DocReadi uses the third-party sub-processors listed below to deliver the service. Sub-processors are bound by written agreements requiring confidentiality, security, and data-protection commitments equivalent to those we commit to our tenants.
We notify tenant account holders by email at least 30 days before activating a new sub-processor. Tenants may object; the parties will discuss a carve-out or termination right where objection is raised.
Current list
| Sub-processor | Role | Data | Region | Safeguards |
|---|---|---|---|---|
| Anthropic | LLM extraction (primary provider) | Document markdown + optional page images | United States |
|
| OpenAI | LLM extraction (tenant opt-in) | Document markdown + optional page images | United States |
|
| Google (Gemini) | LLM extraction (tenant opt-in) | Document markdown + optional page images | United States / EU |
|
| Mistral | OCR + LLM extraction (tenant opt-in) | PDF bytes or markdown | European Union (France) |
|
| xAI (Grok) | LLM extraction (tenant opt-in) | Document markdown | United States |
|
| OpenRouter | LLM aggregator (tenant opt-in) | Document markdown | United States (aggregator); downstream provider varies — MAY include PRC (China) region models |
|
| Baidu (Qianfan-OCR, via OpenRouter) | OCR-tuned vision LLM — free-tier model (tenant opt-in, DISABLED by default) | Document images + extracted text | China (PRC) |
|
| Alibaba (Qwen, via OpenRouter) | Vision/OCR LLM — Qwen3-VL / Qwen2.5-VL family (tenant opt-in, DISABLED by default) | Document text + optional images | China (PRC) |
|
| Meta (Llama, via OpenRouter) | Vision LLM — Llama 3.2 11B Vision (tenant opt-in, DISABLED by default) | Document text + optional images | Varies (US / EU) — open-weight; the OpenRouter-side host (DeepInfra, Groq, etc.) is the actual data recipient and rotates per request |
|
| Railway | Application + database hosting | All application data at rest and in transit | EU West 4 (the Netherlands) for this deployment |
|
| Amazon Web Services (S3) | Encrypted pg_dump backup storage | Age-encrypted database dumps | United States (us-east-1) |
|
| Meta (WhatsApp Business API) | Inbound document ingestion from WhatsApp (optional per tenant) | Media attachments forwarded from WhatsApp numbers | United States / global |
|
| OpenStreetMap Nominatim | Address geocoding (optional per tenant) | Vendor address strings | European Union |
|
| Sentry | Error tracking (active in production) | Stack traces + request metadata + company_id/user_id tags | Configurable (US or EU) |
|
| Polar | Merchant of Record — international (USD/EUR/GBP) billing | Billing identity (name, email), payment + subscription metadata, company_id | United States / global |
|
| Paystack | Payment processor — South African (ZAR) billing | Billing identity (name, email), payment + subscription metadata, company_id | South Africa / Nigeria |
|
| Resend | Transactional + notification email; Outbox email-delivery destination | Recipient email address, name, email subject/body; AND processed document-bundle attachments when a tenant configures an email delivery destination | United States |
|
| Cloudflare | DNS + inbound email routing + email-in document ingestion (Email Worker) | DNS queries; inbound email envelope + body forwarded to the operator; and — on the email-in ingestion path — tenant supplier-inbox messages incl. their document attachments | United States / global edge |
|
| Xero | Accounting-system delivery — Bill push (optional per tenant; dormant by default) | Approved-document financial data only: supplier/contact name, VAT number, email, invoice number + date, line descriptions, amounts, tax + GL account codes | United States / Australia / European Union (Xero's regions) |
|
Sub-processors marked as providing a specific LLM provider are activated per-tenant: a tenant may choose a default extraction provider and may opt-in / opt-out of alternatives via the tenant settings page. The default provider is Anthropic.
Change history
We maintain an audit trail of sub-processor changes. Current state reflects the list above.
- 2026-04-24: Initial published list.
- 2026-07-01: Split out explicit rows for the PRC-region models routable via the OpenRouter aggregator (Baidu Qianfan-OCR, Alibaba Qwen, Meta Llama) — previously only disclosed inside the OpenRouter row's notes. All three remain disabled by default; a super-admin must opt a tenant in.
Contact
Sub-processor questions: [email protected].