Back to Trust

Sub-Processor List

Third-Party Sub-Processors

Last updated: August 30, 2026

We use third-party services to operate Tempreon. This page lists all sub-processors — companies that process personal data on our behalf. Each provider is selected for its security posture; the certifications each provider holds are listed alongside it, verified against the provider's own trust documentation. Our core infrastructure providers maintain SOC 2 Type II certification or higher.

We will provide at least 30 days advance notice via email before adding new sub-processors that involve a new category of data processing. Changes to providers within the same service category do not constitute a material change.

ServiceCategoryData ProcessedLocationCertifications
SupabaseDatabase & InfrastructureAll user data (Core Imprint, Knowledge Vault, Instincts, behavioral signals)United States (AWS us-east-1)
SOC 2 Type IIHIPAA BAA Available
AnthropicAI InferenceUser prompts, knowledge content assembled for context, Core Imprint sectionsUnited States
SOC 2 Type IIISO 27001:2022ISO/IEC 42001:2023
OpenAIEmbedding InferenceText submitted for vector embedding — knowledge entries, identity sections, and search queries. API data is not used for model training per OpenAI's API data-usage policy.United States
SOC 2 Type IIISO 27001:2022ISO 27701:2019
VercelHosting & CDNRequest metadata, server logs, static assetsUnited States / Global Edge
SOC 2 Type IIISO 27001PCI DSS v4.0
StripePayment ProcessingBilling data, payment methods, subscription statusUnited States / Global
PCI DSS Level 1SOC 2 Type IIISO 27001
ResendTransactional EmailEmail addresses, email content for transactional messagesUnited States
SOC 2 Type II
PostHogProduct AnalyticsUsage events, session data, feature interactions (consent-gated)United States / EU
SOC 2 Type IIHIPAA
SentryError MonitoringError data, stack traces, minimal user context for debuggingUnited States
SOC 2 Type IIISO 27001
CloudflareBot & Abuse MitigationIP address, browser fingerprint signals, request metadata for Turnstile bot challenges on authentication and support surfacesGlobal edge
SOC 2 Type IIISO 27001ISO 27018
UpstashRate LimitingIP address, timestamp, request count for sliding-window rate limits on authentication and support endpoints. Counters expire automatically.United States (AWS us-east-1)
SOC 2 Type II
Google Analytics (GA4)Web AnalyticsPage views, device info, usage data (consent-gated)United States / Global
SOC 2 Type IIISO 27001
Google Tag ManagerTag ManagementScript delivery mechanism only — no user data storedUnited States / Global
SOC 2 Type IIISO 27001
TermlyConsent ManagementVisitor consent records on the public site — consent choices, IP address, and banner interactionsUnited States
GDPR/CCPA DPA available
SlackOperational AlertsInternal operations notifications — signup email addresses and support ticket subject/content routed to our private operations workspaceUnited States
SOC 2 Type IIISO 27001ISO 27018

Change Log

DateChange
August 30, 2026Disclosure completeness pass from a runtime audit: added OpenAI (embedding inference), Termly (consent management), and Slack (operational alerts). All three were already in use — this corrects the list to match the running system; no new category of processing was introduced. Certifications are now listed per provider as verified against each provider's own trust documentation.
April 27, 2026Added Cloudflare (Bot & Abuse Mitigation) and Upstash (Rate Limiting) following pre-launch security hardening
April 6, 2026Initial sub-processor list published

Questions about our sub-processors?

For questions about data processing or sub-processor changes, contact legal@tempreon.com