A sub-processor is a company Zavi Labs, Inc. engages that may process your data in order for Zavi to work. Each one is contractually limited to processing your data on our behalf, for the stated purpose only. We do not sell your data, and none of the vendors below may use it to train their own foundation models on our account.
1. Core sub-processors
Engaged for every account. These can process customer content or personal data in the course of running the Service.
| Sub-processor | Purpose |
|---|---|
| Anthropic | Foundation model provider — Claude API for agent inference |
| OpenAI | Foundation model provider — used for some agent engines and evaluation passes |
| Foundation model provider — Gemini, for some media and content generation | |
| Fireworks AI | Foundation model provider — used for some agent engines and evaluation passes |
| Helicone | Model-gateway and observability proxy. When enabled, model requests route through Helicone, so it processes prompts and completions in transit on our behalf |
| Voyage AI | Embedding and reranking of stored memory notes so agents can retrieve them |
| Supabase | Postgres database, authentication, and Vault storage for OAuth tokens |
| AWS | Hosting (Amplify for web, EC2 for backend, Secrets Manager for production secrets) and Bedrock for some model inference — us-west-1 |
| Inngest | Background job orchestration for agent runs |
| Recall.ai | Meeting bot that joins and transcribes meetings you schedule it for. See the meeting recording section of our Privacy Policy |
| E2B | Isolated sandboxes in which agents execute code on your behalf |
| Anchor | Hosted browser sessions agents use to browse on your behalf |
| Composio | Connector and tool broker for some third-party integrations |
| Pipedream | Connector and tool broker for third-party integrations you connect |
| LiveKit | Real-time audio transport for voice sessions |
| DataForSEO | Search and AI-answer data for search-visibility checks you run |
| Cloudflare | Bot protection (Turnstile) on public forms |
| Stripe | Payment processing and subscription billing |
| SendGrid (Twilio) | Transactional email — sign-in emails, agent results, and agent email replies |
| PostHog | Product analytics for public funnel page views and whitelisted product events |
| Mixpanel | Product analytics for page views and whitelisted product events |
| Apify | Public-web data collection that agents run on your behalf, such as competitor and social research |
| Tavily | Web search that agents run on your behalf |
| Fal | Image and video generation |
| Higgsfield | Video and speech generation |
2. Provisioning sub-processors
Engaged only if you use Zavi to provision infrastructure — a database, a hosted site, or a domain. If you do not use those features, these never receive your data.
| Sub-processor | Purpose |
|---|---|
| Neon | Postgres databases provisioned for projects you ask Zavi to build |
| Render | Hosting for sites and services provisioned on your behalf |
| GitHub | Code repositories created for projects you ask Zavi to build |
| Cloudflare | DNS for domains provisioned on your behalf |
| Domain registrar | Domain registration. Registrant contact details are shared with the registrar, the registry, and ICANN where required by domain policy |
3. Integrations you connect yourself
These are not sub-processors we appointed. You connect each one yourself, and we use that access only for what you connected it for. Disconnecting the integration, or removing Zavi's access in that provider's own settings, ends our access. Data flowing to these providers is a disclosure at your direction.
4. How we announce changes
We update this page when we add or remove a sub-processor, and we change the date at the top when we do. If you would like to be emailed before a new core sub-processor starts processing your data, email support@zaviagent.com and we will add you to the notification list. Customers on a signed Data Processing Addendum receive advance notice as set out in that agreement.
