Sub-Processors
Effective Date: May 28, 2026 · Last Updated: May 28, 2026 · Version 2.0
Meridian AI engages the third-party service providers listed below to deliver the Platform. Each sub-processor processes data on our behalf under a Data Processing Agreement (DPA) where applicable, and is bound to confidentiality and security commitments at least as protective as those in our Privacy Policy. We notify customers via email at least 30 days before adding a new sub-processor that materially changes the categories of data shared.
Infrastructure & Hosting
Run the platform, store data, and deliver content to your browser.
Vercel Inc.
United States (global edge)Purpose: Application hosting, serverless functions, edge caching
Data shared: All data flows through the application layer; logs retained 30 days
Railway Corp.
United States (EU West region for primary DB and worker)Purpose: PostgreSQL database, Redis cache, background worker hosting
Data shared: Account data, deal content, AI usage records, OAuth tokens (encrypted), audit logs
Amazon Web Services, Inc.
United States (us-west-2 region for backups)Purpose: S3 object storage for database backups and file uploads
Data shared: Logical pg_dump backups (encrypted), document file uploads
Cloudflare, Inc.
United States (global edge)Purpose: DNS resolution, edge caching via Vercel
Data shared: Request metadata (IP, user agent), no application data
AI Processors
Process the AI prompts you send through Meridian agents. All listed providers contractually commit not to train their public models on customer data.
Anthropic, PBC
United StatesPurpose: Primary AI model (Claude) for all agent workflows
Data shared: Prompts and contextual data you submit to AI agents; AI-generated responses
OpenAI, LLC
United StatesPurpose: Fallback AI model and specialized tasks
Data shared: Prompts when this provider is selected by the model router
Google LLC (Gemini API)
United StatesPurpose: Specific AI tasks (text classification, translation)
Data shared: Prompts when this provider is selected
Communications & Messaging
Send and receive messages on your behalf via integrations you connect.
Resend Inc.
United StatesPurpose: Transactional email delivery (account, billing, notifications, dunning)
Data shared: Recipient email address, subject, body content
Twilio Inc.
United StatesPurpose: SMS messaging via INT-04 integration (when an organization connects it)
Data shared: Phone numbers, message content (only for orgs with connected Twilio credentials)
Meta Platforms, Inc. (WhatsApp Business API)
United StatesPurpose: WhatsApp messaging via INT-03 integration
Data shared: Recipient WhatsApp numbers, message content (only for orgs with connected credentials)
Slack Technologies, LLC
United StatesPurpose: Slack workspace integration via INT-05
Data shared: Workspace ID, channel IDs, message content (sent on your behalf)
LiveKit, Inc.
United StatesPurpose: Video meeting infrastructure (when enabled)
Data shared: Meeting metadata, audio/video streams during active calls
Identity Providers (OAuth)
Authenticate users and grant scoped access to mailbox, calendar, and contacts when integrations are connected.
Google LLC
United StatesPurpose: Google OAuth login, Gmail (INT-01), Google Calendar (INT-02), People API contacts
Data shared: Account profile, OAuth tokens (stored encrypted), and on-demand mailbox/calendar/contacts access scoped to permissions you grant
Microsoft Corp.
United StatesPurpose: Microsoft OAuth, Outlook Mail (INT-06), Outlook Calendar, Microsoft Graph contacts
Data shared: Account profile, OAuth tokens (stored encrypted), and on-demand mailbox/calendar/contacts access scoped to permissions you grant
Payments
Process subscription billing and payment method storage.
Stripe, Inc.
United StatesPurpose: Payment processing, subscription billing, customer portal (PAY-01, PAY-02)
Data shared: Cardholder data (PCI-scope; Stripe-hosted, we receive only customer ID and subscription metadata), billing address, organization name
Observability
Help us detect and resolve errors. Receive limited request context, never deal content.
Functional Software, Inc. (Sentry)
United StatesPurpose: Error monitoring and performance tracing (OPS-02)
Data shared: Error stack traces, request URL, status, user agent, sometimes anonymized user ID. We strip deal content, AI prompts, and OAuth tokens from error reports.
External Data Sources
Queried on-demand when you use the corresponding feature. Your search query and minimum-necessary context are transmitted; no other account data is shared.
PitchBook Data, Inc.
United StatesPurpose: VC/PE company and deal intelligence (DS-10). Per-org credentials.
Data shared: Search queries, company IDs you look up
Crunchbase Inc.
United StatesPurpose: Company and funding round data (DS-11, ENR-CB). Per-org credentials.
Data shared: Search queries, organization IDs you look up
OpenSanctions / Open Sanctions Ltd.
United KingdomPurpose: Sanctions screening across UN, EU, OFAC, and other lists (COMP-01/02, ENR-OS)
Data shared: Names, identifiers you screen
OpenOwnership Ltd.
United KingdomPurpose: Beneficial ownership data (COMP-03, ENR-OO)
Data shared: Company identifiers you query
Nubela Pte. Ltd. (Proxycurl)
SingaporePurpose: LinkedIn profile enrichment for contacts (ENR-PC)
Data shared: Contact names, LinkedIn URLs you enrich
GDELT Project
United StatesPurpose: Global news and events feed (ENR-GDELT)
Data shared: Search queries (public, free dataset)
Newscatcher API
United States / FrancePurpose: EN+AR news aggregation (ENR-NC, DS-09)
Data shared: Search queries and topic filters
U.S. Securities and Exchange Commission (EDGAR)
United StatesPurpose: Public US securities filings (DS-08, ENR-EDGAR)
Data shared: Company CIK and filing identifiers you query (public, free)
Free Law Project (CourtListener)
United StatesPurpose: US court records (ENR-CL)
Data shared: Search queries (public, free)
Magnitt
United Arab EmiratesPurpose: MENA deal and startup data (ENR-MAGNITT)
Data shared: Search queries and company IDs
Development & Source Control
Used to develop and ship the platform; not part of the production runtime.
GitHub, Inc.
United StatesPurpose: Source code repository and CI/CD pipelines
Data shared: No customer data; only source code and CI logs
How to receive change notifications
Enterprise customers automatically receive sub-processor change notifications at their designated privacy contact. To subscribe additional addresses or to receive notifications outside of an active subscription:
Email privacy@meridianai.fyi with the subject line "Subscribe: Sub-processor changes." You can object to a specific sub-processor by replying within 30 days; we will work with you on alternatives or, if no alternative is workable, terminate the affected portion of your subscription with a pro-rata refund.
© 2026 Meridian AI. All rights reserved.