Effective date: October 1, 2026
Version: 26a-subprocessors-v1-2026-10-01
Last updated: October 1, 2026
Changelog: Initial register from repository, runtime/provider, and enabled-feature audit. Separates current, optional, and planned paths.
This list is based on code/configuration-path review, not a certification that a provider is connected for a specific customer, has received a particular payload, or has signed a specific agreement. "Current" means a present product processing path or service exists. "Optional / gated" requires a separate connection, action, feature setup, or consent. "Planned only" is not a current processing connection.
We do not claim universal provider locations, completed transfer terms, a blanket no-training agreement, or contract status not evidenced in current records. For route-specific provider and deployment locations, request current written confirmation before relying on a location commitment.
Current: product-controlled path is used or is part of the service; this does not show that a customer's account is connected.
Optional / gated: the customer must establish an account/connection, authorize the scope, or initiate the relevant task.
Planned only: roadmap item, not a live customer-facing provider connection.
| Provider / service | Status | Purpose | Information that may be processed | Location | Scope and source note |
|---|---|---|---|---|---|
| Anthropic and OpenAI | Current | Direct model-response routes. | Prompts, model replies, relevant submitted workspace context, and request metadata needed for the selected task. | Endpoint, account, billing plan, and provider region vary by route and have not been verified as a blanket deployment fact. | Direct response paths exist. Provider terms and retention differ; see the Privacy Policy for the exact training/data-retention caveat. |
| Clerk | Current | Authentication, account identity, and sessions. | Account identifiers, email/profile fields returned by the selected sign-in method, authentication events, and session/security information. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Required application authentication provider. Exact Clerk cookie names have not been independently verified. |
| Cloudflare | Current | DNS and Turnstile contact-form anti-abuse checks. | DNS/routing request information and contact-form abuse-check browser/request signals, as applicable. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Cloudflare DNS is current. This does not mean Cloudflare customer-site hosting or Cloudflare for SaaS is a live product feature. |
| Google Fonts | Current | Font delivery on public pages. | Font request and browser network information, including IP address. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Not product analytics and not controlled by optional analytics preferences. |
| Google Gemini | Current | Grounded web-research/visibility tasks, not ordinary agent chat. | The query or research content required by the selected grounded research task. | Google project, billing plan, and processing region have not been verified. | Research route only. Google's no-training treatment differs by billing plan; the actual project billing status is unverified. Do not send sensitive information to this route unless the applicable plan/terms have been checked. |
| Northwest Registered Agent / CorpTools | Current | Business formation and related corporate-tools workflows. | Customer-provided business and relevant owner/member formation information, filing status, and related workflow details. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Formation provider capability. Information may also be submitted to a government filing office. Submission and agency acceptance are separate outcomes. |
| PostgreSQL | Current | Application database and workspace state. | Account/workspace records, connected-account details, service activity, and information customers submit. | Database host and region are unverified. | Current application data store. |
| Postmark | Current | Transactional and invitation email delivery. | Recipient address, message content, delivery state, and necessary request metadata. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Current configured transactional-email provider. Resend is not listed as a current provider. |
| Replit | Current | Application hosting, runtime, and deployment infrastructure. | Requests, network/security information, and data handled by the hosted application. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Current hosting path. Replit's optional, cookieless published-traffic analytics are separate and may be enabled by an operator. |
| Replit AI and OpenRouter | Current | Other configurable model routes, including routes to Claude, Grok, and Llama models. | Prompts, model replies, relevant submitted workspace context, and route-specific request metadata. | Endpoint, billing plan, selected underlying provider, and provider region depend on the configured route. | A model's family/name does not alone identify the processing entity, endpoint, or applicable plan. Free and paid route terms can differ. |
| Replit Object Storage and Google Cloud Storage SDK | Current | Object/file storage. | Selected uploaded or generated files and associated object metadata. | Storage vendor and region are not established by SDK usage. Confirm the actual service and region from deployment records. | Replit Object Storage is used through a Google Cloud Storage SDK. SDK identity is not evidence of a Google Cloud customer account, region, or contract. |
| Stripe | Current | Axiom Helm subscription billing and payment processing. | Billing contact, subscription identifiers/status, and limited card metadata from Stripe. The app does not display full card numbers or CVCs. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Current subscription billing provider. |
| 1Password, Bitwarden, Keeper, Vault, AWS Secrets Manager, Doppler, and Infisical | Optional / gated | Server-side secrets-vault adapters. | Only a selected secret field and related connection information when that particular adapter is configured. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Adapters do not prove a customer connection. Retrieved secret fields are server-side and are not sent to language-model prompts. |
| Ayrshare | Optional / gated | Supported social publishing to X, LinkedIn, Meta, and TikTok. | The selected social account connection, content, and publishing outcome for the requested operation. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Optional publishing path. Not all destinations are connected; a supported path does not establish an actual account connection. |
| Browserbase | Optional / gated | Remote-browser sessions. | Task instructions, browser session state, and page information required for the session. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Configured browser sessions with applicable policy and human review. |
| ElevenLabs | Optional / gated | Operator-initiated voice transcription and speech synthesis. | The audio turn for transcription and the agent's reply text for speech synthesis. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Voice feature; not automatically loaded on the public site. |
| GitHub | Optional / gated | Customer-authorized repository and pull-request workflows. | Repository identifiers, source files or diffs selected for the task, and pull-request/review metadata needed for the requested operation. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Requires a specific repository/account grant and action. Code availability or a repository adapter is not an active customer connection. |
| Google applications and APIs | Optional / gated | Separately authorized Gmail, Calendar, Drive, Analytics, Search Console, Business Profile, and Ads features; sign-in profile data is separate. | The connected account/profile and data within the specific permission, selected resource, and task. | Google account, API feature, billing plan, and processing location vary and have not been verified for every connected account. | Native integrations and connected apps exist. Sign-in with Google alone does not authorize every listed product or imply that a specific account is connected. |
| Keenable, SerpAPI, Semrush, DataForSEO, and Apify | Optional / gated | Web search/research, search-result, SEO, visibility, and supported actor tasks. | The query, public URL, domain, location, or task input needed for the particular research operation. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Research adapters/capabilities; request-specific use depends on available configuration and selected task. |
| Microsoft Graph | Optional / gated | Authorized Outlook/Microsoft email, calendar, and related account workflows. | Mailbox, calendar, or profile information covered by the specific permission and selected task. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Requires a separate Microsoft account authorization. |
| Pipedream connected applications | Optional / gated | User-authorized third-party workflow connections, including supported Slack, HubSpot, and Notion app workflows. | Connection metadata and the specific task payload sent to or received from the connected application. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Each connection is optional and must be configured and authorized. A listed app, provider adapter, or available secret does not mean a customer's account is connected. |
| PostHog | Optional / gated | Optional product analytics. | Analytics events and browser identifiers/storage after a user explicitly allows optional analytics. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Off until the user allows it in cookie preferences; a decline disables it and clears PostHog identifier cookies/local storage in that browser. |
| QuickBooks, Xero, Plaid, FreshBooks, and Mercury | Optional / gated | Partner-gated finance integrations. | Connection details and financial account or transaction data required by the specific authorized workflow. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Partner and customer authorization required. Adapter presence is not an active customer connection. |
| Snitcher | Optional / gated | Business identification on eligible public marketing and authentication pages. | Eligible public-page URL, title, referrer, and network IP used to estimate the associated company, not to identify an individual. After an eligible, voluntary public form/sign-up event, allow-listed identity fields may be sent when the required notices and consent are active. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Requires explicit analytics permission plus the current, versioned Snitcher notice. Credentials and private app routes are excluded. DNT is a strict opt-out. GPC defaults optional processing off, but the public-root flow preserves an explicit current acceptance; the separate customer-tag roadmap is not mounted. |
| Stripe Connect and customer Stripe accounts | Optional / gated | Customer-authorized payment workflows. | Account/transaction identifiers and payment/invoice details needed for a selected authorized workflow. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Partner/customer-account and task dependent; a capability does not prove an account is connected. |
| Twilio and mobile carriers | Optional / gated | Text ATLAS phone verification and SMS routing/delivery. | Mobile number, message text, consent/STOP state, and message-routing/delivery metadata. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Requires configured phone/SMS service. Mobile information is not shared for third-party or affiliate marketing; text opt-in data/consent is not shared with third parties. |
| Vercel Sandbox | Optional / gated | Sandbox task execution. | Task inputs and temporary environment content required for that sandbox run. | The sandbox is configured for iad1. That specific configuration is not a general provider/account region guarantee. | Sandbox capability, not customer-site hosting. |
| WordPress, Webflow, and Wix | Optional / gated | Authorized website CMS content and publishing actions. | Selected site, page/draft content, connection metadata, and action outcome. | Provider, endpoint, deployment, and support regions have not been verified from the available configuration and contract records. | Requires the customer's separate site account, supported connection, and applicable approval. |
| Cloudflare for SaaS and Vercel customer-site hosting | Planned only | Possible future customer-site hosting and custom-domain features. | If released: website content, domain configuration, and relevant routing/request information. | 25A is unfinished and the hosting adapters are not mounted. No region or current processing is claimed for them. | Planned/enablement-dependent 25A only; current Cloudflare DNS does not make Cloudflare for SaaS or Vercel site hosting live. |
| Higgsfield, Runway, and Google Veo | Planned only | Potential future advertising-creative/video generation. | If released: prompts, selected creative inputs, generated output, and task metadata. | No such feature is enabled; provider and region would be confirmed before release. | Unstarted 25E roadmap. Keys or builder tools do not establish a current customer-facing connection. |
| TikTok Ads, LinkedIn Ads, X Ads, Meta Pixel/Conversions API, and Google Marketing tags | Planned only | Potential future paid campaign management and website tracking/conversion features. | If released: advertising account identifiers, campaign and audience data, creative, and browser events. | The 25A-25F features are unfinished; provider/region/contract details must be confirmed before any activation. | Unstarted roadmap, including an unmounted 25A tag. Distinct from optional Ayrshare social publishing and separately gated Google Ads application capabilities. |
Planned-provider change notice
Before a planned provider is activated for customer data, Mahlum must verify the selected provider, purpose, data categories, region/transfer basis, applicable terms, and connection controls and update this register. 25A through 25F are not represented here as completed releases. We have no general production customer-site tag, Meta Pixel, conversion API, LinkedIn Ads, TikTok Ads, or X Ads installation from those unfinished roadmap items.
Subprocessor change questions
Questions or a reasoned objection: privacy@axiomhelm.com. Workspace owners/admins may enable optional notice emails in authenticated privacy settings. An optional email setting cannot suppress required service, billing, security, legal, or deletion notices.
Changelog
October 1, 2026: Initial register from repository, runtime/provider, and enabled-feature audit. Separates current, optional, and planned paths.