Subprocessors
Last Updated: September 2, 2026
turbopuffer engages the following vendors to process customer data in the course of providing the service. See our Security & Compliance page for the controls that govern this processing and our DPA for contractual commitments.
| Subprocessor | Purpose of Processing | Data Categories | Processing Location |
|---|---|---|---|
Amazon Web Services (AWS) | Compute and storage, embedding inference | Customer data | Customer-selected region |
Baseten | Embedding inference | Customer data | Colocated with customer-selected region |
Datadog | Observability and monitoring | Usage data, service data | United States |
Fireworks AI | Embedding inference | Customer data | Colocated with customer-selected region |
Google LLC (GCP) | Compute and storage, embedding inference | Customer data | Customer-selected region |
Incident.io | Production monitoring and alerting | Usage data, service data | United States |
OpenAI | Embedding inference | Customer data | United States |
Orb | Billing and invoicing | Usage data, billing details | United States |
PlanetScale | Dashboard database hosting | Usage data, service data, account details (e.g., email addresses) | United States |
Polar Signals | CPU and memory performance profiling | Usage data, service data | United States |
Pylon | Customer support | Support communications, contact IDs, and any data provided in tickets | United States |
Resend | Customer notifications | Email addresses and notification content | United States |
Stripe | Payment processing | Billing contact and payment details | United States |
Teleport | Privileged access management | Operator access records, customer data reachable in-session | United States |
Vercel | Website and dashboard hosting | Usage data, service data, account details | United States |
Voyage AI (MongoDB) | Embedding inference | Customer data | United States |
WorkOS | Dashboard authentication | Login email addresses and authentication details | United States |
Scope of processing
turbopuffer hosts customer data in the cloud region a customer selects when creating a namespace. AWS and GCP provide compute and storage only for namespaces deployed in that provider's regions. For example, a customer whose namespaces are all in GCP regions engages only GCP for compute and storage.
Embedding inference providers are engaged only if the customer enables native embedding, an opt-in feature, and configures an embedding model hosted by that provider.
Subprocessors for purposes other than compute and storage and embedding inference support the turbopuffer platform across all hosted deployments, regardless of the cloud regions or features a customer uses. They process service data (customer-supplied identifiers such as namespace and attribute names) and usage data. They do not receive customer content stored in turbopuffer, except where the customer consents (data shared in support tickets, approved privileged-access sessions).
Deployment model scope
The table above applies to turbopuffer-hosted deployments (multi-tenant and single-tenant). For BYOC deployments, customer contracts directly with its cloud provider, and that provider is not a turbopuffer subprocessor.