Disclosure · last updated May 2026
Sub-processors
Third parties that process customer data on behalf of Sovereign Matrix. Required disclosure for GDPR, POPIA, and SOC2 due diligence. We update this page (and notify enterprise customers via the email on file) at least 30 days before any addition or material change.
Infrastructure · 3
- DPA / privacy →
Vercel
Core dependency- Purpose
- Application hosting, edge runtime, CDN
- Data
- Request payloads and IP addresses while routing customer traffic
- Region
- Global edge · primary US-east
- DPA / privacy →
Neon
Core dependency- Purpose
- Managed PostgreSQL — primary data store
- Data
- Tenant data, accounts, packets, audit logs, payments, all tables in src/db/schema.ts
- Region
- AWS us-east-2 (configurable per project)
- DPA / privacy →
Upstash
Optional- Purpose
- Distributed rate limiting (Redis)
- Data
- Rate-limit keys (IP / user-id hashes), no payloads
- Region
- Global
Authentication · 1
- DPA / privacy →
Clerk
Core dependency- Purpose
- Authentication, session management, organization membership
- Data
- Email, name, OAuth profile fields, IP at sign-in, MFA factors
- Region
- AWS us-east-1 with EU residency option
AI model providers · 7
- DPA / privacy →
Anthropic
Optional- Purpose
- Claude model inference (when the routing layer selects it)
- Data
- Prompt + completion text only, retained by Anthropic for 30 days for trust-and-safety review per their policy
- Region
- US
- DPA / privacy →
Google (Gemini)
Optional- Purpose
- Gemini model inference
- Data
- Prompt + completion text
- Region
- US (configurable to EU)
- DPA / privacy →
NVIDIA NIM
Optional- Purpose
- Open-source model inference (default routing)
- Data
- Prompt + completion text
- Region
- US
- DPA / privacy →
Cerebras
Optional- Purpose
- Ultra-fast inference for latency-sensitive runs
- Data
- Prompt + completion text
- Region
- US
- DPA / privacy →
Groq
Optional- Purpose
- Fast-inference fallback
- Data
- Prompt + completion text
- Region
- US
- DPA / privacy →
DeepSeek
Optional- Purpose
- Reasoning model option in the routing layer
- Data
- Prompt + completion text
- Region
- Routed via NIM (US); not direct
- DPA / privacy →
Black Forest Labs (FLUX)
Optional- Purpose
- Image generation in image-gen agent
- Data
- Image prompt text
- Region
- EU
Payments · 4
- DPA / privacy →
Stripe
Core dependency- Purpose
- Card processing, subscription management, invoicing
- Data
- Email, billing address, last 4 of card (we never see full PAN), subscription metadata
- Region
- Global, EU residency available
- DPA / privacy →
PayFast
Optional- Purpose
- ZAR card processing for South African customers
- Data
- Email, billing address, transaction metadata
- Region
- South Africa
- DPA / privacy →
Yoco
Optional- Purpose
- Alternative ZAR processor
- Data
- Email, billing address, transaction metadata
- Region
- South Africa
- DPA / privacy →
Paystack
Optional- Purpose
- African multi-currency processor (NGN, KES, GHS)
- Data
- Email, billing address, transaction metadata
- Region
- Nigeria, Kenya, Ghana, South Africa
Communications · 5
- DPA / privacy →
Resend
Optional- Purpose
- Transactional email (welcome, alerts, packet completion)
- Data
- Recipient email + email body
- Region
- US, EU residency available
- DPA / privacy →
Twilio
Optional- Purpose
- Outbound SMS, voice (when voice agent fires), WhatsApp via Sandbox
- Data
- Recipient phone, message text, call metadata
- Region
- US
- DPA / privacy →
ElevenLabs
Optional- Purpose
- Voice synthesis when voice-agent paths fire
- Data
- Text to be synthesized
- Region
- US
- DPA / privacy →
Telegram
Optional- Purpose
- Operator alerts to commander channel (optional)
- Data
- Operator-set messages, not customer data
- Region
- Global
- DPA / privacy →
HubSpot
Optional- Purpose
- CRM webhook automation — fires only when customer connects HubSpot
- Data
- Deal events the customer sends us
- Region
- US, EU residency available
Research / web data · 2
- DPA / privacy →
Tavily
Optional- Purpose
- Live web search for blog-gen + competitor agents (research_ai)
- Data
- Search query, no customer data
- Region
- US
- DPA / privacy →
Firecrawl
Optional- Purpose
- Web crawling for research-heavy agents (when configured)
- Data
- Target URL only
- Region
- US
Monitoring · 1
- DPA / privacy →
Sentry
Optional- Purpose
- Error tracking, performance monitoring
- Data
- Error stack traces, request metadata. Configured to scrub PII before send.
- Region
- US, EU residency available
Analytics · 1
- DPA / privacy →
Plausible
Optional- Purpose
- Privacy-friendly analytics (no cookies, no fingerprinting)
- Data
- Page-view URL, referrer domain, country (from IP, then discarded)
- Region
- EU (Germany)
What you can opt out of
Sub-processors marked “Optional” can be disabled for your tenant on request. Core dependencies (Vercel, Neon, Clerk, Stripe) cannot — they back the platform's primary functions and disabling them would prevent us from delivering the service.
Email privacy@sovereignmatrix.agency with your tenant ID and the sub-processors you want disabled.
How we notify you of changes
- Adding a sub-processor: we update this page and email enterprise customers at least 30 days before the new processor goes live.
- Removing a sub-processor: we update this page on the day of removal. No advance notice required.
- Material change in scope: treated the same as “adding a sub-processor.”