Axiom Sub-processors
What this is
A sub-processor is a third party we engage that may process customer content on our behalf to run Axiom. We keep this list current. Before a new sub-processor begins processing customer content, we add it here and notify account holders in advance, with an opportunity to object, consistent with our Terms and Data Processing Addendum. Adding or switching a provider (for example a new AI model provider) is an edit to this list and a notice — never a rewrite of the Privacy Policy.
Current sub-processors
| Sub-processor | Purpose | Customer data it holds or transits | Processing region | Status |
|---|---|---|---|---|
| Supabase (Supabase Pte. Ltd.) | Database, authentication, in-project search indexing | All workspace content and account data at rest; account email and sign-in; onboarding inputs. Search indexing runs inside our own Supabase project and is not sent to any embedding vendor. | United States (AWS us-east-2) | Live |
| Railway | Application, worker and website hosting | All workspace text transits the worker while a task runs; operational logs | United States (us-west2) | Live |
| OpenAI | AI model inference | The working context of a task (role description, goal, relevant knowledge, task and acceptance terms), work product being checked, and — once — the onboarding brief. We do not send your account email, your name, or your organization's name or identifiers. | United States (data-residency option not taken) | Live |
| Grafana Cloud (Raintank Inc.) | Uptime monitoring; website analytics | Service-health signal, with no customer content; cookieless, in-session website analytics (page views, funnel events). | United States (US East) | Live |
| Resend | Transactional email (account sign-in and verification messages; workspace alerts to the account owner; website waitlist and enquiry confirmations) | Recipient email address, message content and metadata; for website messages, the details you submitted | United States | Live |
| Stripe | Payment processing (when paid plans open) | Billing contact and payment status; card last four digits — never the full card number | United States | Planned — not yet enabled |
| Cloudflare (Cloudflare, Inc.) | Domain name service and network proxy for the Axiom website | Requests to the website, including the details you submit in its forms, pass through Cloudflare's network | Global network; requests may be handled in data centers outside the United States | Live |
| HubSpot (HubSpot, Inc.) | Customer relationship management: one record for each person who gives us an email address, through our website, an Axiom account, a payment, or a message to our support, privacy or security addresses | The details you submit on our website (name, work email, role and message) and your organization, taken from your email domain; your account email when you open an Axiom account; billing contact, and a record of each payment and refund; your email address and the messages you send to our support, privacy and security addresses; and which of these routes you came through | United States; HubSpot may process in other locations through its affiliates and sub-processors | Live (website waitlist and enquiry details). Planned — not yet enabled for accounts, payments and support mail |
Each provider's own sub-processor list
Each provider maintains its own downstream sub-processor list with its own change-notice mechanism:
- Supabase — https://supabase.com/legal/customer-resources/subprocessor-list (30-day notice)
- Railway — https://trust.railway.com/item/subprocessors
- OpenAI — https://platform.openai.com/subprocessors (30-day objection window)
- Grafana Labs — https://grafana.com/legal (subscribe to change notifications)
- Resend — https://resend.com/legal/subprocessors (14-day notice)
- Stripe — https://stripe.com/legal/service-providers
- Cloudflare — https://www.cloudflare.com/gdpr/subprocessors/
- HubSpot — https://legal.hubspot.com/sub-processors-page
Notes
- "Live" means the provider is engaged in the running product today. "Planned" means the row is drafted so that enabling the provider is a list edit and a notice, not a policy change.
