Trust
Subprocessors
Status of this document
Engineering draft. Entries marked like this are not yet confirmed and must be filled in from the actual contracts and hosting arrangements before this page is treated as authoritative.
A subprocessor is a third party that may process customer data on our behalf. This page lists them by role, so you can see who is involved before you connect anything.
1. Infrastructure
| Role | Provider | Data processed | Region |
|---|---|---|---|
| Compute and database hosting | To be confirmed | All control-plane records: accounts, workspaces, agents, runtimes, sessions, usage, avatars | To be confirmed |
| TLS certificates | Let's Encrypt (Internet Security Research Group) | Domain names only. No customer data. | United States |
| Domain registration and DNS | To be confirmed | Domain records only. No customer data. | To be confirmed |
| Transactional email | None in use | Korps sends no automated email today. | Not applicable |
| Analytics, advertising, session recording | None in use | No third-party tracking is loaded on korps.ai. See Cookies. | Not applicable |
2. Model providers
Model providers are engaged per workspace, by your configuration. Korps does not send your content to a provider you have not connected to an agent.
Status today: Korps records which provider each agent is assigned to, but it does not hold your provider credential and does not make the model call itself. The key stays on the server you attached, and that server is what contacts the provider. So a provider becomes your processor through your own credential and your own machine, and Korps is not in the path of your prompts.
| Provider | Data processed | Engaged when |
|---|---|---|
| Anthropic | Prompt and response content for agents you assign to it, plus token counts | You connect it to an agent |
| OpenAI | Prompt and response content for agents you assign to it, plus token counts | You connect it to an agent |
| xAI | Prompt and response content for agents you assign to it, plus token counts | You connect it to an agent |
| Google (Gemini) | Prompt and response content for agents you assign to it, plus token counts | You connect it to an agent |
| DeepSeek | Prompt and response content for agents you assign to it, plus token counts | You connect it to an agent |
If you bring your own provider credential, that provider is your contractual counterparty, and their terms govern whether your prompts are retained or used for training. Check them. Korps does not use your content to train models.
3. Infrastructure you attach
Servers, VPS hosts and runtimes you connect to Korps are yours, not ours. Your hosting provider for those machines is your subprocessor, not a Korps subprocessor, and their terms and location are your responsibility.
4. Diligence
Before engaging a subprocessor we intend to check that it offers security appropriate to the data, that a written processing agreement is in place, and that a lawful transfer mechanism exists where data leaves the UK or EEA. Counsel must confirm which of these agreements are actually executed today.
5. Notification of changes
We will publish additions or replacements here before they start processing customer data, and we intend to give at least 30 days' notice for material changes so customers can object. Customers who have signed the Data Processing Addendum may object as set out there. A subscription mechanism for change notices is to be added.
6. Contact
privacy@korps.ai · mailbox to be confirmed