Service Provider Inventory

A technical inventory of third parties documented in Praesidia's current production path and platform integrations.

Technical inventory last verified: September 2026. This page reports the service-provider data path supported by the repository's deployment policy, runbooks, and runtime integrations. It is not a contractual subprocessor schedule and, beyond the production hosting region, does not assert provider regions, transfer mechanisms, change-notice periods, or negotiated legal roles. Request reviewed contractual information from legal@praesidia.ai.

Provider Documented technical role Data that may pass through the service
Amazon Web Services (AWS) Current production application hosting for Praesidia's public app, API, and MCP services in the eu-west-1 (Ireland) region, plus key management, object storage, and message queuing where those features are configured Account and platform data handled by those services, including request and response content; key and encryption metadata, stored objects or audit anchors, and queued service payloads for enabled integrations
Cloudflare Edge proxy and TLS termination at Cloudflare's global edge, in front of the AWS production services Requests and responses sent to public endpoints, plus connection and request metadata
Stripe Payment processing, invoicing, and subscription billing Billing contact, transaction, and payment-method data
Mailgun (Sinch) Transactional delivery of account, security, and product email Recipient name and email address, plus transactional message content
Sentry (when configured) Application error monitoring and crash diagnostics Technical error and request diagnostics, which may include limited account identifiers
Sigstore Rekor (when external anchoring is enabled) Public transparency-log anchoring for audit-integrity proofs Cryptographic hash commitments, not the underlying audit records
OpenAI (platform-configured connection) Model inference when an organization uses the platform's configured default instead of its own provider connection Prompt and response content for those model requests

Current hosting boundary

AWS in the eu-west-1 (Ireland) region, behind Cloudflare, is the current live production host for Praesidia's public app, API, and MCP services, and is where customer data is processed today. Cloudflare terminates TLS at its global edge before requests reach AWS, so this inventory does not describe an EU-only data path.

Customer-configured model connections

An organization can configure its own provider connection, including OpenAI, Anthropic, Google Gemini, Mistral AI, Cohere, DeepSeek, Qwen, Moonshot, a self-hosted endpoint such as Ollama, or any OpenAI-compatible API. Praesidia routes model requests only to the connection selected for that organization. The contractual role of a customer-selected provider depends on the applicable account and agreement and is therefore not assigned by this technical inventory.

Questions

For technical privacy questions, email privacy@praesidia.ai. For questions about the availability of a reviewed DPA or contractual provider schedule, email legal@praesidia.ai.