Subprocessor List
Last Updated: 2026-03-26 Effective Date: 2026-03-26
Pavri uses the following third-party subprocessors to deliver its services. We notify customers of changes to this list at least 30 days in advance by email or dashboard notification.
Infrastructure Subprocessors
| Subprocessor | Purpose | Location | Data Processed | SOC2 Status |
|---|---|---|---|---|
| Google Cloud Platform (GCP) | Primary cloud infrastructure (Kubernetes, GKE, Cloud Storage) | USA, EU (configurable) | All platform data | SOC2 Type II ✓ |
| Amazon Web Services (AWS) | Secondary / backup infrastructure | USA | Backup data | SOC2 Type II ✓ |
| Microsoft Azure | Secondary infrastructure (Azure Kubernetes Service) | USA, EU (configurable) | Secondary workloads | SOC2 Type II ✓ |
Database and Messaging
| Subprocessor | Purpose | Location | Data Processed | SOC2 Status |
|---|---|---|---|---|
| ClickHouse Cloud (or self-hosted) | Telemetry storage (agent events, sessions) | Customer's chosen region | Agent telemetry events | SOC2 Type II ✓ |
| PostgreSQL (cloud-managed) | Policy state, agent registry, audit logs, account data | Customer's chosen region | Account data, policy config, audit log | Platform SOC2 ✓ |
| NATS JetStream (self-hosted) | Event streaming between services | Customer's cluster | Event envelope metadata | N/A (self-hosted) |
| Redis | Rate limiting state | Customer's cluster | API key + request metadata (no PII) | N/A (self-hosted) |
Authentication
| Subprocessor | Purpose | Location | Data Processed | SOC2 Status |
|---|---|---|---|---|
| WorkOS | Enterprise SSO (SAML/OIDC), user directory, JWT issuance | USA (AWS-hosted) | User identity, email, org membership | SOC2 Type II ✓ |
AI / Machine Learning (Detection Pipeline)
| Subprocessor | Purpose | Location | Data Processed | SOC2 Status |
|---|---|---|---|---|
| Anthropic | T3 LLM judge (async, uncertain cases only) | USA | Subset of flagged prompt content (0.50-0.85 confidence band + 1-5% audit sample) | SOC2 Type II ✓ |
| OpenAI | T3 LLM judge (fallback) | USA | Subset of flagged prompt content (same as above) | SOC2 Type II ✓ |
Note: T3 LLM judge is only invoked for events with confidence scores in the uncertain band (0.50-0.85) and a configurable audit sample (default 1-5% of traffic). Customers can disable T3 in their detection settings to prevent content from leaving their infrastructure. The T0 (patterns) and T1 (ONNX model) tiers run entirely in the customer's environment.
Communications
| Subprocessor | Purpose | Location | Data Processed | SOC2 Status |
|---|---|---|---|---|
| SendGrid (Twilio) | Transactional email (alert notifications, invites) | USA | Email addresses, alert notification content | SOC2 Type II ✓ |
Billing
| Subprocessor | Purpose | Location | Data Processed | SOC2 Status |
|---|---|---|---|---|
| Stripe | Payment processing and subscription management | USA | Payment card data, billing contact information | SOC2 Type II ✓, PCI DSS Level 1 ✓ |
Note: Pavri does not store payment card data. All payment data is handled exclusively by Stripe.
Monitoring and Observability
| Subprocessor | Purpose | Location | Data Processed | SOC2 Status |
|---|---|---|---|---|
| Grafana Cloud (optional) | Metrics dashboards and alerting | EU or USA (configurable) | Prometheus metrics (no PII) | SOC2 Type II ✓ |
| PagerDuty | Incident management and on-call rotation | USA | Incident metadata, contact info | SOC2 Type II ✓ |
Data Processing Agreements
Pavri has executed Data Processing Agreements (DPAs) with all subprocessors that handle personal data. Enterprise customers can request a summary of applicable DPAs from privacy@pavri.ai.
Changes to This List
We will notify customers at least 30 days before adding a new subprocessor that handles personal data. Customers with data processing agreements that include change notification rights may object to new subprocessors in writing within 30 days of notification.
Contact: privacy@pavri.ai