Subprocessors

We use trusted vendors to operate the Services. This page lists subprocessors that may process Customer Content.

Change Notice

We will provide at least 30 days' notice before adding a new subprocessor that processes Customer Content (except in emergencies where immediate action is required for security or operational reasons).

Current Subprocessors

Last updated: August 5, 2026

Vendor Name Purpose Data Categories Regions Trust/Security
Microsoft Azure
Microsoft Corporation
Cloud hosting and infrastructure services Application data, customer content, usage data United States Azure Trust Center →
Stripe
Stripe, Inc.
Payment processing Payment information, billing data Global Stripe Security →
Cloudflare
Cloudflare, Inc.
CDN, DDoS protection, security services Network traffic data, IP addresses Global Cloudflare Trust Hub →
OpenAI
OpenAI, L.P.
Language model inference for AI Coding Guide AI chat messages and text embeddings (session only, not stored). No PHI on self-serve tiers. On BAA-eligible tiers, PHI may be processed under an executed BAA with zero data retention and no training; shaped identifiers are additionally minimized before inference. United States OpenAI Enterprise Privacy →
Azure OpenAI Service
Microsoft Corporation
Planned — not yet in use
Language model inference for AI Coding Guide (planned replacement for OpenAI) AI chat messages and text embeddings (session only, not stored). No customer data is sent to this service today. This notice was published on 7 September 2026; we will begin using it no earlier than 8 October 2026. Microsoft approved modified abuse monitoring for our resource on 7 September 2026: prompts and completions are not stored for any period, are never seen by human reviewers, and are never used to train or fine-tune any model. Inference is pinned to the United States data zone. Until the cutover we continue to use OpenAI. United States (East US 2) Azure OpenAI Data Privacy →
Anthropic
Anthropic, PBC
Language model inference for AI Coding Guide AI chat messages (session only, not stored). No PHI on self-serve tiers. On BAA-eligible tiers, PHI may be processed under an executed BAA with zero data retention and no training; shaped identifiers are additionally minimized before inference. United States Anthropic Privacy Center →
Twilio Verify
Twilio Inc.
SMS OTP for account verification and anti-abuse Phone number (E.164) for OTP only. Not linked to PHI. United States Twilio Privacy →
Google / Microsoft OAuth
Google LLC; Microsoft Corporation
Federated user authentication (sign-in) OAuth identity tokens. No PHI transmitted. United States Provider Privacy →

Notes

  • All subprocessors are contractually bound to protect customer data and comply with applicable privacy and security requirements.
  • For enterprise customers with a BAA, subprocessors that handle PHI are also required to comply with HIPAA requirements.
  • We may use Azure AI services for the Platform AI-assisted coding features when processing customer charts.

Your Objection Rights

Enterprise customers may object to the use of a new subprocessor by contacting us within the 30-day notice period. We will work with you in good faith to find a commercially reasonable solution, which may include not using the new subprocessor for your data or allowing you to terminate the affected services.

To object to a subprocessor or ask questions, contact: [email protected]