# Subprocessors

**Last Updated**: August 5, 2026

turbopuffer engages the following vendors to process customer data in the course
of providing the service. See our [Security & Compliance](/docs/security) page
for the controls that govern this processing and our [DPA](/dpa) for contractual
commitments.

## Infrastructure subprocessors

turbopuffer hosts customer data in the cloud region a customer selects when
creating a namespace. The following subprocessors are engaged only for
namespaces deployed in that provider's regions. A customer whose namespaces are
all in GCP regions engages only GCP, and vice versa.

| Subprocessor                  | Purpose of Processing | Data Categories | Processing Location      |
| ----------------------------- | --------------------- | --------------- | ------------------------ |
| **Amazon Web Services** (AWS) | Compute and storage   | Customer data   | Customer-selected region |
| **Google LLC** (GCP)          | Compute and storage   | Customer data   | Customer-selected region |

## Platform subprocessors

The following subprocessors support the turbopuffer platform across all hosted
deployments, regardless of the cloud region a customer selects. They process
service data (customer-supplied identifiers such as namespace and attribute
names) and usage data. They do not receive customer content stored in
turbopuffer, except where the customer consents (data shared in support tickets,
approved privileged-access sessions).

| Subprocessor      | Purpose of Processing                | Data Categories                                                       | Processing Location |
| ----------------- | ------------------------------------ | --------------------------------------------------------------------- | ------------------- |
| **Datadog**       | Observability and monitoring         | Usage data, service data                                              | United States       |
| **Incident.io**   | Production monitoring and alerting   | Usage data, service data                                              | United States       |
| **Orb**           | Billing and invoicing                | Usage data, billing details                                           | United States       |
| **PlanetScale**   | Dashboard database hosting           | Usage data, service data, account details (e.g., email addresses)     | United States       |
| **Polar Signals** | CPU and memory performance profiling | Usage data, service data                                              | United States       |
| **Pylon**         | Customer support                     | Support communications, contact IDs, and any data provided in tickets | United States       |
| **Resend**        | Customer notifications               | Email addresses and notification content                              | United States       |
| **Stripe**\*      | Payment processing                   | Billing contact and payment details                                   | United States       |
| **Teleport**      | Privileged access management         | Operator access records, customer data reachable in-session           | United States       |
| **Vercel**        | Website and dashboard hosting        | Usage data, service data, account details                             | United States       |
| **WorkOS**        | Dashboard authentication             | Login email addresses and authentication details                      | United States       |

\* Stripe acts as a processor for the billing we direct, and as an independent
controller for the payment processing and compliance obligations it carries out
under its own legal duties.

## Optional feature subprocessors

Customer content is sent to the following subprocessors only if the customer
enables [native embedding](/docs/embedding), an opt-in feature, and configures
an embedding model hosted by that provider.

| Subprocessor            | Purpose of Processing | Data Categories | Processing Location                     |
| ----------------------- | --------------------- | --------------- | --------------------------------------- |
| **Baseten**             | Compute               | Customer data   | Colocated with customer selected region |
| **Cohere**              | Compute               | Customer data   | United States                           |
| **Fireworks AI**        | Compute               | Customer data   | Colocated with customer selected region |
| **Voyage AI (MongoDB)** | Compute               | Customer data   | United States                           |

## Deployment model scope

The tables above apply to turbopuffer-hosted deployments (multi-tenant and
single-tenant). For [BYOC](/docs/byoc) deployments, customer contracts directly
with its cloud provider, and that provider is not a turbopuffer subprocessor.

  Subscribe to subprocessor update notifications for when we engage new
  subprocessors.


---

This page: [/docs/security/subprocessors.md](https://turbopuffer.com/docs/security/subprocessors.md)

All documentation pages: [/llms.txt](https://turbopuffer.com/llms.txt)

All documentation in one file: [/llms-full.txt](https://turbopuffer.com/llms-full.txt)
