Trust center / Subprocessors

Third-party data paths.

The active provider set is configuration-dependent. This register distinguishes product categories and requires deployment owners to publish the exact enabled vendors before handling customer data.

Provider categories

CategoryPurposeData sent
Model gateway / model providersClaim extraction and adjudicationSubmitted or de-identified claim content and task instructions
Retrieval providersSource discoveryClaim-derived search queries
Email deliveryPasswordless account sign-inEmail address and single-use sign-in URL
Payment processorPaid account checkout and billingBilling and transaction information submitted to the processor
Infrastructure providersRouting, hosting and availabilityNetwork metadata and encrypted service traffic

Current deployment register

Vendor-level publication is a release gate.

The recovered deployment supports multiple optional retrieval and model providers. The staging configuration audit will establish which vendors are actually enabled; no vendor is represented here as active merely because a credential variable exists.

Change process

Material additions should be recorded with provider, purpose, data categories, processing region when known, applicable terms, and effective date before activation. Enterprise agreements may provide notice or objection rights.