BrainOrchestra
CapabilitiesPlatformModelsCompliancePricingDocs
Sign inJoin waitlist →Join

Sub-processors

Third parties that process customer data on behalf of Xalerate AB.

Brain Orchestra — Sub-processor List

This document lists the current sub-processors used by Xalerate AB to provide the Brain Orchestra service. It is incorporated by reference into our Data Processing Agreement (legal/DPA.md) as Annex III.

Effective date: May 3, 2026 Last updated: 2026-08-23

How to subscribe to change notifications

When we add or replace a sub-processor, we notify active customers by email at least 14 days in advance, to the email address associated with the customer account. During that notice period, a customer may object in writing to the new sub-processor on reasonable grounds (see DPA Section 4.3).

To receive sub-processor change notices, make sure your account email is current. Enterprise customers with a signed commercial agreement may additionally request change notices to a designated DPO email address.


Infrastructure and platform sub-processors

These sub-processors support Brain Orchestra's operations directly and may receive any personal data processed through the service.

Sub-processorPurposeLocation of processingTransfer mechanism
Railway Corp.Primary hosting (gateway, dashboard, website, PostgreSQL, Redis if applicable)Netherlands (europe-west4) — EUN/A (EU)
Amazon Web Services EMEA SARLAWS Bedrock runtime and AWS Pricing API (for routing Claude, Nova, Titan, and Mistral Devstral through Bedrock, and for refreshing model pricing)Frankfurt (eu-central-1) and Stockholm (eu-north-1) — EUN/A (EU)
Cloudflare (legal entity to be confirmed from the executed DPA)Authoritative DNS for the service's public hostnames (CNAME flattening at the apex). All records are DNS-only: traffic is not proxied through Cloudflare, so no customer request or response content traverses it.To be confirmed from the executed DPATo be confirmed from the executed DPA

Email and communication sub-processors

Sub-processorPurposeLocation of processingTransfer mechanism
Resend, Inc.Transactional email (signup confirmations, password reset, account notices, sub-processor change notices)United StatesEU Standard Contractual Clauses (Module 3, Processor → Sub-processor)

Payment sub-processors

Sub-processorPurposeLocation of processingTransfer mechanism
Stripe, Inc. (with Stripe Payments Europe Ltd for EU customers)Subscription and payment processing (payment methods, invoices, receipts, webhooks)United States (primary) with EU routing via Stripe Payments EuropeEU Standard Contractual Clauses (Module 3, Processor → Sub-processor); Stripe is also a certified EU-US Data Privacy Framework participant

LLM provider sub-processors

Important: the LLM provider sub-processors below only receive Customer Data when the Customer's project is configured to route to them. Each customer controls which providers are enabled for their projects through the territorial tier setting and the routing_preferences.allowed_models list.

Sub-processorPurposeWhen engagedLocation
Anthropic PBCLLM inference for Claude models via the Anthropic direct APIOnly when the customer's project uses the unrestricted territorial tier AND routing_preferences permits Anthropic direct routingUnited States (transferred under SCCs Module 3)
Anthropic PBC via AWS BedrockLLM inference for Claude models via Amazon Bedrock (Frankfurt cross-region inference)When the customer's project uses eu_cloud tierEU (Frankfurt eu-central-1)
OpenAI, LLC (and OpenAI Ireland Ltd for EEA customers)LLM inference for GPT-4o, GPT-o3, GPT-o4-mini via the OpenAI direct APIOnly when the customer's project uses the unrestricted territorial tierUnited States (transferred under SCCs Module 3)
Mistral AI S.A.S.LLM inference for Mistral Small, Medium, Large, Codestral, Pixtral Large, Devstral via the Mistral direct APIWhen the customer's project uses eu_cloud or eu_strict tierFrance — EU
Mistral via AWS Bedrock StockholmLLM inference for Mistral Devstral via Amazon Bedrock Stockholm direct serverlessWhen the customer's project uses eu_sweden tierSweden (Stockholm eu-north-1)
Amazon Web Services — Nova models via Bedrock StockholmLLM inference for Amazon Nova Lite via Amazon Bedrock Stockholm direct serverlessWhen the customer's project uses eu_sweden or eu_cloud tier and routes to Nova LiteSweden (Stockholm eu-north-1) or Netherlands (via EU cross-region inference profile for eu_cloud)
Google LLCLLM inference for Gemini Flash and Gemini Pro via the Google AI direct APIOnly when the customer's project uses the unrestricted territorial tierUnited States (transferred under SCCs Module 3)
Cohere, Inc. via AWS Bedrock FrankfurtEmbedding inference (cohere-embed-multilingual)When the customer's project uses eu_cloud tier and routes to Cohere embeddingsEU (Frankfurt eu-central-1)
Amazon Web Services — Titan embeddings via BedrockEmbedding inference (titan-embed-v2-frankfurt, titan-embed-v2-sweden, titan-multimodal-embed-frankfurt)When the customer's project uses eu_cloud or eu_sweden tier and routes to TitanFrankfurt (eu-central-1) or Stockholm (eu-north-1) — EU
OpenAI — embedding models via direct APIEmbedding inference (openai-embed-3-small, openai-embed-3-large)Only when the customer's project uses the unrestricted territorial tierUnited States (transferred under SCCs Module 3)
xAI Corp.LLM inference for Grok 4.3, Grok 4 Fast, Grok 4, Grok 3 Mini via the xAI direct API (api.x.ai)Only when the customer's project uses the unrestricted territorial tier AND the customer explicitly requests grok-* models by name (xAI is not in default routing)United States (transferred under SCCs Module 3; xAI's named EU representative is Lionheart Squared Ltd, Dublin)
Zhipu / Z.ai — API operator Jingsheng Hengxing Technology Pte. Ltd.LLM inference for GLM-5.2 via the Z.ai direct API (api.z.ai)Only when the customer's project uses the unrestricted territorial tier AND the customer explicitly requests glm-* models by name (Z.ai is not in default routing)Singapore — the international API is operated by Jingsheng Hengxing Technology Pte. Ltd.; content is processed in Singapore under Singapore law, is not used to train models, and is not stored. The Zhipu PRC parent entities are on the US BIS Entity List (a US export-control measure, an ownership note — not the processing location). Transfers under SCCs Module 3 and Transfer Impact Assessment per Schrems II requirements.

For US-hosted providers, transfers are made under the EU Standard Contractual Clauses (Module 3, Processor → Sub-processor) as specified in the table above. Where a provider participates in the EU-US Data Privacy Framework, that framework provides an additional basis for the transfer. Transfer Impact Assessments are conducted and maintained internally and are available to Customers upon request under the audit rights in DPA Section 4.7.

Note on Kimi (Moonshot) models. The direct Moonshot Kimi API (api.moonshot.ai, PRC-hosted) is not a customer sub-processor: it is used only for Brain Orchestra's own internal engineering tooling and is never engaged for Customer Data — a customer request for a direct Moonshot model returns no_route, so no Customer Data is transferred to Moonshot or to the People's Republic of China. The customer-selectable Kimi K2.6 is a separate route: an open-weight model run on EU-sovereign infrastructure operated within the EU, with no service procured from and no runtime connection to the model's author.

EU-hosted open-weight inference sub-processors

These providers host open-weight models on EU infrastructure. Like the LLM provider sub-processors above, they receive Customer Data only when the Customer's project is configured to route to them.

⚠️ Evidential status of the entity and region columns. The rows below are published with those two fields marked to be confirmed from the executed DPA rather than filled from general knowledge, an API region field, or a service tier name. A published sub-processor row is an assertion about a third party's corporate identity and processing location; only that third party's written commitment can source it. A visibly incomplete field is disclosed here in preference to both omitting the row and guessing the value.

Sub-processorPurposeWhen engagedLocation
Evroc (legal entity to be confirmed from the executed DPA)LLM inference for EU-hosted open-weight models offered as evroc-* routesWhen the customer's project uses the eu_sweden, eu_cloud or unrestricted tier and routes to an evroc-* modelTo be confirmed from the executed DPA
Berget (legal entity to be confirmed from the executed DPA)LLM inference for EU-hosted open-weight models offered as berget-* routesWhen the customer's project uses the eu_sweden, eu_cloud or unrestricted tier and routes to a berget-* modelTo be confirmed from the executed DPA
Nebius (legal entity to be confirmed from the executed DPA)LLM inference for open-weight models offered as nebius-* routesOnly when the customer's project uses the unrestricted territorial tier and routes to a nebius-* modelTo be confirmed from the executed DPA — the service's own catalog records the processing region for these routes as unconfirmed, so no region is stated here

PII sub-processors

Sub-processorPurposeLocation of processingTransfer mechanism
Microsoft Presidio (open-source library, self-hosted by Brain Orchestra)PII detection, pseudonymization, and redaction in prompts before they reach LLM providersSame host as Brain Orchestra core (Railway europe-west4 — EU)N/A (self-hosted, no data leaves EU)

Note: Presidio is an open-source library operated by Brain Orchestra on its own infrastructure. It is not a third-party data processor in the legal sense — it is part of Brain Orchestra's platform. It is listed here for transparency because it processes personal data as a distinct service sidecar.

Analytics and observability sub-processors

Brain Orchestra does not use third-party website analytics or product telemetry processors that receive personal data. Observability is handled entirely in-app via the admin dashboard. A Prometheus-compatible /internal/metrics endpoint is available for optional external integration but is not currently connected to any third-party service.

Historical changes

This section records material additions, removals, or replacements of sub-processors. Brain Orchestra is in early operation and will populate this section as changes occur.

DateChange
2026-04-14Initial list created.
2026-04-25Production-ready cleanup; transfer mechanisms confirmed.
2026-04-25Removed Grafana Labs — observability moved fully in-app (6735bc6).
2026-07-23Removed Moonshot AI — the direct Moonshot Kimi API is reclassified internal-only (not customer-selectable; customer requests return no_route), so Moonshot no longer receives Customer Data. Removal reduces data egress and requires no advance notice. Customer-selectable Kimi K2.6 is a separate EU-hosted open-weight route.
2026-08-23Added Evroc, Berget and Nebius. These EU-hosted open-weight inference routes were already customer-selectable and had not been listed. This is disclosure of processors already in the path, not an addition of new ones: who processes has not changed, so DPA Section 4.3 advance notice is not triggered by this correction. Their legal entity and processing region are published as to-be-confirmed from the executed DPA rather than inferred.
2026-08-23Added Cloudflare (authoritative DNS, DNS-only with no proxying). Previously unlisted. Disclosure of an existing arrangement; who processes has not changed.

Questions or objections: support@xalerate.com

Terms of ServicePrivacy PolicyData Processing AgreementSub-processorsQuestions about these terms? support@xalerate.com
BrainOrchestra

Governed LLM access for regulated enterprises. Built by Xalerate AB.

EU AI ActGDPREU-resident
Product
  • Dashboard
  • API Docs
  • Model catalog
  • Shadow AI governance
  • Claude Code via BO
  • Catalog changelog
Company
  • Xalerate AB
  • Contact
Legal
  • Privacy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
  • Responsible Disclosure
Also by Xalerate
  • Nootio
  • Just Smarter Eval
© 2026 Brain Orchestra by Xalerate AB. All rights reserved.
All systems normal