Subprocessors
Last Updated: August 5, 2026
turbopuffer engages the following vendors to process customer data in the course of providing the service. See our Security & Compliance page for the controls that govern this processing and our DPA for contractual commitments.
Infrastructure subprocessors
turbopuffer hosts customer data in the cloud region a customer selects when creating a namespace. The following subprocessors are engaged only for namespaces deployed in that provider's regions. A customer whose namespaces are all in GCP regions engages only GCP, and vice versa.
| Subprocessor | Purpose of Processing | Data Categories | Processing Location |
|---|---|---|---|
Amazon Web Services (AWS) | Compute and storage | Customer data | Customer-selected region |
Google LLC (GCP) | Compute and storage | Customer data | Customer-selected region |
Platform subprocessors
The following subprocessors support the turbopuffer platform across all hosted deployments, regardless of the cloud region a customer selects. They process service data (customer-supplied identifiers such as namespace and attribute names) and usage data. They do not receive customer content stored in turbopuffer, except where the customer consents (data shared in support tickets, approved privileged-access sessions).
| Subprocessor | Purpose of Processing | Data Categories | Processing Location |
|---|---|---|---|
Datadog | Observability and monitoring | Usage data, service data | United States |
Incident.io | Production monitoring and alerting | Usage data, service data | United States |
Orb | Billing and invoicing | Usage data, billing details | United States |
PlanetScale | Dashboard database hosting | Usage data, service data, account details (e.g., email addresses) | United States |
Polar Signals | CPU and memory performance profiling | Usage data, service data | United States |
Pylon | Customer support | Support communications, contact IDs, and any data provided in tickets | United States |
Resend | Customer notifications | Email addresses and notification content | United States |
Stripe* | Payment processing | Billing contact and payment details | United States |
Teleport | Privileged access management | Operator access records, customer data reachable in-session | United States |
Vercel | Website and dashboard hosting | Usage data, service data, account details | United States |
WorkOS | Dashboard authentication | Login email addresses and authentication details | United States |
* Stripe acts as a processor for the billing we direct, and as an independent controller for the payment processing and compliance obligations it carries out under its own legal duties.
Optional feature subprocessors
Customer content is sent to the following subprocessors only if the customer enables native embedding, an opt-in feature, and configures an embedding model hosted by that provider.
| Subprocessor | Purpose of Processing | Data Categories | Processing Location |
|---|---|---|---|
Baseten | Compute | Customer data | Colocated with customer selected region |
Cohere | Compute | Customer data | United States |
Fireworks AI | Compute | Customer data | Colocated with customer selected region |
Voyage AI (MongoDB) | Compute | Customer data | United States |
Deployment model scope
The tables above apply to turbopuffer-hosted deployments (multi-tenant and single-tenant). For BYOC deployments, customer contracts directly with its cloud provider, and that provider is not a turbopuffer subprocessor.