Subprocessors

Last Updated: September 2, 2026

turbopuffer engages the following vendors to process customer data in the course of providing the service. See our Security & Compliance page for the controls that govern this processing and our DPA for contractual commitments.

SubprocessorPurpose of ProcessingData CategoriesProcessing Location
Amazon Web Services (AWS)
Compute and storage, embedding inference
Customer data
Customer-selected region
Baseten
Embedding inference
Customer data
Colocated with customer-selected region
Datadog
Observability and monitoring
Usage data, service data
United States
Fireworks AI
Embedding inference
Customer data
Colocated with customer-selected region
Google LLC (GCP)
Compute and storage, embedding inference
Customer data
Customer-selected region
Incident.io
Production monitoring and alerting
Usage data, service data
United States
OpenAI
Embedding inference
Customer data
United States
Orb
Billing and invoicing
Usage data, billing details
United States
PlanetScale
Dashboard database hosting
Usage data, service data, account details (e.g., email addresses)
United States
Polar Signals
CPU and memory performance profiling
Usage data, service data
United States
Pylon
Customer support
Support communications, contact IDs, and any data provided in tickets
United States
Resend
Customer notifications
Email addresses and notification content
United States
Stripe
Payment processing
Billing contact and payment details
United States
Teleport
Privileged access management
Operator access records, customer data reachable in-session
United States
Vercel
Website and dashboard hosting
Usage data, service data, account details
United States
Voyage AI (MongoDB)
Embedding inference
Customer data
United States
WorkOS
Dashboard authentication
Login email addresses and authentication details
United States

Scope of processing

turbopuffer hosts customer data in the cloud region a customer selects when creating a namespace. AWS and GCP provide compute and storage only for namespaces deployed in that provider's regions. For example, a customer whose namespaces are all in GCP regions engages only GCP for compute and storage.

Embedding inference providers are engaged only if the customer enables native embedding, an opt-in feature, and configures an embedding model hosted by that provider.

Subprocessors for purposes other than compute and storage and embedding inference support the turbopuffer platform across all hosted deployments, regardless of the cloud regions or features a customer uses. They process service data (customer-supplied identifiers such as namespace and attribute names) and usage data. They do not receive customer content stored in turbopuffer, except where the customer consents (data shared in support tickets, approved privileged-access sessions).

Deployment model scope

The table above applies to turbopuffer-hosted deployments (multi-tenant and single-tenant). For BYOC deployments, customer contracts directly with its cloud provider, and that provider is not a turbopuffer subprocessor.