Legal
Subprocessor Register
Last updated July 14, 2026
Cortex uses the following subprocessors to deliver the platform. This register matches the one published in the Trust Center; customers on the DPA receive 30 days' notice before any new subprocessor goes live.
01Current subprocessors
- Cloud infrastructure (GCP) — compute, storage, managed Postgres. Data: all tenant data (encrypted). Region: customer-selected.
- Anthropic — LLM inference via the Router. Data: prompt + context at run time. Region: US / EU.
- Google (Gemini) — LLM inference via the Router. Data: prompt + context at run time. Region: US / EU.
- OpenAI — optional LLM inference via the Router. Data: prompt + context at run time. Region: US.
- Object storage / CDN — artifact and asset delivery. Data: generated artifacts (encrypted). Region: customer-selected.
- Error & ops telemetry — reliability monitoring. Data: operational metadata only, no payloads. Region: US / EU.
02Notes
Model subprocessors are inference-only and contractually barred from training on customer data. Bring-your-own-key tenants call providers under their own agreements; air-gapped deployments use local models and engage no model subprocessor at all.
To subscribe to change notices, email privacy@cortexaios.com with subject "Subprocessor notices".
Questions about this document: legal@cortexaios.com · See also the Trust Center