 1/2/3, ISO 27001/17/18, HIPAA, FedRAMP High |
| Microsoft Azure OpenAI | GPT family on Azure regions | US, EU, UK, CA, IN, SG, JP, AE, BR | SOC 2, ISO 27001, HIPAA, FedRAMP High, IRAP, C5 |
| xAI | Grok family inference | US | SOC 2 (in progress) |
| Mistral AI | Open + commercial Mistral models | EU | GDPR DPA, SOC 2 (in progress) |
| Fireworks AI | Open-source model hosting | US | SOC 2 Type II, HIPAA BAA |
| Together AI | Open-source model hosting | US | SOC 2 Type II |
| Groq | Low-latency inference | US | SOC 2 Type II |
| Cerebras | High-throughput inference | US | SOC 2 |
| AWS Bedrock | Multi-model gateway (Anthropic, Meta, Cohere, Mistral) | US, EU, UK, APAC | SOC 1/2/3, HIPAA, FedRAMP High, IRAP |
Infrastructure & operations
| Subprocessor | Purpose | Region | Certifications |
|---|---|---|---|
| Amazon Web Services | Compute, storage, KMS for the managed control plane | US, EU, UK, IN, SG, AU, JP, BR | SOC 1/2/3, ISO 27001/17/18, HIPAA, PCI, FedRAMP High, IRAP |
| Cloudflare | Edge routing, DDoS, TLS termination, WAF | Global anycast | SOC 2, ISO 27001, PCI DSS |
| Neon (Postgres) | Metadata store: keys, policies, audit index (encrypted at rest) | US, EU | SOC 2 Type II, HIPAA-ready |
| ClickHouse Cloud | Analytics warehouse for token/latency/cost metrics | US, EU | SOC 2 Type II, ISO 27001 |
| Upstash Redis | Semantic cache for eligible requests | US, EU, APAC (per policy) | SOC 2 |
| Datadog | Internal operational observability (no customer prompt/completion content) | US, EU | SOC 2/3, ISO 27001, HIPAA |
| Resend | Transactional email (invites, alerts) | US | SOC 2 Type II |
| Stripe / Paddle | Billing and tax | US, EU | PCI DSS Level 1, SOC 1/2 |
How do I get change notifications?+
Subscribe to the RSS feed at /trust/subprocessors.rss or add the trust email list in Enterprise plans. 30-day notice before any new activation.
Can I exclude specific subprocessors?+
Yes — set a provider deny-list in your policy. If exclusion leaves no eligible peer for a request, it hard-fails with a policy_violation instead of leaking.
Do these subprocessors see raw prompts?+
Only the model provider selected for a given request sees the prompt (after guardrails). Infrastructure subprocessors see encrypted transit and metadata only; content is encrypted at rest with per-tenant keys.