Sub-processors

The sub-processor list. It is one company.

Your legal team will ask for this list first, so here it is, complete. A sub-processor is anybody we use who could in principle touch data covered by our processing terms.

Every name on a sub-processor list is one more party to trust. This list has one.

The list

Who, what for, and what they could see.

Sub-processorWhat it does for usWhat it could see
MicrosoftAzure, West Europe Compute, the control-plane database, the key vault holding one connection secret per project, and the certificates. Everything we hold, which is the inventory on data handling: your structure, your people's email addresses, grants, and the access trail. No copy of your business data exists for it to see.

That is the list. It is one row because the architecture keeps it to one. The categories drawn below are ones a comparable service would normally have to name here.

Each struck-through category is a party you never have to trust. Nobody to audit, nobody to notify about, nobody holding a copy.

Not on the list, and why

Four parties a reviewer expects to find here.

Each of these is a common sub-processor elsewhere. Here is why none of them is one of ours.

The AI vendor is not our sub-processor

We run no model, so no model provider processes anything on our instruction. The assistant is yours, under your own contract with its vendor, and that contract decides what it does with a conversation. Reviewers most often get this one wrong, so it comes first.

Your identity provider is yours, not ours

Sign-in federates to your own directory. It authenticates your person and returns a verified email; we hold no directory of our own. It is a party to the arrangement, and it is not a party we introduced or could replace.

The sign-in broker is us

The service that handles the OAuth round trip is our own, on the same Azure subscription and in the same region. It holds OAuth machinery and nothing about clients, projects or permissions. It is named here because a reviewer will see it in a redirect and should know what it is, not because it is a third party.

No third-party error reporting or telemetry

No stream of usage or exception data leaves the service for an outside vendor, so no third party holds a copy of what your people asked or what went wrong. Adding one would add a name to this page, and you would be told first.

Changes

How you find out when this list changes.

What we commit to

  • Notice before a new sub-processor handles anything of yours, in writing, with what it does and what it could see.
  • This page updated at the same time, so a prospect and a client are reading the same list.
  • Your right to object is set out in the data processing terms.

How the notice reaches you

  • Named contacts, in writing. Notice goes to the people your agreement names, so it reaches the person who has to act on it.
  • The same list everywhere. This page, the review pack and the processing terms are updated together, so your reviewer and your buyer never hold two different versions.
Ready?

One name on the list. Everything else your reviewer needs, in one pack.

The review pack carries this list, the data inventory and the control mapping, so your security and legal teams can sign off from one document.

Why this exists: our clients rolled out AI assistants that were useful everywhere except where their numbers lived. This connects those systems, so the assistant can finally answer the questions people care about.