The four subprocessors
| Subprocessor | Role | What it touches |
|---|---|---|
| Amazon Web Services | Hosting, and transactional email once enabled | Customer data at rest and in transit, in a single US region (us-east-1). Object storage is encrypted under a per-tenant key, the database under an environment-level key. Amazon SES is provisioned to carry outbound transactional email, but that email is not yet enabled. The product sends no email today. |
| Anthropic (Claude via AWS Bedrock) | Model inference | Customer content submitted for inference, processed in-region inside our own AWS account. No customer data leaves our cloud boundary to reach a model provider, and no inputs or outputs are used to train foundation models. |
| WorkOS | Identity (single sign-on and SCIM directory sync) | It touches sign-in and directory records: the identity your provider asserts and the membership SCIM keeps current, so that deprovisioning takes effect here. It does not touch your compliance content. |
| Tailscale | Administrative network path | No customer content. Tailscale carries the out-of-band admin console on a private network. It is not on the application path your people use. |
Operational vendors
We also disclose vendors that support the business without processing customer content, because omissions read as concealment in a vendor review. None of the five below touches anything you put into the product.
| Vendor | Role | What it touches |
|---|---|---|
| Cloudflare | Bot protection for the marketing site forms, and DNS for zovos.ai | Cloudflare Turnstile checks that a person rather than a bot is sending one of the forms on zovos.ai. It loads when a visitor first moves into a form and receives the visitor's IP address and signals from their browser. On submit, our form endpoints send Cloudflare the one-time token Turnstile issued, with the visitor's IP address, to confirm it. Turnstile sets no cookie on zovos.ai. It protects the marketing site forms only and is not part of the Zovos product. Cloudflare also hosts DNS for zovos.ai. It answers name lookups and does not carry site traffic. No customer content. |
| GitHub | Source control and continuous integration | Our own source code and build logs, in the United States. No customer content. |
| Google Workspace | Our corporate email and documents | Our own correspondence, in the United States. No customer content. |
| Instatus | Public status page and external uptime monitoring | The HTTP responses of our public health endpoints, checked from outside our own infrastructure, and the email address someone gives to subscribe to status updates. It is the monitor of record for the service level in our Terms. Stored in the United States. No customer content. |
| Resend | Newsletter and marketing-site email | It holds the Regulatory Radar mailing list, which is the name and email address someone gives at signup. It also handles delivery and unsubscribes for that list. Stored in the United States. This is the marketing list on zovos.ai and is separate from the product. The product's own transactional email is provisioned through Amazon SES but not yet enabled. |
Changes to this list
Customers receive 30 days notice before any new subprocessor processes customer data. This page is the current list. The same list is available as a document, alongside our other diligence artifacts, from the security page.