Last updated: April 20, 2026
The following categories of third-party service providers ("subprocessors") may process Customer Personal Data on Vedric's behalf in providing the Services. Each subprocessor is engaged under written agreements that impose data protection obligations no less protective than those in our Data Processing Addendum.
Per our DPA, Vedric provides at least thirty (30) days' advance notice before engaging a new subprocessor that will process Customer Personal Data, except where prevented by law or where the new subprocessor replaces an existing one performing the same function. Active Customers can subscribe to update notifications by writing to legal@vedric.io.
The specific identity of each subprocessor (vendor name, exact data center region, contractual reference) is shared under NDA with Customers and prospective Customers upon written request to legal@vedric.io.
| FUNCTION | PURPOSE | REGION |
|---|---|---|
| Cloud infrastructure | Hosting of application servers, databases, and supporting services | United States |
| Edge / content delivery | TLS termination, DDoS mitigation, content delivery for the Services | Global |
| Transactional email delivery | Sending account, security, and operational notifications | United States |
| Error monitoring | Capturing application exceptions to maintain reliability | United States |
| Payment processing | Subscription billing for Customers (where applicable) | United States |
| AI inference (default) | AI-assisted triage and investigation features use OpenAI by default | United States |
| Self-hosted AI inference (opt-in) | Tenants may opt in to Vedric’s self-hosted ("fsec") inference model in place of OpenAI; runs on US-based GPU infrastructure | United States |
This page is updated when subprocessor categories or functions change. Historical versions are available on request.