Subprocessor list
Nebbos engages a small set of subprocessors to operate the platform. This page names each, what they process, where they operate, and what changes trigger a customer notification.
This list is authoritative. If a service isn’t on it, we don’t send customer data to that service. If we plan to add a subprocessor, notice lands at least thirty days before the addition takes effect — see the change process at the bottom of this page.
Current subprocessors
| Subprocessor | Purpose | Location | Data touched |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary cloud infrastructure — compute, storage, data plane | us-east-1, eu-west-1 | All operator-scoped data at rest and in transit |
| Cloudflare | Edge network, DDoS mitigation, WAF, static asset delivery | Global (Anycast) | Request metadata, static assets. No operator-scoped row data. |
| WorkOS | Identity plane — SSO, directory sync, user lifecycle | us-east-1 | Operator identity records, group memberships, session tokens |
| Anthropic / OpenAI / Google Vertex | Third-party model inference (only for redacted-to-cloud tier) | us-east-1, eu-west-1 | PII-stripped prompt content per per-operator tier policy. Model providers contractually cannot train on data. |
| Doppler | Secrets management — platform-side credentials only | us-east-1 | Platform credentials, never customer credentials |
| Sentry | Error tracking | eu-west-1 | Application-layer errors with PII scrubbing; row-level payload never sent |
| Postmark | Transactional email delivery | us-east-1 | Recipient addresses, email body content |
Data residency
All operator-scoped structured data resides in the region assigned at deployment time. For Team-tier operators, this is us-east-1 by default; Enterprise operators may specify eu-west-1. Data does not cross regional boundaries without an explicit, audit-logged replication event.
Change process
- Proposed additions are announced by email to every enterprise contact on file, and via a dated entry in this page’s history section, at least thirty days before the subprocessor is enabled.
- Removals are announced within seven days.
- Objection window: enterprise operators may object in writing during the thirty-day notice period; if unresolved, the operator has the right to terminate the affected contract for cause under the executed DPA.
Requesting confirmations
Written subprocessor confirmations and per-subprocessor DPAs are available on request to enterprise@nebbos.ai.