LEGAL

Subprocessors

Thabit engages a small set of carefully-vetted third-party service providers (“Subprocessors”) to help deliver the Services. This page lists the current Subprocessors, their purpose, the categories of data they process, and their location. We notify customers at least thirty (30) days before adding or replacing a Subprocessor.

LAST UPDATED · APRIL 17, 2026

Notification preferences. To receive email notifications when this list changes, email privacy@thabit.ai with the subject line “Subprocessor notifications” and the email address where you’d like to receive them.

Infrastructure scope. Not every Subprocessor processes every Customer’s data. For example, GovCloud customers route exclusively through AWS GovCloud and Amazon Bedrock (not Anthropic’s commercial API), and Enterprise customers may elect a self-hosted or regional deployment of certain Subprocessors. The DPA governs applicability for each customer.

Current Subprocessors

ProviderPurposeData categoriesLocationSince
Amazon Web Services (AWS)Cloud infrastructure for GovCloud tier (Phase 3+)Customer Data, logs, backupsUnited States (us-east-1, us-gov-west-1, us-gov-east-1)Planned Q3 2026
AnthropicAI inference (Claude model API) for AI-assisted featuresPrompts (transient), no persistent storageUnited StatesApril 2026
ClerkUser authentication and session managementEmail, name, session tokensUnited StatesPlanned Q2 2026
Cloudflare, Inc.Object storage (R2), WAF, DDoS protectionCustomer Data (package artifacts), request logsUnited StatesPlanned Q2 2026
PostHogProduct analytics (self-hosted option available for Enterprise)Anonymized usage events, session metadataUnited States / EUPlanned Q2 2026
SentryError tracking and performance monitoringError traces, redacted request contextUnited StatesPlanned Q2 2026
StripePayment processing and subscription managementBilling name, address, tax ID, payment card (stored by Stripe only)United StatesPlanned Q2 2026
SupabaseManaged PostgreSQL database, auth, and real-time subscriptionsCustomer Data, account data, audit logsUnited States (us-east-1)Planned Q2 2026
VercelWeb application hosting and CDNRequest metadata, deployment logsUnited StatesApril 2026

Excluded Subprocessors

Thabit does not use the following categories of third parties:

  • Third-party advertising or retargeting networks;
  • Third-party data brokers or enrichment services;
  • AI model training providers (Customer Data is not used to train foundation models);
  • Offshore support vendors.

Standard Contractual Protections

Each Subprocessor operates under a written agreement with Thabit requiring, at minimum:

  • Processing only on documented instructions;
  • Confidentiality commitments for personnel;
  • Security measures consistent with the Thabit Security Overview;
  • Breach notification within 72 hours of discovery;
  • Cooperation with audit, data subject rights, and regulatory inquiries;
  • Deletion or return of data on termination.

Changes to This List

Thabit will update this page prior to engaging a new Subprocessor or materially changing an existing engagement. For customers subscribed to change notifications, email notice will be sent at least thirty (30) days in advance. If you object to a proposed change, the termination rights in Section 5 of our DPA apply.