Sub-processor register
The third parties that process personal information on our behalf. KnowMe does not sell or share personal information. We will update this register before activating any new sub-processor.
| Sub-processor | Purpose | Data processed | Location | Posture |
|---|---|---|---|---|
| OpenAI | Model inference — classification, grounded generation with structured-output citations, and the model-as-judge check. | The visitor’s question + approved public knowledge-base excerpts. Never confidential intake or raw contact details. | United States | No-training / zero-retention API tier. |
| Railway | Application hosting and managed Postgres + pgvector (the per-tenant knowledge base and the audit log). | All tenant data at rest, encrypted. Confidential intake is stored only as opaque ciphertext. | United States (US-EAST) | Infrastructure sub-processor; encrypted in transit and at rest. |
Processed in-boundary — not shared
The most sensitive machine-learning steps — embeddings, reranking, faithfulness checking, and PII detection — run on a self-hosted service inside our trust boundary. They are not sub-processors: that data never leaves to a third party.
Dormant
Anthropic is integrated as a fallback model provider but is not active; no tenant data reaches it unless and until we activate it and update this register.
Last updated June 3, 2026 · See our Privacy notice and privacy choices.