Skip to content

Subprocessors and residency

Subprocessors and data residency note

Where the sub-processor list is published, what it covers, and where Customer Data is stored.

Last reviewed: 2026-09-14. Final contractual commitments must be reviewed before signature.

Review status: The list itself is published at https://api.twentycore.ai/api/v1/legal/sub-processors and shown on the privacy page and in the trust center.

The published list

One list names every vendor that receives Customer Data on this deployment, with its purpose, the data it receives and where. The Data Processing Agreement incorporates it by reference.

  • A vendor used only by a feature that is switched off does not appear on it.
  • A new vendor is announced 14 days before it is switched on (DPA clause 4.2).
  • Integrations a customer connects send data to that customer's own accounts and are not sub-processors.

Data residency

Customer Data is stored in DigitalOcean's Singapore region (SGP1): the database, uploaded files and backups.

  • Vendors outside Singapore — AI, email, error monitoring, payments — are listed with their locations.
  • All traffic to the application passes through Vercel and Cloudflare's edge networks.

Customer review

Buyers should review sub-processors, data roles, retention, export, deletion, and legal obligations before production use.

  • Check the published list against your own requirements.
  • Confirm whether a DPA or enterprise agreement is required.
  • Make customer data export available before cancellation or migration.

Buyer checks

Questions this document should help answer.

Which providers receive production customer data?

Where are database, object storage, and backups located?

Which integrations are optional?

What is the data export path if the buyer leaves?