Audience: customers (via trust portal), auditors. Status: Living document — must be re-reviewed every quarter and on every change of vendor.
Last reviewed: 2026-07-22.
| Vendor | Service | Data shared | Region | Security review status | DPA on file |
|---|---|---|---|---|---|
| AWS | S3, SES, KMS (Govcloud), Route 53 | Reports, exports, evidence bundles | us-gov-east-1 / eu-central-1 | ✅ FedRAMP High; SOC 2 Type II | Yes |
| Hetzner | VPS hosting (commercial tier) | App tier compute | DE (FRA1, NBG1) | ✅ ISO 27001; DPA + SCCs | Yes |
| Gemini API — multimodal AI provider, activated only after vendor review and environment configuration | Redacted dataset summaries and profiles only — never raw rows; PII pseudonymised before egress | Provider-controlled; verify contractual region | Review required before activation | Pending | |
| Anthropic | Claude API — optional reasoning provider, routed only where a deployment or organisation configures it | Same restricted envelope as above | US | ✅ SOC 2 Type II | Yes |
| OpenAI | OpenAI API — available AI model provider, routed only where a deployment or organisation configures it | Same envelope as above: redacted summaries/profiles only; never used for training | US | ✅ SOC 2 Type II | Yes |
| Recraft | Editable vector artwork generation; raster path planned — not enabled until vendor review is complete | Prompt and redacted design context; no raw customer datasets | Provider-controlled; verify contractual region | Review required before activation | Pending |
| Stripe | Payments | Email, billing address | US | ✅ PCI DSS Level 1 | Yes |
| PagerDuty | Alerts | Alert payloads only (no customer data) | US | ✅ SOC 2 Type II | Yes |
| Sentry (self-hosted) | Error monitoring | Sanitised error payloads (PII redacted) | DE (self-hosted) | ✅ self-hosted | n/a |
| Datadog | APM, logs (commercial) | Sanitised metrics; PHI/PII redacted via PiiRedactor | EU pod | ✅ SOC 2 Type II; HIPAA BAA | Yes |
| Google (OAuth) | SSO | Email, name | US | ✅ SOC 2 Type II | Yes |
| GitHub | SSO, source control, CI/CD and encrypted deployment secrets | Source code, commit/deployment metadata, encrypted environment secrets | US | ✅ SOC 2 Type II | Yes |
A note on AI model providers. Rahoto’s AI subsystem supports multiple model providers; which one handles a request depends on request complexity, deployment configuration, provider health, and the organisation’s policy. Anthropic leads the configured reasoning tier and Gemini leads the configured economical multimodal tier. What leaves Rahoto is always the same restricted envelope: compact, PII-redacted summaries and profiles of your data — never raw rows. Provider activation is also subject to Rahoto’s vendor-review and contractual controls (see how Rahoto handles your data with AI). Organisations can additionally require that confidential or restricted data never reaches a cloud model at all. Bring-your-own-model endpoints that a customer configures are the customer’s own vendor, not a Rahoto sub-processor.
Vendor onboarding workflow
Adding a new vendor that handles customer data:
- Open ticket in Linear, label
vendor-review. - Complete the security questionnaire (template at
docs/compliance/vendor-questionnaire.md). - Collect:
- SOC 2 Type II (current within 12 months).
- ISO 27001 or equivalent.
- DPA / SCCs signed by Legal.
- Sub-processor list (if vendor uses further sub-processors).
- Risk assessment — score 1-5 on:
- Sensitivity of data shared
- Region of processing
- Cert posture
- Track record / public incidents
- Approval threshold:
- Score < 8: engineering manager approves.
- Score 8-12: CTO approves.
- Score > 12: CTO + General Counsel approve.
- Once approved:
- Add row to this table.
- Add to trust portal sub-processor list (must be public 30 days before vendor goes live for customer data).
- Document data flow in
docs/security/ARCHITECTURE.md. - Update SOC 2 / HIPAA / FedRAMP audit packages.
Vendor offboarding
When a vendor is replaced or removed:
- Stop sending data to the vendor.
- Issue a data deletion request per the DPA.
- Verify deletion (vendor must produce a certificate of destruction).
- Update this table — mark row “Decommissioned
” and keep for audit history; don’t remove.
Sub-processor commitments to customers
Per the customer DPA:
- 30 days advance notice before a new sub-processor handles customer data.
- Customers may object; we’ll work with them or terminate the contract.
- The trust portal lists current sub-processors and changes feed.