Trust center

Sub-processors

These are the providers that process data on our behalf. Each row says what actually reaches that provider rather than describing it as "your data". We do not sell personal data to anyone on this list or off it.

Provider Purpose What reaches them Location Terms PHI path
Google Cloud Platform Infrastructure, compute, and storage Account data, work data, audit records United States DPA. BAA available for HIPAA-eligible services. BAA required
Anthropic Model provider for agent execution The task context sent to the model: prompts, code, and documents in scope for that task United States Commercial API terms. No training on submitted data. BAA on first-party API and Enterprise plans only. BAA required
Stytch Authentication and identity Email address, organization, session records United States DPA Never
Umami Website analytics Aggregate page views. No cookies and no personal data. European Union and United States DPA Never
PostHog Product analytics Usage events within the product United States and European Union DPA Never
AWS SES Transactional email Email address and message content United States DPA Never

How this list is used

  • PHI path. "BAA required" means the provider may handle protected health information only once a Business Associate Agreement is executed with them. "Never" means no PHI is routed there at all, by design rather than by policy.
  • Model access. Our default execution path runs on a subscription plan that is not covered by a BAA, so it is never used for PHI. Work in scope for PHI runs on first-party API or Enterprise plans under a signed BAA.
  • Changes. We tell customers before adding or replacing a sub-processor, and you can object. Ask privacy@lucitra.ai to be notified of changes to this page.
  • Contractual basis. Every provider here is under a data processing agreement. The obligations we take on toward you are in our DPA.