We will give notice before adding a sub-processor that receives customer data.
If you need that commitment in contract form, ask — it belongs in the DPA
rather than on a page we can edit.
Message content
One sub-processor receives anything a person typed.Message classification
required
What reaches them: the text of a message addressed to your agent, and the
word
slack or linear. Capped at 4,000 characters. No identifiers of any
kind. Full detail.Why: to decide whether an inbound message is work, so that a greeting does
not open a billable case and a real request is never silently dropped.Model: a pinned version, so answers cannot change under us without a
deliberate change on our side.Their commitments: TypeSafe state that their model is not trained on
customer requests or responses. See Retention for what we
have and have not contracted for.Platform infrastructure
These receive operational data — accounts, connections, telemetry — and none of them receive your source code.
Traces go to whichever target you chose at enrollment — ours or your own
self-hosted instance. If you chose your own, no trace data reaches us at all.
See Where things run.
Who receives nothing
Worth saying explicitly, because it is the question behind the question:- No model provider receives your source code from us. Prompts containing your code go from your machine to your provider on your key. We are not in that path and could not insert ourselves into it.
- No sub-processor holds a credential to your repositories, because we do not hold one either.
If you are filling in a questionnaire
The two answers people usually need:- Data residency: the control plane runs in AWS
ap-south-1. If your procurement requires a specific region, tell us before you sign rather than after — it is a real constraint on where we can put your tenant, not a checkbox. - Sub-processor change notice: see the note at the top of this page, and get it in the DPA.