Sub-Processors
The third parties who process data on the Cognethics platform. Every add, edit, and retirement is published the moment it lands in the registry.
Current sub-processors
| Sub-processor | Role | Purpose | Hosting location | Data categories | Contract | BAA |
|---|---|---|---|---|---|---|
| Amazon Web Services | Infrastructure | Compute, storage, database, networking, and managed security (CloudTrail, KMS, GuardDuty, Security Hub, VPC Flow Logs). Sensitive application data is encrypted with a dedicated per-tenant AWS KMS customer-managed key (CMK). | AWS region and availability zone selected by the customer (any AWS region), with a cross-region hot standby | all customer data (encrypted at rest); operational logs; encryption key material (per-tenant customer-managed keys); infrastructure telemetry | DPA + BAA | Signed |
| Anthropic | LLM Provider | Large language model inference for AI features (summaries, classifications, generation, agent reasoning). Accessed via Anthropic API directly and via AWS Bedrock. | Anthropic (US) and AWS Bedrock (US regions) | user prompts; document content for AI processing | Data Processing Agreement | Signed |
| Google (Gemini API) | LLM Provider | Large language model inference for specific workflows including healthcare EOB extraction, denial analysis, technical specification extraction, and invoice parsing. | Google (US regions) | document content for AI processing; extracted structured data | Data Processing Agreement | — |
| Cloudflare | CDN / Edge | Edge CDN, DDoS protection, and Cloudflare Tunnel routing for *.cognethics.com. | Global edge network | request metadata (IP, timestamp, User-Agent, referrer) | Data Processing Agreement | — |
Data processing details
Amazon Web Services (AWS)
Region: AWS region and availability zone selected by the customer (any AWS region), with a cross-region hot standby for regional disaster recovery
Services used:
- EC2 (compute)
- RDS / PostgreSQL (database, AWS BAA signed)
- EBS (storage, encrypted)
- VPC (networking, isolated)
- IAM (access control)
- CloudTrail (audit logging)
- KMS (encryption, auto-rotation enabled)
- GuardDuty (threat detection)
- Security Hub (compliance monitoring)
- VPC Flow Logs (network logging)
BAA status: Signed via AWS Artifact
Encryption: All data encrypted at rest via AWS KMS, with a dedicated per-tenant customer-managed key (CMK) for sensitive application data, and in transit (TLS 1.2+)
Compliance: HIPAA-compatible infrastructure; subject to AWS BAA
Anthropic
Service: Large language models (LLM)
Use case: Primary LLM for AI features (summaries, classifications, generation, agent reasoning)
Data sent: User prompts, document content (encrypted in transit)
Access pattern: Anthropic API directly and via AWS Bedrock
Contract: Anthropic commercial terms; Bedrock traffic covered under the AWS BAA
Google (Gemini API)
Service: Large language models (LLM) — Gemini family
Use case: Narrow extraction workflows — healthcare EOB extraction and denial analysis, spare-parts technical specification extraction, invoice parsing
Data sent: Document content for extraction, structured output (encrypted in transit)
Contract: Google Cloud Data Processing Addendum
Cloudflare
Service: CDN, DDoS protection, request routing
Data sent: Request metadata only (IP address, timestamp, User-Agent, referrer)
No access to: Customer data, documents, database content
Purpose: Performance, security, availability
How we notify you of changes
The sub-processor list is a live registry — every add, edit, and retirement is published the moment it lands in the registry.
- RSS — subscribe to
developers.cognethics.com/trust/sub-processors/feed.xmlin any reader (Feedly, Inoreader, NetNewsWire) to get every change pushed to you. - JSON API — fetch
GET /api/v1/core/sub-processors/for the machine-readable list (public, no auth required). Use theupdated_atfield on each row to drive your own diff tooling. - Email — for customers who prefer email, use the contact form under Requesting more information below, select the Security topic, and ask to be added to the change-notification mailing list.
Every change carries a change_log_entry describing what changed
and why, so subscribers can review impact without reading code.
Requesting more information
Pick the matching topic below and we'll route your request to the right team:
- Sub-processor audit reports or certifications — Security topic
- Sub-processor DPA or BAA details — Legal topic
- Data-handling practices — Privacy topic
Request sub-processor information
Pick a topic and we'll route your message to the right team.
Related policies
- Data Protection Agreement (DPA) — request through the form under Requesting more information above (Legal topic)
- Business Associate Agreement (BAA) — request through the form under Requesting more information above (Legal topic)
- Privacy Policy — /legal/privacy/