To provide Korium, Kyroco engages a small number of third-party service providers (“subprocessors”) that may process personal information on our behalf. This page lists our current subprocessors, what they do, where they are located, and the safeguard we rely on for any transfer of personal data outside the EEA, UK, or Switzerland. It is referenced by, and forms part of, our Data Processing Addendum.
The subprocessors below fall into two groups: those that may handle Customer Content (the data you store in your Korium memory, which we process as your processor) and those that handle account, billing, or operational data that Kyroco controls. Because Korium runs on a US-based cloud region by default, most subprocessors are in the United States; each US transfer is covered by an appropriate safeguard, shown in the Transfer safeguard column.
What does not appear here on purpose: Korium performs both entity extraction (a GLiNER model) and vector embedding (a self-hosted Ollama model) using models that run inside our own AWS environment - your content is not sent to any third-party provider for extraction or embedding. The only external AI service is the managed model used for higher-level memory cognition, listed below, which is contractually prohibited from training on your content.
These providers form the infrastructure and AI layer that stores and processes the data you place in Korium.
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services, Inc.AWS | Cloud infrastructure and hosting: compute, managed database (memory storage), object storage, cache, key management, and secrets. | United States (us-east-1) | EU-US DPF + SCCs |
| Amazon Web Services, Inc.Amazon Bedrock | Managed large-language-model inference used for higher-level memory cognition (e.g. the cognitive sort pass). Prompts are not used to train foundation models. | United States | EU-US DPF + SCCs |
These providers support authentication, payments, delivery, and operating the Service.
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Stripe, Inc.Payments | Payment processing, subscription billing, hosted checkout, and the customer billing portal. Kyroco does not store full card numbers. | United States | EU-US DPF + SCCs |
| Cloudflare, Inc.Network | DNS, content delivery, TLS termination, and network security (including the Zero Trust access tunnel). | United States / global edge | EU-US DPF + SCCs |
| Google LLCGoogle Workspace | Transactional and business email delivery (e.g. sign-in, account, and support messages). | United States | EU-US DPF + SCCs |
When you choose to sign in with a third-party identity provider, that provider processes your login on your instruction. These are not subprocessors of your Customer Content; they authenticate access and return an identifier to us.
We keep this page current. Before we add a new subprocessor or replace an existing one that processes personal data, we will give affected customers advance notice of at least thirty (30) days through the mechanism described in our Data Processing Addendum, during which a customer may object on reasonable data-protection grounds. To receive change notifications, contact us at reports@kyroco.ai and ask to be added to the subprocessor-update list.
Each subprocessor is bound by a written agreement imposing data-protection obligations no less protective than those in our own Data Processing Addendum, including the EU Standard Contractual Clauses where required for international transfers. Kyroco remains responsible to its customers for the performance of its subprocessors.