Skip to Content
Trust centerSubprocessor list

Subprocessor list

Nebbos engages a small set of subprocessors to operate the platform. This page names each, what they process, where they operate, and what changes trigger a customer notification.

This list is authoritative. If a service isn’t on it, we don’t send customer data to that service. If we plan to add a subprocessor, notice lands at least thirty days before the addition takes effect — see the change process at the bottom of this page.

Current subprocessors

SubprocessorPurposeLocationData touched
Amazon Web Services (AWS)Primary cloud infrastructure — compute, storage, data planeus-east-1, eu-west-1All operator-scoped data at rest and in transit
CloudflareEdge network, DDoS mitigation, WAF, static asset deliveryGlobal (Anycast)Request metadata, static assets. No operator-scoped row data.
WorkOSIdentity plane — SSO, directory sync, user lifecycleus-east-1Operator identity records, group memberships, session tokens
Anthropic / OpenAI / Google VertexThird-party model inference (only for redacted-to-cloud tier)us-east-1, eu-west-1PII-stripped prompt content per per-operator tier policy. Model providers contractually cannot train on data.
DopplerSecrets management — platform-side credentials onlyus-east-1Platform credentials, never customer credentials
SentryError trackingeu-west-1Application-layer errors with PII scrubbing; row-level payload never sent
PostmarkTransactional email deliveryus-east-1Recipient addresses, email body content

Data residency

All operator-scoped structured data resides in the region assigned at deployment time. For Team-tier operators, this is us-east-1 by default; Enterprise operators may specify eu-west-1. Data does not cross regional boundaries without an explicit, audit-logged replication event.

Change process

  • Proposed additions are announced by email to every enterprise contact on file, and via a dated entry in this page’s history section, at least thirty days before the subprocessor is enabled.
  • Removals are announced within seven days.
  • Objection window: enterprise operators may object in writing during the thirty-day notice period; if unresolved, the operator has the right to terminate the affected contract for cause under the executed DPA.

Requesting confirmations

Written subprocessor confirmations and per-subprocessor DPAs are available on request to enterprise@nebbos.ai.