Trust

Subprocessors

Service providers that may process Customer data on our behalf. We notify changes at least 30 days in advance.

List last reviewed: 2026-05-20

VendorPurposeData typeRegionControls
MiniMaxPrimary LLM inference (Mythos AI)Chat content and extracted textEU / AsiaDPA + zero-retention
Z-AI / GLMFallback LLM inference (degraded mode only)Chat content and extracted textAsiaDPA + fallback only
Stripe Payments Europe Ltd.Payment processing & invoicingBilling identifiers, last 4 digits of cardEU / US (SCC)SCC + DPA
Amazon Web Services EMEA SarlEncrypted dossier and asset storageForensic dossiers and uploaded assetseu-central-1 (Frankfurt)DPA + SSE-KMS
Amazon Web Services EMEA SarlTransactional email deliveryRecipient email, message metadataEUDPA
Functional Software Inc. (Sentry)Application error trackingError stack traces, request paths (PII-scrubbed)EU (de.sentry.io)DPA + PII scrubbing
OpenTelemetry collectorTrace and metric ingestionRequest traces and timing metadataTBD (self-hosted target)Pending production wire-up

Why this list?

Listing sub-processors is required by Art. 28(2) GDPR and is the single most-requested artefact in enterprise procurement. We refresh it every quarter and on every material change.

Informational document published by LegalAudit SA. Statements reflect the current state of controls and are reviewed quarterly. They are not a contractual warranty unless incorporated into a signed agreement. For binding terms request the executed DPA at privacy@legalaudit.ch.

Trust Center