SUBPROCESSOR LIST (CUSTOMER DATA)
Ourfirm.ai, Inc. Effective Date: October 23, 2025 Last Updated: October 23, 2025 Primary Processing Region: United States
This page identifies third-party subprocessors that may process Customer Data to provide the Services. Each subprocessor is bound by confidentiality, security, and data-protection obligations consistent with (and no less protective than) our Data Processing Addendum (“DPA”) and Security Addendum. We do not permit any subprocessor to train models on Customer Data.
Current Subprocessors
| Vendor | Purpose | Data Types | Hosting / Region | Notes |
|---|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure (compute, storage, networking, backups, monitoring) | Customer Data stored/processed by the Services; logs/metrics | U.S. (e.g., us-east) | Encryption at rest and in transit; multi-AZ architecture |
| OpenAI, L.L.C. | Model inference for generation and analysis (where configured) | Prompts/outputs and necessary context provided by the customer | U.S. processing where available | Contractual prohibition on training by default for enterprise endpoints; no model training on Customer Data |
| Anthropic PBC | Model inference for generation and analysis (where configured) | Prompts/outputs and necessary context provided by the customer | U.S. processing where available | Contractual prohibition on training on Customer Data |
| Google (Google Cloud / Gemini) | Model inference for generation and analysis (where configured) | Prompts/outputs and necessary context provided by the customer | U.S. processing where available | Contractual prohibition on training on Customer Data |
| Cerebras Systems, Inc. (as applicable) | Hosted inference for certain open-source models (where configured) | Prompts/outputs and necessary context provided by the customer | U.S. processing where available | No training on Customer Data |
| Mistral AI SAS | Model inference and fine-tuned generation (where configured) | Prompts/outputs and necessary context provided by the customer | U.S. and E.U. processing environments as configured (Paris region by default) | Contractual prohibition on training on Customer Data; encrypted transport and storage; processing performed under SOC 2 Type II-aligned controls |
We endeavor to keep processing within the U.S. If a specific customer integration requires non-U.S. processing (e.g., Mistral’s E.U. cluster), we will obtain customer consent or provide an alternative U.S. processing path where feasible.
Process for Updates
We will provide advance notice of material changes to this list to subscribed admin contacts. Customers may subscribe to updates by emailing privacy@ourfirm.ai with the subject line “Subscribe to Subprocessor Updates.”
Change Log
- 2025-10-23: Initial publication including Mistral AI as approved model subprocessor.
Related Documents
- Terms of Service
- Privacy Policy
- Data Processing Addendum
- Security Addendum