BrainOrchestra
CapabilitiesPlatformModelsCompliancePricingDocs
Sign inJoin waitlist →Join

Sub-processors

Third parties that process customer data on behalf of Xalerate AB.

Brain Orchestra — Sub-processor List

This document lists the current sub-processors used by Xalerate AB to provide the Brain Orchestra service. It is incorporated by reference into our Data Processing Agreement (legal/DPA.md) as Annex III.

Effective date: May 3, 2026 Last updated: 2026-09-16

How to subscribe to change notifications

What this list covers, and how it is derived. This list covers the processors in the request path of the service as built. For inference routes, the service's live routing catalog at the served software version is the authoritative source: a provider is listed here because the catalog routes to it, and the tiers named as "when engaged" are the tiers on which the router can select that route. Infrastructure, email and payment rows are taken from the service's deployed configuration. Any field that only a vendor's written commitment can source (legal entity, contractual processing location) is marked as not established rather than filled in. The list is reconciled against the deployed software on each update; the date below is the date of the last such reconciliation.

When we add or replace a sub-processor, we notify active customers by email at least 14 days in advance, to the email address associated with the customer account. During that notice period, a customer may object in writing to the new sub-processor on reasonable grounds (see DPA Section 4.3).

To receive sub-processor change notices, make sure your account email is current. Enterprise customers with a signed commercial agreement may additionally request change notices to a designated DPO email address.


Infrastructure and platform sub-processors

These sub-processors support Brain Orchestra's operations directly and may receive any personal data processed through the service.

Sub-processorPurposeLocation of processingTransfer mechanism
Railway Corp.Primary hosting (gateway, dashboard, website, PostgreSQL, Redis if applicable)Netherlands (europe-west4) — EUN/A (EU)
Amazon Web Services EMEA SARLAWS Bedrock runtime (routing Claude, Nova, Titan, Cohere embeddings and Mistral Devstral through Bedrock), Amazon Polly (text-to-speech routes), Amazon Transcribe streaming (speech-to-text routes) and the AWS Pricing API (refreshing model pricing)Frankfurt (eu-central-1) and Stockholm (eu-north-1) — EUN/A (EU)
Microsoft (legal entity not established — only the vendor's written commitment can source it)Azure OpenAI Service — LLM inference for the azure-gpt-5-4 route onlySweden Central per the configured Azure OpenAI endpoint (contractual location not established — only the vendor's written commitment can source it) — EUN/A (EU)
Cloudflare (legal entity not established — only the vendor's written commitment can source it)Authoritative DNS for the service's public hostnames. The production customer-facing hostnames (api.brainorchestra.ai, www.brainorchestra.ai, www.xalerate.ai) are DNS-only records pointing at Railway: traffic to them is not proxied through Cloudflare, so no customer request or response content traverses it. The staging hostname and the xalerate.ai apex are proxied through Cloudflare; neither serves customer production data (staging accepts test keys only; the apex serves no API).Not established — only the vendor's written commitment can source itNot established — only the vendor's written commitment can source it

Email and communication sub-processors

Sub-processorPurposeLocation of processingTransfer mechanism
Resend, Inc.Transactional email (signup confirmations, password reset, account notices, sub-processor change notices)United StatesEU Standard Contractual Clauses (Module 3, Processor → Sub-processor)

Payment sub-processors

Sub-processorPurposeLocation of processingTransfer mechanism
Stripe, Inc. (with Stripe Payments Europe Ltd for EU customers)Subscription and payment processing (payment methods, invoices, receipts, webhooks)United States (primary) with EU routing via Stripe Payments EuropeEU Standard Contractual Clauses (Module 3, Processor → Sub-processor); Stripe is also a certified EU-US Data Privacy Framework participant

LLM provider sub-processors

Important: the LLM provider sub-processors below only receive Customer Data when the Customer's project is configured to route to them. Each customer controls which providers are enabled for their projects through the territorial tier setting and the routing_preferences.allowed_models list.

Sub-processorPurposeWhen engagedLocation
Anthropic PBCLLM inference for Claude models via the Anthropic direct APIOnly when the customer's project uses the unrestricted territorial tier AND routing_preferences permits Anthropic direct routingUnited States (transferred under SCCs Module 3)
Anthropic PBC via AWS BedrockLLM inference for Claude models via Amazon Bedrock (Frankfurt cross-region inference)When the customer's project uses eu_cloud tierEU (Frankfurt eu-central-1)
OpenAI, LLC (and OpenAI Ireland Ltd for EEA customers)LLM inference for the GPT-4.1, GPT-4o, GPT-5 and o-series routes via the OpenAI direct API (the live model catalog is authoritative for the exact routes)Only when the customer's project uses the unrestricted territorial tierUnited States (transferred under SCCs Module 3)
Mistral AI S.A.S.LLM inference (Mistral Small, Medium, Large, Codestral, Magistral, Pixtral, Devstral), embeddings (Mistral Embed, Codestral Embed), speech-to-text and text-to-speech (Voxtral) and document OCR via the Mistral direct APIWhen the customer's project uses the eu_strict, eu_cloud or unrestricted tier and routes to a Mistral direct modelFrance — EU
Mistral via AWS Bedrock StockholmLLM inference for Mistral Devstral 2 via Amazon Bedrock Stockholm direct serverless (mistral-devstral-sweden)When the customer's project uses the eu_sweden, eu_cloud or unrestricted tier and routes to mistral-devstral-swedenSweden (Stockholm eu-north-1)
Amazon Web Services — Nova models via Bedrock StockholmLLM inference for Amazon Nova Lite via Amazon Bedrock Stockholm direct serverless (nova-lite-sweden)When the customer's project uses the eu_sweden, eu_cloud or unrestricted tier and routes to nova-lite-swedenSweden (Stockholm eu-north-1) on every tier
Google LLCLLM inference for the Gemini Flash and Gemini Pro routes via the Google AI direct APIOnly when the customer's project uses the unrestricted territorial tierUnited States (transferred under SCCs Module 3)
Cohere, Inc. via AWS Bedrock FrankfurtEmbedding inference (cohere-embed-multilingual-frankfurt)When the customer's project uses the eu_cloud or unrestricted tier and routes to Cohere embeddingsEU (Frankfurt eu-central-1)
Amazon Web Services — Titan embeddings via BedrockEmbedding inference (titan-embed-v2-frankfurt, titan-embed-v2-sweden, titan-multimodal-embed-frankfurt)When the customer's project uses the eu_cloud, eu_sweden or unrestricted tier and routes to TitanFrankfurt (eu-central-1) or Stockholm (eu-north-1) — EU
OpenAI — embedding models via direct APIEmbedding inference (openai-embed-3-small, openai-embed-3-large)Only when the customer's project uses the unrestricted territorial tierUnited States (transferred under SCCs Module 3)
xAI Corp.LLM inference for the Grok 4.x and Grok 3 Mini routes, plus Grok image generation, text-to-speech and speech-to-text, via the xAI direct API (api.x.ai)Only when the customer's project uses the unrestricted territorial tier and routes to a grok-* model (by explicit name, or by automatic selection on that tier)United States (transferred under SCCs Module 3; xAI's named EU representative is Lionheart Squared Ltd, Dublin)
Zhipu / Z.ai — API operator Jingsheng Hengxing Technology Pte. Ltd.LLM inference for GLM-5.2 via the Z.ai direct API (api.z.ai)Only when the customer's project uses the unrestricted territorial tier and routes to the glm-* direct model (by explicit name, or by automatic selection on that tier)Singapore — the international API is operated by Jingsheng Hengxing Technology Pte. Ltd.; according to Z.ai's published international-API terms, content is processed in Singapore under Singapore law, is not used to train models, and is not stored (the vendor's own written statement; not independently verified by Xalerate). The Zhipu PRC parent entities are on the US BIS Entity List (a US export-control measure, an ownership note — not the processing location). Transfers under SCCs Module 3 and Transfer Impact Assessment per Schrems II requirements.

For US-hosted providers, transfers are made under the EU Standard Contractual Clauses (Module 3, Processor → Sub-processor) as specified in the table above. Where a provider participates in the EU-US Data Privacy Framework, that framework provides an additional basis for the transfer. Transfer Impact Assessments are conducted and maintained internally and are available to Customers upon request under the audit rights in DPA Section 4.7.

Note on Kimi (Moonshot) models. The direct Moonshot Kimi API (api.moonshot.ai, PRC-hosted) is not a customer sub-processor: it is used only for Brain Orchestra's own internal engineering tooling and is never engaged for Customer Data — a customer request for a direct Moonshot model returns no_route, so no Customer Data is transferred to Moonshot or to the People's Republic of China. The customer-selectable Kimi K2.6 / Kimi K3 are separate routes (evroc-kimi-k2-6, berget-kimi-k3): open-weight models run on EU infrastructure operated within the EU, with no service procured from the model's author (for the Evroc route, the published weights run locally on Evroc's Stockholm region).

EU-hosted open-weight inference sub-processors

These providers host open-weight models on EU infrastructure. Like the LLM provider sub-processors above, they receive Customer Data only when the Customer's project is configured to route to them.

⚠️ Evidential status of the entity and region columns. The rows below are published with those two fields marked not established rather than filled from general knowledge, an API region field, or a service tier name. A published sub-processor row is an assertion about a third party's corporate identity and processing location; only that third party's written commitment can source it. A visibly incomplete field is disclosed here in preference to both omitting the row and guessing the value.

Sub-processorPurposeWhen engagedLocation
Evroc (legal entity not established — only the vendor's written commitment can source it)LLM inference for EU-hosted open-weight models offered as evroc-* routesWhen the customer's project uses the se_sovereign, eu_sweden, eu_strict, eu_cloud or unrestricted tier and routes to an evroc-* modelNot established — only the vendor's written commitment can source it
Berget (legal entity not established — only the vendor's written commitment can source it)LLM inference for EU-hosted open-weight models offered as berget-* routesWhen the customer's project uses the se_sovereign, eu_sweden, eu_strict, eu_cloud or unrestricted tier and routes to a berget-* modelNot established — only the vendor's written commitment can source it
Nebius (legal entity not established — only the vendor's written commitment can source it)LLM inference for open-weight models offered as nebius-* routesOnly when the customer's project uses the unrestricted territorial tier and routes to a nebius-* modelNot established — the service's own catalog records the processing region for these routes as unconfirmed, and only the vendor's written commitment can source it

PII sub-processors

Sub-processorPurposeLocation of processingTransfer mechanism
Microsoft Presidio (open-source library, operated by Xalerate as its own service)PII detection, pseudonymization, and redaction in prompts before they reach LLM providersXalerate's own service in the same Railway project and region as the gateway (europe-west4 — EU), per the deployed configurationN/A (operated by Xalerate; not a third party)

Note: Presidio is an open-source library operated by Brain Orchestra on its own infrastructure. It is not a third-party data processor in the legal sense — it is part of Brain Orchestra's platform. It is listed here for transparency because it processes personal data as a distinct service sidecar.

Analytics and observability sub-processors

As of the reconciliation date, a scan of the service's tracked website, dashboard and gateway source code found no third-party analytics or product-telemetry SDK, no external script tag and no such dependency; observability is handled in-app via the admin dashboard. This statement is bounded to that scan and is repeated at each reconciliation. A Prometheus-compatible /internal/metrics endpoint is available for optional external integration but is not currently connected to any third-party service.

Historical changes

This section records material additions, removals, or replacements of sub-processors. Brain Orchestra is in early operation and will populate this section as changes occur.

DateChange
2026-04-14Initial list created.
2026-04-25Production-ready cleanup; transfer mechanisms confirmed.
2026-04-25Removed Grafana Labs — observability moved fully in-app (6735bc6).
2026-07-23Removed Moonshot AI — the direct Moonshot Kimi API is reclassified internal-only (not customer-selectable; customer requests return no_route), so Moonshot no longer receives Customer Data. Removal reduces data egress and requires no advance notice. Customer-selectable Kimi K2.6 is a separate EU-hosted open-weight route.
2026-08-23Added Evroc, Berget and Nebius. These EU-hosted open-weight inference routes were already customer-selectable and had not been listed. This is disclosure of processors already in the path, not an addition of new ones: who processes has not changed, so DPA Section 4.3 advance notice is not triggered by this correction. Their legal entity and processing region are published as not established rather than inferred.
2026-08-23Added Cloudflare (authoritative DNS, DNS-only with no proxying). Previously unlisted. Disclosure of an existing arrangement; who processes has not changed.
2026-09-16Added Microsoft Azure OpenAI Service (the azure-gpt-5-4 route, Sweden Central) — disclosure of a route already in the path, not a new processor. Corrected the Cloudflare row: production customer hostnames are DNS-only; the staging host and the xalerate.ai apex are proxied. Corrected "when engaged" tiers and purposes to match the live routing catalog (Mistral direct also on unrestricted; Devstral/Nova/Titan/Cohere Bedrock routes also on unrestricted; Evroc/Berget on all five tiers; AWS row now names Polly and Transcribe). Corrected a published processing LOCATION: Amazon Nova Lite is served from Stockholm (eu-north-1) on every tier; the earlier statement that eu_cloud requests use a Netherlands cross-region profile was wrong. Added a scope-and-derivation statement beside the change-notice clause; replaced "to be confirmed from the executed DPA" with "not established" wherever only a vendor's written commitment can source a field; bounded the analytics statement to a source scan; removed the unsupported "not in default routing" qualifiers on the xAI and Z.ai rows. Reconciled the two published copies into one document and added a CI guard that keeps them identical.

Questions or objections: support@xalerate.com

Terms of ServicePrivacy PolicyData Processing AgreementSub-processorsQuestions about these terms? support@xalerate.com
BrainOrchestra

Governed LLM access for regulated enterprises. Built by Xalerate AB.

EU AI ActGDPREU-resident
Product
  • Dashboard
  • API Docs
  • Model catalog
  • Shadow AI governance
  • Claude Code via BO
  • Catalog changelog
Company
  • Xalerate AB
  • Contact
Legal
  • Privacy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
  • Responsible Disclosure
Also by Xalerate
  • Nootio
  • Just Smarter Eval
© 2026 Brain Orchestra by Xalerate AB. All rights reserved.
All systems normal