TRUST CENTER

Subprocessors and service dependencies

A transparent inventory of dependency categories; named vendors and regions must match the production deployment and signed agreements.

Last reviewed: 31 August 2026

Configured dependency

PostgreSQL hosting

Stores application and tenant data. The operator, region, encryption and backup terms depend on the selected managed database.

Configured dependency

S3-compatible object storage

Stores private customer uploads. The operator and region are deployment-specific; the bucket must remain private and encrypted.

Configured dependency

OpenAI API

Processes bounded content for enabled AI features. It is disabled by default in staging and production until explicitly enabled.

Configured dependency

Resend email delivery

Receives destination email addresses and transactional message content for verification, recovery and notifications.

Private service

Docling document conversion

Processes imported documents inside the configured private service boundary. The deployment must prevent public ingress.

Optional

Customer-enabled connectors

Google Drive, Confluence, Notion and SharePoint integrations process only after customer authorization. Credentials are encrypted at rest by the application.