Material sub-suppliers

Last updated March 24, 2026

Responsibly uses the following sub-processors and sub-suppliers to deliver its services. Where personal data is transferred outside the European Economic Area (EEA), such transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission or another appropriate safeguard under Chapter V of the GDPR.

This list may be updated from time to time to reflect changes in our supplier relationships. Customers who have subscribed to update notifications will be informed in accordance with the terms of their agreement.

Material sub-supplier register

Sub-supplierProcessing regionNature of processingCertificationsSecurity page
Auth0EU (Germany, Ireland)Platform authentication provider (IAM)ISO 27001, SOC2View
VercelEU (EU project region)IaaS/PaaS, Edge Network and CDN for the Web UI and API endpointsISO 27001, SOC2View
AWSEU (Germany, Ireland, Luxembourg)Cloud hosting provider (IaaS/PaaS)ISO 27001, ISO 27017, ISO 27018, SOC2View
GoogleEU (Germany, Ireland, Netherlands, Belgium, Denmark)Cloud hosting provider (IaaS/PaaS)ISO 14001, ISO 27001, SOC 1, SOC 2, SOC 3View
HubspotEU (Germany)Customer account managementSOC 2 Type II, SOC 3View
MixpanelEU (Germany, Ireland, Netherlands, Belgium, Denmark)Analytics provider for usage dataSOC 2 Type IIView
SentryUS*Technical troubleshooting of customer issuesSOC2 Type I, SOC2 Type II, ISO 27001View
SlackUS*Internal communicationsISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, SOC 3View
ZapierUS*Cross-platform notificationsSOC 2 Type II, SOC 3View
OpenRouterUS*LLM routing and AI gateway servicesSOC 2 Type I, SOC 2 Type IIView
PineconeUS*Vector database and semantic search infrastructureSOC 2 Type II, ISO/IEC 27001View

* Processing takes place in the United States. Transfers of personal data to these sub-suppliers are subject to Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms in accordance with GDPR Chapter V.