Trust  /  Subprocessors

Everyone who touches your data.

The complete processing chain: what each vendor does, which region it runs in, and what data reaches it. If a name is not on this list, it does not process Customer Data.

Updated 28 July 2026Revision 1430 days notice on changes
§01  /  Current list

Nine vendors.
No surprises.

Each one is bound by a written agreement imposing obligations no less protective than our own Data Processing Addendum, and we remain liable for their performance.

Infrastructure2 vendors
VendorPurposeProcessing regionData reached
Amazon Web ServicesPrimary hosting, compute, object storage and managed PostgresEU (Frankfurt) / US (N. Virginia)Customer Data, account data
CloudflareCDN, DNS, TLS termination and DDoS protectionGlobal edgeRequest metadata, IP addresses
Platform operations2 vendors
VendorPurposeProcessing regionData reached
SentryApplication error monitoring and stack tracesEU (Frankfurt)Diagnostic data, redacted payloads
Grafana CloudMetrics, dashboards and alerting for platform healthEU (Frankfurt)Operational telemetry only
Communications2 vendors
VendorPurposeProcessing regionData reached
PostmarkTransactional email: approvals, notifications, digestsUSRecipient address, message content
TwilioOptional SMS delivery for approval routingUSPhone number, message content
Business operations3 vendors
VendorPurposeProcessing regionData reached
StripeSubscription billing and payment processingUS / EUBilling contact, payment metadata
HubSpotSales CRM and enquiry handlingEU (Frankfurt)Prospect contact details
PlainCustomer support ticketingEUSupport correspondence
§02  /  How this list changes

Notice before,
not after.

Adding a vendor to the processing chain is a decision you get to react to, not discover.

01 · Notice

30 days, in writing.

Workspace administrators are emailed at least 30 days before we add or replace a subprocessor that processes Customer Data. This page is updated at the same time, with a new revision number.

02 · Objection

You can object.

Raise a reasonable data protection objection inside the notice window and we will work on an alternative. If none exists, you may terminate the affected service and take a prorated refund.

03 · Diligence

Reviewed before, and annually.

Every vendor is assessed for security posture, processing location, transfer mechanism and breach commitments before onboarding, then re-reviewed each year.

Model providers

Where you supply your own model provider key, that provider is your processor, not ours, and its terms govern the content you send. Providers you connect through outbound MCP credentials sit in the same category.

Read the DPA
Notifications

Get told when this list changes.

Workspace administrators are notified automatically. Anyone else evaluating us can subscribe to the same notice.