Sub-processors¶
Last updated: 2026-05-07. Versioned at the bottom of this page.
Subscribe to changes: contact pilot@nanorix.io to be notified of sub-processor additions or material changes.
What is a sub-processor¶
A sub-processor is a third-party service Nanorix uses to deliver our service. Some sub-processors may receive customer data; others receive only operational telemetry (no PHI / PII / regulated data).
Per Nanorix's zero-retention architecture, the substrate itself does not retain customer data beyond capsule lifetime. The sub-processor list below is therefore minimal compared to typical SaaS providers.
Active sub-processors¶
Infrastructure provider¶
| Sub-processor | Purpose | Data category | Region |
|---|---|---|---|
| Google Cloud Platform (Google LLC) | Compute (Cloud Run gen2) + database (Cloud SQL Postgres 15) + storage (GCS) + KMS (Cloud KMS Ed25519) | Customer-declared metadata + AuditProof storage + API request logs (operational telemetry; no capsule contents retained per zero-retention discipline) | us-central1 (Iowa, USA) |
Additional regions (europe-west1, ap-southeast2, ca-central1) are planned and will be listed here when live.
Payment + billing¶
| Sub-processor | Purpose | Data category | Region |
|---|---|---|---|
| Stripe (Stripe, Inc.) | Payment processing + subscription billing + metered usage (per-AuditProof billing) | Payment instrument metadata (Stripe-tokenized; Nanorix never sees raw card data) + customer billing email + AuditProof emission counters | US (primary) with EU + UK regional infrastructure per Stripe's published sub-processor disclosures |
Transactional email¶
| Sub-processor | Purpose | Data category | Region |
|---|---|---|---|
| Brevo (Sendinblue SA) | Transactional email delivery (signup confirmations + team invitations + billing notifications) | Customer signup email + team invitation email + billing notification email (no capsule contents) | EU (primary infrastructure) |
What is NOT a sub-processor¶
Some entities customers might assume are sub-processors but are not under Nanorix's processing relationship:
| Entity | Why it's NOT a sub-processor |
|---|---|
| Anthropic / OpenAI / customer's own LLM provider | Nanorix's substrate orchestrates customer code that calls these services; the customer holds the BAA / DPA with the model provider. Nanorix never proxies model calls; the customer's egress allowlist permits direct customer→provider connection. |
| Customer's own EHR / data warehouse / object store | Customer's egress profile permits direct customer→service connection; Nanorix attests the destruction-of-data boundary, not the downstream storage. |
| Customer's own KMS / HSM (customer-managed signing keys) | Customer signs AuditProofs with their own keys; Nanorix never sees plaintext private key material. |
This distinction matters: the Nanorix substrate does not add itself to your downstream BAA chain. Your existing BAAs with model providers + EHR vendors + KMS providers remain unchanged.
Notification of changes¶
We maintain a log of sub-processor additions or material changes below. Customers on the Team and Enterprise tiers receive 30 days advance notice via the email contact on file before any new sub-processor is added.
To subscribe to change notifications: contact pilot@nanorix.io.
Change log¶
| Date | Change |
|---|---|
| 2026-05-07 | Initial sub-processor disclosure published. |
Contact¶
Questions about sub-processors: pilot@nanorix.io DPA / BAA inquiries: pilot@nanorix.io Security / privacy: see security and privacy policy