Subprocessors.
A subprocessor is a third-party service we use to operate LatentGraph and that may process Customer Content or personal data on our behalf. We engage subprocessors only under written agreements that require them to provide at least the same level of data protection committed to in our Privacy Policy and any executed Data Processing Addendum (DPA). This page is the authoritative, live list.
Active Subprocessors — Infrastructure
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS), Inc. | Cloud compute (EKS, EC2), storage, and networking. All LatentGraph application services run inside our isolated AWS VPC. | All Customer Content, account data, usage data | AWS region(s) used by LatentGraph; Enterprise customers may request a specific region |
LLM Providers (process Customer Content for graph generation)
LLM inference is used to mine implicit dependencies, generate summaries, and extract design intent from PR history. Customer Content (source code excerpts, file paths, commit metadata) is sent to one of the platforms below per request.
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| AWS Bedrock | Hosted LLM inference (e.g. Anthropic Claude) | Source code excerpts, file paths, commit metadata submitted at indexing | US |
| Google Cloud Platform | LLM inference via Vertex AI (e.g. Gemini, Anthropic via Vertex) | Source code excerpts, file paths, commit metadata submitted at indexing | US |
| OpenRouter, Inc. | LLM routing service that proxies inference requests to underlying model providers (e.g. Anthropic, OpenAI, Mistral) per request | Source code excerpts, file paths, commit metadata submitted at indexing | US |
Customer Content sent to LLM providers is not used to train any models — see Privacy Policy §4. Where supported by the underlying provider, zero-retention configurations are enabled. For OpenRouter, retention depends on which underlying model handles a given request; we select routes that support zero retention where feasible.
Enterprise customers can configure bring-your-own-key (BYOK) so that LLM calls run against their own provider account.
Payments
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| PCI-DSS-compliant payment processors | Card, UPI, net banking, and wallet processing; subscription billing; invoicing; tax handling (specific providers will be listed here once integrated) | Billing name, billing address, payment method (processors store card data; we store only last 4 digits and brand), GSTIN where provided, invoice history | India and/or US, depending on the customer's region |
No other third-party services process Customer Content or personal data. Internal company tooling (e.g. email, productivity, code repositories) does not have access to Customer Content.
Notifications of Changes
We give at least 30 days' notice before adding a new subprocessor that processes Customer Content. You can subscribe to change notifications by emailing contact@latentforce.ai with the subject "Subscribe — subprocessor updates".
If you object to a new subprocessor for good-faith reasons, contact contact@latentforce.ai within the notice period. We will work with you in good faith to address the concern, including by offering a configuration that avoids the subprocessor where feasible. If we cannot, you may terminate the affected subscription and receive a pro-rata refund of any unused prepaid fees.
Historical Changes
| Date | Change |
|---|---|
| 01/03/2026 | Initial publication |