Sub-processors

The sub-processor list. It is one company.

A sub-processor is anybody we use who could in principle touch data covered by our processing terms. A serious review asks for this list before it asks anything else, so it is published here rather than sent on request, and it is the complete list rather than the notable entries.

A short sub-processor list is not a boast. It is the smallest number of people who can see this.

The list

Who, what for, and what they could see.

Sub-processorWhat it does for usWhat it could see
MicrosoftAzure, West Europe Compute, the control-plane database, the key vault holding one connection secret per project, and the certificates. Everything we hold, which is the inventory on data handling: your structure, your people's email addresses, grants, and the access trail. No copy of your business data exists for it to see.

That is the list, and it is one row because the architecture keeps it to one. Every category drawn out below is one a comparable service would normally have to name here.

The struck-through row is the point of the page. Each of those is a party a comparable service would have to name, and each one absent is a party that never has to be trusted, audited or notified about.

Not on the list, and why

Four things a reviewer usually expects to find here.

Each of these is a common sub-processor and each is genuinely absent, for a reason worth stating rather than for a virtue worth claiming.

The AI vendor is not our sub-processor

We run no model, so no model provider processes anything on our instruction. The assistant is yours, under your own contract with its vendor, and what it does with a conversation is governed by that contract rather than by ours. This is the single most common misreading of how this product sits, so it is first.

Your identity provider is yours, not ours

Sign-in federates to your own directory. It authenticates your person and returns a verified email; we hold no directory of our own. It is a party to the arrangement, and it is not a party we introduced or could replace.

The sign-in broker is us

The service that handles the OAuth round trip is our own, on the same Azure subscription and in the same region. It holds OAuth machinery and nothing about clients, projects or permissions. It is named here because a reviewer will see it in a redirect and should know what it is, not because it is a third party.

No error reporting or telemetry

No application monitoring is wired to the service, so no stream of exception data leaves it and no third party holds a copy of what went wrong. Adding one would add a sub-processor and change this page, which is exactly the trade this list exists to make visible.

Changes

How you find out when this list changes.

What we commit to

  • Notice before a new sub-processor handles anything of yours, in writing, with what it does and what it could see.
  • This page updated at the same time, so a prospect and a client are reading the same list.
  • Your right to object is in the data processing terms rather than described loosely here.

How the notice reaches you

  • Named contacts, in writing. Notice goes to the people your agreement names, so it arrives with the person who has to act on it rather than in a feed nobody reads.
  • The same list everywhere. This page, the review pack and the processing terms are updated together, so your reviewer and your buyer never hold two different versions.
Ready?

Everything else a reviewer asks for. Let's put it to work.

A forecast submission, a partner follow-up or an approval that keeps getting stuck. We will map the systems, actions and controls needed to move it forward.

Why this exists: useful assistants connect an answer to an action, and an action to a completed job.