Sub-processors

Effective: April 27, 2026 · Last updated: April 27, 2026

This page lists the third-party sub-processors that may process Customer Data on behalf of Tangle Technologies, Inc. ("Tangle"). We update this list when a sub-processor is added, removed, or its role materially changes.

Notification of changes

Subscribe to sub-processor change notifications by emailing [email protected] with subject "Sub-processor notifications". We give at least 30 days' notice before adding a new sub-processor that processes Customer Data, except where the change is required by law or to address a security incident.

Active sub-processors

Sub-processor Service Customer Data processed Region Legal basis
Hetzner Online GmbHCloud infrastructure (compute, storage, networking)All Customer Data within sandboxesGermany / FinlandSCCs
Cloudflare, Inc.Edge security, DNS, DDoS, R2 object storageRequest metadata, IP addresses, audit artifactsUS / EU edge POPsSCCs
Stripe, Inc.Payment processingBilling email, name, payment-method tokens (no full PAN)USDPA
Google LLC (Google Workspace)Staff email, calendar, document collaborationCustomer support communicationsUSDPA
Sentry (Functional Software, Inc.)Error reporting, performance telemetryError events; credentials, PCI cardholder data, and government IDs scrubbed by the runtime redactor before sendUSDPA
OpenAI, L.L.C.LLM inference (when Customer selects an OpenAI model)Prompt + completion text. Egress filter scrubs auth credentials, PCI, and gov-IDs before transmission. store: false enforced when caller hasn't set it.USAPI DPA
Anthropic, PBCLLM inference (when Customer selects an Anthropic model)Prompt + completion text; same redaction as OpenAI. Account-level Zero Data Retention (ZDR) governs vendor retention.USCommercial Terms + ZDR addendum
ResendTransactional email (account, billing, security)Email addresses of account holdersUSDPA
GitHub, Inc.Source hosting, CI execution, container registryTangle internal source; not Customer DataUSEnterprise agreement

Customer-selected model vendors

Customers choose their model vendor at sandbox creation. Selecting a different vendor changes which sub-processor receives prompt content. Customers requiring a specific vendor under their own DPA or BAA should contact [email protected].

Outbound data minimization

Two enforcement layers run before any Customer Data leaves a sandbox to a sub-processor:

  1. Internal observability redaction. Credentials, PCI cardholder data, and government identifiers are stripped from logs, error events, audit trails, and billing events before they leave the runtime.
  2. External egress redaction + no-retention. Outbound JSON bodies to model vendors run through the same redactor; OpenAI Chat Completions are augmented with store: false when the caller hasn't set it.

Customers can fetch the live posture from any sandbox at GET /privacy (authenticated).

Contact

For DPA copies, sub-processor change subscriptions, or SOC 2 Type II report requests: [email protected].