MAISIGHT REV 01

BLUEPRINT · LEGAL / SUBPROCESSORS

Subprocessors

Last updated 2026-08-15. Back to the legal pack.

This page has not yet been reviewed by counsel and is not legal advice.

The compliance attributes in the last column are the providers' own published claims about themselves, not certifications mAiSight holds. mAiSight is not SOC 2 audited and not ISO 27001 certified.

This is the canonical answer to "where does our data go?" It is the list referenced by the Data Processing Addendum section 6, and it is the list we give 30 days' notice against before changing.

Current subprocessors

Provider Purpose Data processed Region Provider's own compliance claims
Hetzner Cloud Application hosting All customer data, at rest and in transit Falkenstein, Germany (EU) GDPR DPA · ISO 27001
Anthropic Glossary and equation extraction (default model provider), and the evaluation judge Document text sent to the API; prompts cached for one hour United States Zero-retention API option · SOC 2 Type II
Voyage AI Embeddings for cross-document term reconciliation Term and symbol strings, and their definitions United States Privacy policy. We confirm current certification status at onboarding rather than asserting it here.
Cloudflare DNS, and CDN delivery for the embed widget bundle Widget bundle and read-side request IPs, handled by Cloudflare at the edge and never retained by us Global edge GDPR DPA · SOC 2 Type II

The extraction provider is yours to choose

Anthropic is the default, but the extraction model is configurable against any OpenAI-compatible endpoint. Two consequences follow, and both are worth stating plainly to a reviewer:

The evaluation judge used for our own quality measurement stays on Anthropic regardless of your extraction setting; it runs against fixture data, not customer prose.

Not subprocessors

These appear in our operational tooling but do not process customer data.

Adding a subprocessor

Any new third party that would process customer data triggers all three:

  1. A new row in the table above, with every column filled in.
  2. A 30-day customer notice — email to the security contact on file, plus a dated update to this page.
  3. A DPA addendum where the customer has one in place.

Your rights

Contact

Subprocessor questions go to codeblackwell@gmail.com. A dedicated compliance address will be published here once the operating entity is finalized.