Fundation GmbH uses the following subprocessors to run AI-Flow. Each one processes customer data only as needed to deliver the service, under a data processing agreement, and offers EU data processing or Standard Contractual Clauses.
| Subprocessor | Purpose | Data processed | Location | Certifications |
|---|---|---|---|---|
| Heroku (Salesforce) | Application hosting | Application data in transit through the app | EU region | ISO 27001/27017/27019, SOC 1/2/3, PCI-DSS |
| MongoDB Atlas | Database and backups | Knowledge base content, agent configs, usage records, user records | EU | SOC 2 Type II, ISO 27001 |
| Cloudflare | CDN, WAF, TLS termination | Request metadata, IP addresses in transit | Global edge, EU config | SOC 2 Type II, ISO 27001, ISO 27701 |
| Microsoft Entra ID | Authentication (sign-in) | Email, name, tenant ID, auth tokens | Microsoft EU | ISO 27001, SOC 1/2 |
| SolarWinds Papertrail | Log management | Operational logs: request metadata and record identifiers. Document content, prompts and model responses are not written to logs. | United States, under Standard Contractual Clauses | SOC 2 |
Model inference is not our subprocessor
AI-Flow runs on the customer's own LLM API keys. The customer chooses the model provider and inference runs against that provider under the customer's own key and contract. The model provider the customer selects is therefore the customer's own subprocessor, not ours, and it does not appear on this list. Keys are held in an encrypted vault and are never passed into a model's context window.
With AI-Flow the buyer decides where the prompts go, and keeps the key.
Keeping it current
We notify customers before we add or change a subprocessor, so they can object. To be notified of changes to this list, write to [email protected].
Last updated: 14 September 2026. Fundation GmbH, Köln.