> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pavoai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sub-Processors

This page lists every third party that can process data on Pavo's behalf, grouped by role. All operate under Data Processing Agreements (DPAs). Optional integrations are **individually gated per instance and disabled unless you enable them — in both deployment models**. The definitive list for your deployment is fixed in the DPA annex, and changes are notified per the DPA.

<Note>
  In Customer VPC deployments there is no customer-data egress by default: the core services below can be self-hosted inside your VPC, and any managed service you choose instead runs from your own account, under your control. See [Customer VPC](/deployment/customer-vpc).
</Note>

## Hosting infrastructure

| Sub-processor          | Purpose                      | Data it processes                                                                                 | Deployment notes                                                            |
| :--------------------- | :--------------------------- | :------------------------------------------------------------------------------------------------ | :-------------------------------------------------------------------------- |
| **Google Cloud (GCP)** | Cloud hosting for Pavo Cloud | All customer data on the platform (classified Confidential); AES-256 at rest, TLS 1.2+ in transit | Pavo Cloud only. In VPC deployments your own cloud account hosts everything |

## Core platform services

| Sub-processor     | Purpose                    | Data it processes                                                                  | Deployment notes                                                                                            |
| :---------------- | :------------------------- | :--------------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------- |
| **Elasticsearch** | Search & retrieval index   | Processed representations of customer data — text, summaries, embeddings, metadata | Pavo Cloud: managed, per-org isolated. VPC: self-hosted (one-click, no egress) or managed from your account |
| **Temporal**      | Durable workflow execution | Workflow state and metadata; may reference customer-data identifiers               | Same choice as above; mTLS throughout                                                                       |
| **Grafana**       | Observability dashboards   | Operational metrics only — no customer data                                        | Same choice as above                                                                                        |

## Model providers

Zero data retention; no training on your data.

| Sub-processor | Purpose       | Data it processes                                  | Deployment notes                                                                                          |
| :------------ | :------------ | :------------------------------------------------- | :-------------------------------------------------------------------------------------------------------- |
| **OpenAI**    | LLM inference | Prompts and completions derived from customer data | ZDR agreement; scoped keys in secrets manager. In VPC, default is in-account inference (Bedrock / Vertex) |
| **Anthropic** | LLM inference | Prompts and completions derived from customer data | Same as above                                                                                             |

## Optional — disabled unless enabled, in both models

| Sub-processor | Purpose                             | Data it processes                                             | Deployment notes                |
| :------------ | :---------------------------------- | :------------------------------------------------------------ | :------------------------------ |
| **Modal**     | On-demand GPU / training compute    | Training and compute inputs, only for jobs you approve        | Individually gated per instance |
| **Langfuse**  | LLM tracing & observability         | LLM traces — prompts, completions, token metadata             | Individually gated per instance |
| **Parallel**  | Public web research for agent tasks | Public web search queries only — no customer data transmitted | Individually gated per instance |

## Supporting services — no customer business data

| Sub-processor | Purpose                            | Data it processes                                                                                 | Deployment notes                                   |
| :------------ | :--------------------------------- | :------------------------------------------------------------------------------------------------ | :------------------------------------------------- |
| **Zitadel**   | Identity & SSO (OIDC)              | Platform user identities: names, work emails, authentication metadata                             | Pavo Cloud: managed. VPC: deployed inside your VPC |
| **Amplitude** | Product usage analytics            | Platform user identifiers (name, work email) and feature-usage events — no customer business data | Pavo Cloud only — not present in VPC deployments   |
| **Brevo**     | Transactional email & OTP delivery | Platform user email addresses and delivery metadata only — no customer business data              | Pavo Cloud only — not present in VPC deployments   |

***

For the DPA and the sub-processor annex for your deployment, contact [**srijan@pavoai.com**](mailto:srijan@pavoai.com).
