In the default evidence mode (Mode 1) no subprocessor below receives raw customer data — the runner executes inside your perimeter and only hashes, booleans, counts and signatures leave. The rows marked Mode 2 / Mode 3 apply only when you authorise those modes.
Infrastructure and platform
| Subprocessor | What it does | Data involved | Location |
|---|---|---|---|
| Hosting provider | Runs the site, the notary, the console and the immutable evidence store | Account data; hashes, invariant status, nonces, signatures; console ratings | United States |
| Amazon Web Services (KMS, S3 Object Lock) Mode 2 | Per-tenant key custody and immutable storage of non-sensitive cryptographic artefacts; encrypted Mode 2 diagnostics | Pseudonymised AST snippets and execution plans (Mode 2 only, 14-day TTL); hashes and signatures | United States (customer-selectable region on request) |
| Sigstore / Rekor transparency log | Public signature verification for signed runner builds | Build signatures only; no customer data | Public |
| Werify (werify.ai) | Single sign-on and payment authorisation for the console | Account identifiers, email; no assurance content | United States |
| tao.ai OpsDB | Managed database service for the console | Console records, when the database driver is enabled | United States |
| Stripe | Card billing for the Baseline Assurance Sprint | Billing contact and payment details; no assurance content | United States |
| Google Analytics | Aggregate website analytics | Site usage, IP address; no assurance content | United States |
| Email delivery | Transactional and notification email, including recall notices | Name, email, message contents | United States |
| Slack | Internal alerting; shared channels with customers who want one | Notification metadata; anything a customer posts in a shared channel | United States |
| Asana | Work tracking for reported issues, where a customer enables it | Issue contents | United States |
People
| Who | What they do | Data involved | Bound by |
|---|---|---|---|
| EvalQA triage staff Mode 2 | Diagnose an invariant failure from a sanitised export | Pseudonymised AST snippet and execution plan, 14 days | Employment confidentiality; access logged |
| Qualified reviewers (independent contractors) Mode 3 | Adjudicate INDETERMINATE and Sev-1 items on regulated schemas, inside the customer’s VDI | What is visible on screen in the customer-controlled session; nothing transferred | Individual confidentiality agreement, identity verification, time-boxed and logged access, processing location recorded |
Reviewers are the subprocessor that matters most for this service, so they are listed like any other. Before an engagement starts we tell you how many reviewers may be involved, their qualification tier and their processing location. How that access is controlled.
Not used
- No model provider receives your data by default. The Tier-2 automated semantic judge runs on infrastructure we control; if an engagement needs a third-party model we name the provider in the order form first and you can decline it.
- No advertising, marketing-analytics or data-broker services.
- No offshore review without your agreement. If your data must stay in one jurisdiction, say so and we staff accordingly — or tell you we cannot.
How this changes
We give 30 days’ notice before a new subprocessor starts processing customer data. If you object on reasonable data-protection grounds we work with you, and if we cannot resolve it you may terminate the affected service without penalty.