Sub-processors
Notes: Some services are optional or configuration-dependent (e.g., choice of LLM providers, observability tooling). When a service is not enabled for a given deployment, it will not process customer data.
Core infrastructure & hosting
| Sub-processor | Purpose | Location | Notes |
|---|---|---|---|
| Google Cloud (Google LLC) | Host, run, store, and secure the Cortex platform and customer content. Cloud Run · Cloud SQL (PostgreSQL) · Cloud Storage · Pub/Sub · Secret Manager · Cloud Logging/Monitoring · Artifact Registry · Cloud Build | EU (europe-west*) by default | Governed by Google Cloud DPA and security controls. View safeguards → |
| Google (Firebase / Cloud Identity Platform) | User authentication, session management, identity verification. Firebase Auth / Identity Platform | EU (europe-west*) by default | Authentication is a core security control. Governed by Google Cloud DPA. View safeguards → |
AI / model providers (configuration-dependent)
| Sub-processor | Purpose | Location | Notes |
|---|---|---|---|
| Google Cloud (Vertex AI) | AI processing for chat, extraction, generation, embeddings, and document parsing. LLM inference (Gemini) · Embeddings · OCR / Mistral OCR via Vertex | EU (europe-west*) by default | Governed by Google Cloud DPA and security controls. |
| Landing AI | Powering document parsing, extraction, figure description, and schema wizard. AI inference for agentic document extraction and extraction schema generation | EU by default | Governed by Landing AI DPA. View safeguards → |
| OpenAI | AI processing for semantic search, chat, and report generation when configured as the LLM or embedding provider. OpenAI is the default embedding provider. LLM inference · Text embeddings (text-embedding-3-small, default embedder) | United States | Document excerpts sent at inference time only; not used for model training under the API terms of service. Governed by OpenAI Data Processing Addendum. View safeguards → |
| Anthropic | AI processing for chat and report generation when Claude models are configured as the LLM provider. LLM inference (Claude models) | United States (direct API) or EU via Google Vertex AI | When routed via Google Vertex AI, Google Cloud DPA applies and data stays within GCP infrastructure. Direct Anthropic API governed by Anthropic Data Processing Addendum. View safeguards → |
Document editor & collaboration (if enabled)
| Sub-processor | Purpose | Location | Notes |
|---|---|---|---|
| Tiptap GmbH | Convert imported DOCX and Markdown files into the Cortex rich-text document format. Document content is transmitted to the Tiptap Convert API during import. Tiptap Convert — DOCX and Markdown import | EU | Content sent to api.tiptap.dev during import operations only. Governed by Tiptap Data Processing Agreement. View safeguards → |
Observability / product analytics (if enabled)
| Sub-processor | Purpose | Location | Notes |
|---|---|---|---|
| Langfuse (Langfuse GmbH) | Monitor and debug AI runs — latency, quality, prompt/response traces. LLM tracing/observability | EU by Default | Governed by Langfuse DPA. View safeguards → |
Email sending platform
| Sub-processor | Purpose | Location | Notes |
|---|---|---|---|
| Resend | Build modern email templates that works well across all email clients Transactional email | United States | GDPR-compliant hosting
DPA signed with Cube5 (Data processor)
DPA includes a Standard Contractual Clause to handle proper data export from the EU to the US. View safeguards → |
Change management
Cube5 will update this list when adding or replacing sub-processors used to provide Cortex. Customers are notified at least 30 days in advance of material changes in accordance with the Data Processing Agreement.
Last updated: 2026-05-11