How to read this list
A subprocessor is a third party that may process client data as part of delivering our service. The list depends on the deployment model, so we present it that way rather than giving one list that is only true sometimes.
The authoritative list for a given engagement is attached to that engagement’s data processing agreement and repeated in its architecture document. If the two ever disagree, the signed agreement governs. This page is the general picture.
With enterprise API inference (default)
| Subprocessor | Role | Data it may process | Primary locations |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting, compute, relational storage, object storage, secret storage, outbound AI gateway, transactional email routing | All data held by the system, encrypted at rest | United States, global edge network |
| OpenAI, L.L.C. | Model inference for extraction, summarization, and question answering | Only the content submitted in a given inference request, under enterprise terms with no training on submitted content and zero or minimal retention | United States |
| Amazon Web Services, Inc. | Dedicated compute where an engagement requires it | Data processed by that component, encrypted at rest | Region selected per engagement |
| DigitalOcean, LLC | Dedicated compute where an engagement requires it | Data processed by that component, encrypted at rest | Region selected per engagement |
| GitHub, Inc. (Microsoft) | Source code hosting and change history | Application source code and configuration. No client business data, no credentials | United States |
Cloudflare holds SOC 2 Type II and ISO/IEC 27001 certification. AWS holds SOC 2 and ISO/IEC 27001. DigitalOcean holds SOC 2. GitHub and OpenAI both publish SOC 2 Type 2 reports. We rely on those attestations for the platform layer and do not present them as evidence about Vectyr’s own controls.
AWS and DigitalOcean appear only where an engagement uses dedicated compute; the engagement’s own documentation states which providers are actually in use.
Where an engagement requires an additional model provider — because a particular capability, region, or contractual term demands it — that provider is added to the engagement’s model register with advance notice, and is subject to the same requirements: enterprise terms, no training on client content, and zero or minimal retention.
With self-hosted inference
Where a client’s policy or data classification requires that content never reach an external AI service, extraction runs on open-weight models on GPU capacity we operate for that client alone.
In that configuration no model provider is a subprocessor at all. The list reduces to the hosting providers above, which process the data as infrastructure rather than as an AI service, and GitHub, which holds no client data.
This is the configuration we recommend where an institutional policy restricts submission of non-public data to external AI tools. See Hosting, isolation, and AI processing.
Systems that are not client-data subprocessors
For completeness, because reviewers reasonably ask: Vectyr uses ordinary business tooling for its own operations — email and calendaring, a marketing CRM holding website enquiry contacts, video conferencing, and accounting. These hold Vectyr’s own business records and the business contact details of people we correspond with. They are not connected to client production systems and do not receive client project data.
Client systems we connect to at the client’s direction — a Microsoft 365 tenant, a SharePoint estate, a line-of-business API — are the client’s own systems, not our subprocessors. We are a processor acting on the client’s instruction in respect of that data.
Changes to the list
We give clients at least 30 days’ written notice before adding or replacing a subprocessor that will process their data, unless a shorter period is necessary to address a security or availability emergency, in which case we notify as soon as practicable and explain why.
A client may object to a proposed subprocessor on reasonable data-protection grounds. If we cannot offer a workable alternative, the client may terminate the affected service without penalty for the remainder of the term. These commitments are in our data processing agreement; this page describes them so nobody has to sign something to find out what the terms are.
To be notified of changes, email trust@vectyr.co and we will add you to the subprocessor notice list for your engagement.
Assessment of subprocessors
Before a subprocessor is approved we review its security posture and available attestations, its contractual terms — particularly around training on submitted data, retention, and sub-subprocessing — its data locations and transfer mechanisms, and its availability and incident history. Approved subprocessors are reviewed annually and whenever their terms change materially. The method is in Vendor and subprocessor management.