Subprocessors

Fundation GmbH uses the following subprocessors to run AI-Flow. Each one processes customer data only as needed to deliver the service, under a data processing agreement, and offers EU data processing or Standard Contractual Clauses.

Subprocessor Purpose Data processed Location Certifications
Heroku (Salesforce) Application hosting Application data in transit through the app EU region ISO 27001/27017/27019, SOC 1/2/3, PCI-DSS
MongoDB Atlas Database and backups Knowledge base content, agent configs, usage records, user records EU SOC 2 Type II, ISO 27001
Cloudflare CDN, WAF, TLS termination Request metadata, IP addresses in transit Global edge, EU config SOC 2 Type II, ISO 27001, ISO 27701
Microsoft Entra ID Authentication (sign-in) Email, name, tenant ID, auth tokens Microsoft EU ISO 27001, SOC 1/2
SolarWinds Papertrail Log management Operational logs: request metadata and record identifiers. Document content, prompts and model responses are not written to logs. United States, under Standard Contractual Clauses SOC 2

Model inference is not our subprocessor

AI-Flow runs on the customer's own LLM API keys. The customer chooses the model provider and inference runs against that provider under the customer's own key and contract. The model provider the customer selects is therefore the customer's own subprocessor, not ours, and it does not appear on this list. Keys are held in an encrypted vault and are never passed into a model's context window.

With AI-Flow the buyer decides where the prompts go, and keeps the key.

Keeping it current

We notify customers before we add or change a subprocessor, so they can object. To be notified of changes to this list, write to [email protected].

Last updated: 14 September 2026. Fundation GmbH, Köln.