Skip to content

All documents public, all kept current with each release

Vol. I · No. 127RahotoFrankfurt · EU-hosted

“The evidence your security team will ask for.”

Trust Center

Sub-processor list

Every vendor that touches customer data, what they do, and their compliance posture. 30-day notice on changes.

Audience
customers, procurement, privacy officers
Last reviewed
2026-07-22

Audience: customers (via trust portal), auditors. Status: Living document — must be re-reviewed every quarter and on every change of vendor.

Last reviewed: 2026-07-22.


Vendor Service Data shared Region Security review status DPA on file
AWS S3, SES, KMS (Govcloud), Route 53 Reports, exports, evidence bundles us-gov-east-1 / eu-central-1 ✅ FedRAMP High; SOC 2 Type II Yes
Hetzner VPS hosting (commercial tier) App tier compute DE (FRA1, NBG1) ✅ ISO 27001; DPA + SCCs Yes
Google Gemini API — multimodal AI provider, activated only after vendor review and environment configuration Redacted dataset summaries and profiles only — never raw rows; PII pseudonymised before egress Provider-controlled; verify contractual region Review required before activation Pending
Anthropic Claude API — optional reasoning provider, routed only where a deployment or organisation configures it Same restricted envelope as above US ✅ SOC 2 Type II Yes
OpenAI OpenAI API — available AI model provider, routed only where a deployment or organisation configures it Same envelope as above: redacted summaries/profiles only; never used for training US ✅ SOC 2 Type II Yes
Recraft Editable vector artwork generation; raster path planned — not enabled until vendor review is complete Prompt and redacted design context; no raw customer datasets Provider-controlled; verify contractual region Review required before activation Pending
Stripe Payments Email, billing address US ✅ PCI DSS Level 1 Yes
PagerDuty Alerts Alert payloads only (no customer data) US ✅ SOC 2 Type II Yes
Sentry (self-hosted) Error monitoring Sanitised error payloads (PII redacted) DE (self-hosted) ✅ self-hosted n/a
Datadog APM, logs (commercial) Sanitised metrics; PHI/PII redacted via PiiRedactor EU pod ✅ SOC 2 Type II; HIPAA BAA Yes
Google (OAuth) SSO Email, name US ✅ SOC 2 Type II Yes
GitHub SSO, source control, CI/CD and encrypted deployment secrets Source code, commit/deployment metadata, encrypted environment secrets US ✅ SOC 2 Type II Yes

A note on AI model providers. Rahoto’s AI subsystem supports multiple model providers; which one handles a request depends on request complexity, deployment configuration, provider health, and the organisation’s policy. Anthropic leads the configured reasoning tier and Gemini leads the configured economical multimodal tier. What leaves Rahoto is always the same restricted envelope: compact, PII-redacted summaries and profiles of your data — never raw rows. Provider activation is also subject to Rahoto’s vendor-review and contractual controls (see how Rahoto handles your data with AI). Organisations can additionally require that confidential or restricted data never reaches a cloud model at all. Bring-your-own-model endpoints that a customer configures are the customer’s own vendor, not a Rahoto sub-processor.


Vendor onboarding workflow

Adding a new vendor that handles customer data:

  1. Open ticket in Linear, label vendor-review.
  2. Complete the security questionnaire (template at docs/compliance/vendor-questionnaire.md).
  3. Collect:
    • SOC 2 Type II (current within 12 months).
    • ISO 27001 or equivalent.
    • DPA / SCCs signed by Legal.
    • Sub-processor list (if vendor uses further sub-processors).
  4. Risk assessment — score 1-5 on:
    • Sensitivity of data shared
    • Region of processing
    • Cert posture
    • Track record / public incidents
  5. Approval threshold:
    • Score < 8: engineering manager approves.
    • Score 8-12: CTO approves.
    • Score > 12: CTO + General Counsel approve.
  6. Once approved:
    • Add row to this table.
    • Add to trust portal sub-processor list (must be public 30 days before vendor goes live for customer data).
    • Document data flow in docs/security/ARCHITECTURE.md.
    • Update SOC 2 / HIPAA / FedRAMP audit packages.

Vendor offboarding

When a vendor is replaced or removed:

  1. Stop sending data to the vendor.
  2. Issue a data deletion request per the DPA.
  3. Verify deletion (vendor must produce a certificate of destruction).
  4. Update this table — mark row “Decommissioned ” and keep for audit history; don’t remove.

Sub-processor commitments to customers

Per the customer DPA:

  • 30 days advance notice before a new sub-processor handles customer data.
  • Customers may object; we’ll work with them or terminate the contract.
  • The trust portal lists current sub-processors and changes feed.