Sub-processors
Last updated: June 28, 2026
To run AgentSpeed we use a small set of trusted third-party services. Each is bound by data-protection terms consistent with our Privacy Policy and DPA. Because we are metadata-first, none of these receive your prompts or model outputs.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel | Application hosting and content delivery | Account and usage data; request metadata | USA |
| Neon | Primary database (Postgres) | Account data and telemetry metadata | USA |
| Upstash | Redis for rate limiting | IP addresses and key identifiers (transient) | USA |
| Cloudflare R2 | Object storage for scan evidence | Scan artifacts and screenshots | USA / Global |
| Anthropic | LLM-powered features (explanations, copilot, failure patterns) | Metadata and derived prompts (no customer prompt or output content) | USA |
| Browserbase | Headless browser for journey canaries | Target URLs and step results | USA |
| Resend | Transactional email | Email address and message content (sign-in links, alerts, digests) | USA |
| Stripe | Payment processing | Billing details and customer identifier | USA / Global |
| Slack | Alert delivery (only if you connect it) | Alert notification content | USA |
| Honeycomb | Operational observability of the Service (optional) | Service performance telemetry | USA |
Changes and notice
We may add or replace sub-processors as the Service evolves. Where the DPA applies, we will give notice of new sub-processors so you have an opportunity to object. To be notified of changes, email privacy@agentspeed.com.