Sub-processors
A vendor who will not name their sub-processors is asking you to trust a chain you cannot see. This is the whole chain — what each link does, where it runs, and whether it can reach tenant content at all.
What a sub-processor is, and why the list is short
A sub-processor is any third party we engage that may process customer data on our behalf. Under the data processing agreement we remain responsible to you for what they do, so the incentive is to have as few as possible.
Each one is engaged under a written agreement imposing confidentiality and security obligations at least as protective as those we owe you, and is assessed before engagement and reviewed annually.
The column worth reading is the last one. Most of these cannot see tenant content at all — they handle billing identifiers, delivery addresses or error metadata. Only three sit anywhere near your product data, and each is there for a reason we can state in one line.
The current list
Accurate as at the date above. Anything not on this list does not process customer data, and if you find something that appears to contradict that, tell us — it would be a defect rather than an omission.
Sub-processors as at 2026-08-25
| Provider | Purpose | Location | Reaches tenant content? |
|---|---|---|---|
| Hetzner | Application and database hosting, backups | Germany (EU) | Yes — it is where the data lives |
| Anthropic | AI model inference for agent features | US, zero-retention terms | Yes — per request, discarded after; never trained on |
| Resend | Transactional email: invitations, notifications, alerts | US, SCCs in place | Partial — names, emails and notification subject lines |
| Stripe | Subscription billing and payment processing | US / Ireland, SCCs in place | No — billing contacts and invoices only |
| Sentry | Error monitoring and stack traces | EU region | Incidental — scrubbed traces; object content is filtered |
| Cloudflare | DNS, TLS termination and edge protection | Global edge | In transit only — no storage of tenant content |
AI model providers, specifically
This is the entry that decides evaluations, so it is separated out. When an agent runs, the objects relevant to that request are sent to a model provider to produce the answer and are then discarded.
Requests are made under a zero-retention arrangement. Prompts and completions are not retained by the provider and are not used to train any model. That is a contractual term with the provider, not a setting we toggle, and it is mirrored as a contractual term to you in section four of the Terms of Service.
Two ways to reduce this surface further. Bring your own key: requests go to your own provider account under your own contract, and we never hold the content. Disable agents at tenant level: no content reaches a model provider at all, agent features stop working, and nothing else in the product is affected.
Model routing sends cheaper work to smaller models, so the provider set for a given tenant depends on which agents you enable. The usage screen shows which model handled which request.
Where data sits, and transfers
Production data is held in the European Union by default. Backups are held in the same region and are encrypted at rest with keys we control.
Where a sub-processor operates outside the UK or EEA, transfers are made under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, with a transfer risk assessment on file that we will share under NDA.
Regional data residency — pinning a tenant to a named jurisdiction — is not yet offered, and neither is single-tenant or on-premise deployment. These are tracked commitments rather than current capabilities, and a buyer whose contract requires them should know that before an evaluation rather than during procurement.
Changes, notice and your right to object
Before a new sub-processor begins processing customer data, we will update this page and notify account administrators by email at least thirty days in advance. Subscribing to notifications does not require a support ticket; administrators receive them automatically.
You may object to a new sub-processor on reasonable data-protection grounds within those thirty days. We will work with you to find an alternative arrangement, and where none is possible you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees. An objection right that costs you the contract is not a right, so it does not work that way here.
Emergency replacements — where a provider fails or a security issue forces an immediate move — are made first and notified within five working days, with the same objection right applying afterwards.
Questions and audits
The security review pack covers the isolation design, the audit chain verification procedure, the access control model and the test list, and is published rather than gated behind a sales call.
Under the data processing agreement you may audit our compliance once in any twelve-month period on reasonable notice, and more often where a supervisory authority requires it. In practice most reviewers are satisfied by the review pack and a call with an engineer, which we prefer too.
Sub-processor questions: privacy@dev.co. If a specific entry blocks a deal, say so early — some of these are replaceable and we would rather know while it is still a choice.