DRAFT — verify before publishing. This list is a template scaffold. Confirm the actual vendors, regions, and purposes against your live infrastructure and contracts before relying on it. Sub-processors must be kept current under GDPR Art. 28.
Brahmalabs engages the third-party sub-processors below to help deliver the platform. Each is bound by data-protection terms no less protective than our Data Processing Addendum, and we remain responsible for their performance. This page reflects our SaaS offering; self-hosted / on-premises deployments run in the customer's own environment and typically involve none of these sub-processors for customer data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud / hosting provider | Compute, networking, managed Kubernetes hosting the platform | EU / US (region-selectable) |
| Object storage (MinIO / S3-compatible) | Storage of run artifacts, knowledge-base documents, and skill bundles | Same region as deployment |
| Managed PostgreSQL | Application database and per-tenant data | Same region as deployment |
| Container registry | Storage of platform and custom sandbox images | Same region as deployment |
| Sub-processor | Purpose | Location |
|---|---|---|
| WorkOS | Authentication, single sign-on, and organisation directory | US |
| Dodo Payments | Payment processing and billing (Merchant of Record) | US / global |
| Email / notification provider | Transactional email and product notifications | US / EU |
| Analytics (cookieless) | Privacy-preserving product analytics | EU / US |
Brahmalabs is bring-your-own-key: when a customer connects their own model-provider key, inference requests are routed to that provider under the customer's own account and terms. Those providers act as the customer's own sub-processors, not ours. We route requests through our LLM gateway but do not mark up or retain model inference. Customers select which providers (e.g. Anthropic, OpenAI, Google, or self-hosted models) they enable.
We will update this page and, for material additions, give advance notice to customers (via the dashboard and/or email to account administrators) before a new sub-processor begins processing. Customers may object on legitimate data-protection grounds by emailing [email protected]; we will work in good faith to address reasonable objections.
To subscribe to sub-processor change notices, contact [email protected].