Every vendor. Every DPA.
No surprises.
Procurement-ready subprocessor list. We keep this page current - when we sign a new DPA, we add a row here the same day.
Complete TappHQ subprocessor list
Every vendor we share customer data with, their purpose, data location, retention policy, and DPA status.
| Vendor | Purpose | Retention | Region | DPA Status | Links |
|---|---|---|---|---|---|
| Anthropic | The AI models (Claude) behind Ask TappIQ, AI agents, Content Studio, and our content-safety screening. | No retention. Your prompts and the AI's responses are not stored by Anthropic under a zero-retention commercial agreement. | United States | Signed | DPA →Subprocessors → |
| Vercel AI Gateway | Routes AI requests to Anthropic and other model providers, with automatic retries and failover for reliability. | Basic request information retained 30 days for monitoring; message content is not retained. | United States, European Union | Signed | DPA →Subprocessors → |
| Voyage AI | Powers search and content matching across your knowledge base. | No long-term retention. Results are returned and not stored by the vendor. | United States | Signed | DPA → |
| Supabase | Sign-in and account security (multi-factor authentication and recovery codes), the main application database (your records, audit logs, knowledge-base articles, and encrypted credentials), and file storage. Independently SOC 2 Type II certified for authentication. | Kept until you delete it. Records are recoverable for a window before permanent removal, and are fully deleted when an account is closed. | United States (US East) | Signed | DPA →Subprocessors → |
| Upstash | Short-lived counters that enforce rate limits and AI usage budgets. | Temporary only. Data expires within seconds to a day; nothing is kept long-term. | United States, European Union (replicated) | Signed | DPA →Subprocessors → |
| Sentry | Error monitoring to keep the platform reliable. Personal data is scrubbed before it is sent. | 90 days for error events; 30 days for performance events. | United States | Signed | DPA →Subprocessors → |
| Vercel | Hosting and edge network for the TappHQ web application. | Access logs 30 days; build files 90 days. | Global content delivery; primary region United States (US East). | Signed | DPA →Subprocessors → |
| OPSWAT (MetaDefender Cloud) | Malware scanning for uploaded files. Today TappHQ sends only a cryptographic hash of each file for reputation lookup - the file itself does not leave TappHQ. Full-content scanning is disabled pending a signed data processing agreement. | Hash lookups are not retained as customer data by the vendor. No file content is transmitted while full-content scanning remains disabled. | United States | Pending | Subprocessors → |
How we keep this list honest
Vendor onboarding, annual review, change notification, and DPA refresh - documented in our AI Vendor Management Policy.
Annual review
Every vendor is reviewed annually per TappHQ's AI Vendor Management Policy. Per-vendor review dates and DPA refresh cadence are tracked in the annual review log.
30-day notice
TappHQ notifies customers of material changes to the subprocessor list at least 30 days in advance. Enterprise customers may request customer-specific notifications.
Signed DPAs on request
Signed DPAs are available on request for enterprise evaluators. Send your procurement questionnaire (SIG, CAIQ, Vendor Risk Assessment) and we'll respond within three business days.
Day-one transparency
When we sign a new DPA, we add a row to this page the same day. No staging, no approval queue - the table is the source of truth.
Need a signed DPA or vendor questionnaire response?
Send your SIG Lite, CAIQ, or Vendor Risk Assessment. We respond within three business days. Customer-specific subprocessor notifications available for Enterprise.