Skip to content

Sub-processors

Last updated: 2026-05-07. Versioned at the bottom of this page.

Subscribe to changes: contact pilot@nanorix.io to be notified of sub-processor additions or material changes.


What is a sub-processor

A sub-processor is a third-party service Nanorix uses to deliver our service. Some sub-processors may receive customer data; others receive only operational telemetry (no PHI / PII / regulated data).

Per Nanorix's zero-retention architecture, the substrate itself does not retain customer data beyond capsule lifetime. The sub-processor list below is therefore minimal compared to typical SaaS providers.


Active sub-processors

Infrastructure provider

Sub-processor Purpose Data category Region
Google Cloud Platform (Google LLC) Compute (Cloud Run gen2) + database (Cloud SQL Postgres 15) + storage (GCS) + KMS (Cloud KMS Ed25519) Customer-declared metadata + AuditProof storage + API request logs (operational telemetry; no capsule contents retained per zero-retention discipline) us-central1 (Iowa, USA)

Additional regions (europe-west1, ap-southeast2, ca-central1) are planned and will be listed here when live.

Payment + billing

Sub-processor Purpose Data category Region
Stripe (Stripe, Inc.) Payment processing + subscription billing + metered usage (per-AuditProof billing) Payment instrument metadata (Stripe-tokenized; Nanorix never sees raw card data) + customer billing email + AuditProof emission counters US (primary) with EU + UK regional infrastructure per Stripe's published sub-processor disclosures

Transactional email

Sub-processor Purpose Data category Region
Brevo (Sendinblue SA) Transactional email delivery (signup confirmations + team invitations + billing notifications) Customer signup email + team invitation email + billing notification email (no capsule contents) EU (primary infrastructure)

What is NOT a sub-processor

Some entities customers might assume are sub-processors but are not under Nanorix's processing relationship:

Entity Why it's NOT a sub-processor
Anthropic / OpenAI / customer's own LLM provider Nanorix's substrate orchestrates customer code that calls these services; the customer holds the BAA / DPA with the model provider. Nanorix never proxies model calls; the customer's egress allowlist permits direct customer→provider connection.
Customer's own EHR / data warehouse / object store Customer's egress profile permits direct customer→service connection; Nanorix attests the destruction-of-data boundary, not the downstream storage.
Customer's own KMS / HSM (customer-managed signing keys) Customer signs AuditProofs with their own keys; Nanorix never sees plaintext private key material.

This distinction matters: the Nanorix substrate does not add itself to your downstream BAA chain. Your existing BAAs with model providers + EHR vendors + KMS providers remain unchanged.


Notification of changes

We maintain a log of sub-processor additions or material changes below. Customers on the Team and Enterprise tiers receive 30 days advance notice via the email contact on file before any new sub-processor is added.

To subscribe to change notifications: contact pilot@nanorix.io.


Change log

Date Change
2026-05-07 Initial sub-processor disclosure published.

Contact

Questions about sub-processors: pilot@nanorix.io DPA / BAA inquiries: pilot@nanorix.io Security / privacy: see security and privacy policy