Trust Center

Subprocessors

Subprocessors are third-party infrastructure and service providers that may process customer data depending on configuration, account settings, and feature usage.

Current provider review

Infrastructure, billing, AI, monitoring, and optional integrations.

This list is intended to help business customers review likely vendor dependencies before onboarding. Optional providers apply only when the relevant feature or environment configuration is enabled.

ProviderService categoryPurposeData categoriesRegion / transfer noteStatusNotes
SupabaseDatabase, authentication, storage if configuredAuthentication, tenant data, lead records, subscription stateAccount identifiers, authentication metadata, tenant records, lead records, subscription references, and storage objects if configured.EU region configured where available / verify project settingsCore infrastructureProject region, backups, and enabled services should be verified before customer onboarding.
VercelHosting and deploymentWeb hosting, serverless runtime, logsRequest metadata, runtime logs, deployment telemetry, and public page assets.Global edge/runtime providerCore infrastructureServer-side secrets should stay in deployment environment variables and never be exposed to client code.
StripePayments and billingCheckout, subscription billing, customer portal, webhook eventsBilling contact details, checkout session data, subscription records, invoice references, and payment event metadata.Stripe global payment infrastructureCore billing providerPayment card details are handled by Stripe and should not be stored by the AgentFlow application.
OpenAIAI processingAI lead qualification and structured scoringLead messages, qualification context, scoring inputs, and AI output fields intentionally sent for processing.Depends on OpenAI processing terms and account configurationAI providerUse prompt and payload minimization. Avoid sending unnecessary personal data or sensitive details.
HubSpotCRM integrationContact sync/enrichment when HUBSPOT_ACCESS_TOKEN is configuredSelected contact fields, company fields, lead status, and CRM handoff notes.Depends on customer HubSpot account and vendor termsOptional integrationActive only when configured for a customer workflow and validated for that workspace.
SlackNotificationsInternal alerts or workflow notifications when SLACK_WEBHOOK_URL is configuredLimited notification payloads, lead routing summaries, and operational alerts.Depends on Slack workspace and vendor termsOptional integrationNotification payloads should avoid raw lead messages and sensitive details where possible.
Google Calendar / Google SheetsProductivity integrationsCalendar/sheets readiness where configuredScheduling metadata, spreadsheet rows, and workflow fields selected by the customer implementation.Depends on Google Workspace account and vendor termsOptional/readiness path unless surfaced in UIValidate OAuth scopes, active UI behavior, and customer configuration before treating as live.
SentryError monitoringError capture and operational diagnosticsError traces, request metadata, stack context, and diagnostic information filtered to avoid raw PII.Depends on Sentry project settings and vendor termsOptional/observability, if configuredFilter sensitive values and avoid attaching customer payloads to diagnostic events.
AmplitudeProduct analyticsGDPR-safe product analytics, page views, funnel analyticsProduct events, page views, funnel events, pseudonymous identifiers, and analytics metadata where configured.EU data region used by server analytics where configured; verify client and project settingsOptional/product analytics, if configuredKeep analytics events aggregated or pseudonymous and avoid raw lead content.
UptimeRobotUptime monitoringPublic uptime checks and status visibilityPublic URL availability, response status, and response timing for monitored endpoints.External monitoring providerExternal monitoring providerHealth and status endpoints should not expose customer records, secrets, or provider payloads.
AWS SESTransactional emailTransactional email if SMTP variables are configuredRecipient email addresses, delivery metadata, and transactional message content required for sending.Depends on SES selected region, verified sending identity, and customer configurationOptional/readiness pathConfirm production access, bounce handling, and complaint monitoring before production sending.

Data minimization

  • Do not send unnecessary personal data to optional integrations.
  • Do not log raw lead messages or sensitive details where avoidable.
  • Use server-side secrets only.
  • Keep provider payloads limited.

Change notification

Customers may review this page for subprocessor changes. AgentFlow Enterprise does not promise a specific notice period on this page unless a signed agreement or separate legal terms state one.

Transparency notice

This page is for transparency and vendor review. It is not a certification or legal opinion.