Sub- processors
The third parties SafeGora engages to deliver the Services. Drawn from our internal vendor management register. We notify customers at least 30 days in advance of any addition or replacement, and customers may object on reasonable data-protection grounds per the DPA scaffold.
Status-honest sub-processor list (not a signed DPA exhibit by itself).
This page is the customer-facing stable URL for the current list. Vendor DPA status marked TBD remains open in the internal register. This is not a claim of SOC 2 certification, a completed trust center, or that all enterprise integrations are live. Internal source of truth: docs/security/vendor-management-register.md in the product repository.
As of: July 19, 2026. Changes require a corresponding code update, an entry in the change history below, and customer notification per the SafeGora Data Processing Addendum scaffold Section 7 (template — Legal review before execution).
Notice of change. SafeGora will provide at least thirty (30) days' advance notice before adding or replacing a sub-processor. Customers who have subscribed to sub-processor change notifications via Ollie@safegora.com will receive the notice by email. Customers may object on reasonable data-protection grounds within the notice window; if the parties cannot reach a commercially reasonable resolution, the customer may terminate the affected Services without penalty (DPA scaffold Section 7).
Active sub-processors
| Vendor | Service provided | Categories of data Processed | Processing location | DPA note |
|---|---|---|---|---|
| Google Cloud Platform (Google LLC) | Primary cloud infrastructure: compute (Cloud Run), managed PostgreSQL (Cloud SQL), object storage (Cloud Storage), networking (VPC, Load Balancer, Cloud Armor), observability (Cloud Logging, Cloud Monitoring), secret storage (Secret Manager), managed container registry (Artifact Registry), Pub/Sub, and Cloud DLP inspection used on selected free-text paths. | Customer Personal Data at rest and in transit within the SafeGora platform (tenant-scoped application data, filings artifacts, audit records). | us-west1 (United States) — primary data plane | Google Cloud Data Processing Addendum (account-level). |
| Google Vertex AI / Gemini (Google LLC) — AI inference paths | Generative AI and embeddings used by SafeGora product features (compliance assistance, document/vision/voice paths where enabled, retrieval embeddings). All calls go through the SafeGora LLM facade (kill switches, budgets, PII redaction, grounding) before any external model endpoint. | Tenant-context prompts after ingestion-time and request-time PII redaction where applied; regulatory and tenant chunk text used for embeddings; AI usage telemetry (model, intent, token counts, latency, cost) for governance accounting. | United States. Embeddings: Vertex AI (regional). Text inference today: Google Generative Language API (consumer Gemini API key path). Move to Vertex AI customer-managed terms for text inference is planned, not complete — see the AI notes section. | GCP-hosted Vertex services are covered by the Google Cloud DPA. The consumer Generative Language API path is a separate data-handling posture and is disclosed for procurement review. |
| WorkOS, Inc. | Browser authentication (User Management SDK): password, Magic Auth, and social OAuth code exchange; sealed-session cookie issuance; authentication audit events. Enterprise SSO (SAML/OIDC) and tenant-enforced MFA via WorkOS are planned / deferred — not presented as a completed buyer-live product claim today. | Authentication identifiers (email, tenant association), session credentials, login event records. | United States | WorkOS DPA confirmation on file is an open item in the internal vendor register (Tier-1 onboarding artifact). |
| Stripe, Inc. | Subscription billing: checkout, card tokenization, payment-method storage, invoicing, and subscription lifecycle webhooks. | Billing contact name and email, payment-method tokens (card PAN data is tokenized by Stripe and does not rest in SafeGora systems), invoice and subscription metadata. | United States | Stripe Services Agreement + Data Processing Agreement. |
| Google Workspace (SMTP relay) | Transactional email via application SMTP (account verification, password reset, invites, notifications, filing-related mail). | Recipient email address, sender identity, message subject and body (may include incident or training metadata as configured by Customer use). | United States (Google Workspace / GCP agreements) | Covered under Google Workspace / Google Cloud agreements. |
| Cloudflare, Inc. | Authoritative DNS for safegora.com and related hostnames. SafeGora does not rely on Cloudflare Workers as a Customer Personal Data processing plane. | DNS query metadata for public hostnames. Marketing/public request metadata may transit CDN/DNS edges where enabled. | Global DNS edge; no claim of Customer data residency on Cloudflare compute | Cloudflare DPA confirmation on file is an open item in the internal vendor register. |
AI sub-processor notes (honest)
SafeGora routes product AI through an internal LLM facade with tenant-aware PII redaction and grounding controls before requests leave the control plane. Embeddings use Vertex AI with application default credentials. Text inference today uses the consumer Generative Language API (Gemini API key path). Migration of text inference onto Vertex AI customer-managed terms is planned and not complete. Procurement should treat that distinction as a live discussion point — not as “all AI already on Vertex enterprise terms.”
Google's commitments for Google Cloud services are documented in the Google Cloud Data Processing Addendum and Google Cloud Service Specific Terms.
Not listed as active sub-processors (audit clarity)
- Sentry, PagerDuty, public status-page providers — listed as TBD / confirm usage in the internal vendor register; not asserted as production Customer Personal Data processors here.
- Anthropic / OpenAI — not used for product runtime LLM calls.
- AWS / Azure — not the primary application cloud (single-cloud Google Cloud posture).
- Customer IdPs (Okta, Azure AD, Google Workspace as IdP) — when enterprise SSO ships, federation is planned via WorkOS enterprise connections; that path is deferred (see trust SSO runbook). Customer IdPs are not SafeGora-subscribed subprocessors.
Affiliates and intra-group processing
OllieLabs LLC has no subsidiaries that Process Customer Personal Data at this time. If that changes, the affiliate will be added to this list with the same 30-day advance notice discipline as any third-party sub-processor.
Transfer mechanisms
Primary application data plane is the United States (us-west1). Where Customer Personal Data originates in the European Economic Area, the United Kingdom, or Switzerland, the transfer mechanism contemplated by the DPA scaffold is the EU Standard Contractual Clauses (Module 2: controller-to-processor) and the United Kingdom International Data Transfer Addendum as incorporated by the SafeGora DPA scaffold Section 13. Each sub-processor relationship is intended to be governed by a written agreement imposing data-protection obligations no less protective than the SafeGora DPA once executed; open vendor DPA items are called out above.
Change history
| Effective date | Change |
|---|---|
| 2026-07-19 | Honesty alignment with the internal vendor management register: listed Google Workspace SMTP as the transactional email path; removed vendors not confirmed as production subprocessors in the register (e.g. third-party ESP / unconfirmed error trackers); expanded AI endpoint honesty (Vertex embeddings vs consumer Generative Language API for text inference); added this change-history section for procurement audit trail. |
| 2026-07-14 | Retired Firebase Cloud Messaging (Google LLC) as a sub-processor. Push notification delivery uses the open Web Push standard served directly by SafeGora on Google Cloud (no separate messaging sub-processor); previously stored device push registration tokens were deleted. |
| 2026-05-27 | Added Google Cloud Vertex AI / Gemini entry for generative AI features that route through the SafeGora LLM facade. |
Sub-processors retired (retained for audit trail)
Firebase Cloud Messaging (Google LLC) — retired effective July 14, 2026. Push notification delivery now uses the open Web Push standard served directly by SafeGora on Google Cloud. Previously stored device push registration tokens were deleted.
Firebase / Identity Platform (GCIP) — fully off-boarded as the browser authentication path (WorkOS is the auth processor for all environments). Residual project cleanup is tracked in the internal vendor register off-boarding section.
Subscribe to change notifications
To receive at least 30 days' advance email notice of any sub-processor change, email Ollie@safegora.com with subject Subprocessor change notifications. We will add the requested address to the notification distribution.
Contact
Questions about a listed sub-processor, redline requests, or data-protection objections: Ollie@safegora.com.
Last updated
July 19, 2026 — honesty alignment with the vendor management register and addition of a formal change-history section. Prior: July 14, 2026 (Firebase Cloud Messaging retirement); May 27, 2026 (Vertex AI / Gemini entry).