Ainfera
Subprocessors · current list · updated 2026-05-23

The full list of vendors
we use to operate Ainfera.

Every company we share data with. Changes announced 30 days ahead.

SubprocessorPurposeData sharedRegion
/// infrastructure
Railwayrailway.apphosting · computeRuns the api.ainfera.ai control + data planes. Receives prompts and responses in transit; nothing persisted on Railway disks — durable state lives in Supabase.us-east
Cloudflarecloudflare.comcdn · ddos · wafPublic-facing request metadata for ainfera.ai, api.ainfera.ai, audit.ainfera.ai, mcp.ainfera.ai. No payload inspection.Global
Modalmodal.comgpu compute · classifierRuns the ModernBERT task-type classifier (S1) on CPU/GPU. Receives only the embedding/feature of the prompt, not the prompt text itself.us-east
/// data & secrets
Supabasesupabase.commanaged postgres · authPrimary database — stores tenant + agent records, the AuditChain table, ledger entries, receipts, model catalog, routing-policy rows. Holds prompt/response hashes (not the content) plus inference metadata. Supabase Auth handles dashboard OAuth (GitHub).us-east
Dopplerdoppler.comsecrets managementStores environment secrets (provider API keys, internal signing key) that the API reads at boot. No customer data.Global
/// upstream model providers
Anthropicanthropic.commodel providerPrompts & responses for calls routed to claude-* models. Their privacy policy governs use.US
OpenAIopenai.commodel providerPrompts & responses for calls routed to gpt-* & embeddings-* models.US
Google AI Studioai.google.devmodel providerPrompts & responses for calls routed to gemini-* models via the Google AI Studio (Generative Language) API. Their privacy policy governs use.US · EU · APAC
Mistralmistral.aimodel providerPrompts & responses for calls routed to mistral-* models.EU
xAIx.aimodel providerPrompts & responses for calls routed to grok-* models.US
Togethertogether.aimodel provider · inference hostPrompts & responses for calls routed via Together's OpenAI-compatible API to open-weights models (Llama, Mistral, Qwen, DeepSeek families). Their privacy policy governs use.US
Groqgroq.commodel provider · inference hostPrompts & responses for calls routed via Groq's OpenAI-compatible API to open-weights models served on LPU inference hardware.US
DeepInfradeepinfra.commodel provider · inference hostPrompts & responses for calls routed via DeepInfra's OpenAI-compatible API to open-weights models.US
Fireworksfireworks.aimodel provider · inference hostPrompts & responses for calls routed via Fireworks AI's OpenAI-compatible API to open-weights models.US
Novita.ainovita.aimodel provider · inference hostPrompts & responses for calls routed via Novita.ai's OpenAI-compatible API to open-weights models.APAC
/// payments & billing
Stripestripe.compaymentsAccount billing info, invoice records, tax registration. No inference data.US · EU
/// transactional comms
Resendresend.comemail · transactionalAccount email and transactional notifications (cap alerts, key-rotation reminders, audit-event webhooks). No marketing.us-east · eu-west
/// developer experience
GitHubgithub.comauth · oauthOAuth handshake to read public profile fields (handle, avatar). No repository access requested.US
Discorddiscord.comcommunityPublic community Discord. Only what you choose to share there.US
Vercelvercel.comstatic hosting · edgeMarketing surface delivery (ainfera.ai) and edge routing logs. No inference payloads.Global

Be notified before we add or change a subprocessor.

30 days' notice, by email, every time. No marketing list — just this one feed.

Recent changes

2026-05-23
updated · disclosed full set of upstream model providers (10) to match live routing reality per /v1/providers. Added Together, Groq, DeepInfra, Fireworks, Novita.ai.
2026-05-22
published · initial subprocessor list for the public beta. Future additions or removals will appear here with 30 days' notice.
Canonical machine-readable list: /security/subprocessors.jsonQuestions: privacy@ainfera.ai