Subprocessors

Last updated: August 10, 2026

HelmIQ uses the third-party providers below to deliver the service. We notify firm owners before a new subprocessor begins handling customer data, and we publish it here at the same time. Customers on a Data Processing Agreement may object to a new subprocessor on data-protection grounds; see the DPA for how that works.

List version v2026.08

SubprocessorPurposeRegionData classes
NeonManaged Postgres: primary application databaseAWS us-east (default)restricted, confidential, internal
VercelApplication hosting: compute, edge, buildGlobal edge; primary USrestricted, confidential, internal, public
ConcentrateAI gateway: single entry point for all model inference; routes to downstream providers under enforced Zero Data Retention; native web searchUSrestricted, confidential
AnthropicAI inference: Claude models, accessed via the Concentrate gateway under ZDR (not Anthropic-direct)USrestricted, confidential
OpenAIAI inference: gpt-4o-mini via the Concentrate gateway under ZDR; plus Whisper audio transcription (no-retention endpoint, OpenAI-direct)USrestricted, confidential
TwilioVoice + SMS: call recording, dial-out, transcription pipeline triggerUSrestricted
Google Workspace (Gmail + Calendar OAuth)Customer-authorized OAuth grants; we read on behalf of customer; we do not host customer Gmail dataCustomer's Google regionrestricted, confidential
Microsoft 365 (Outlook + Calendar + OneDrive/Teams OAuth)Customer-authorized OAuth grants; we read and act on behalf of the customer; we do not host customer mailbox dataCustomer's Microsoft regionrestricted, confidential
ZoomVideo meeting provider used to create user-authorized meeting links for scheduled meetings and calendar invites; identifies the authorized Zoom user. No access to recordings, transcripts, or chat.Customer's Zoom regionconfidential
ResendTransactional + platform email delivery (system notifications, booking and reminder fallback) when a firm has no own mailbox connectedUSconfidential, internal
Cloudflare R2Object storage for uploaded documents and call recordings (encrypted at rest), when configuredUS / auto (Cloudflare)restricted, confidential
StripeBilling: payment processing for Helm subscriptionUSinternal
SentryError monitoring, performance tracing, and session replay (server, edge, and browser); captures exception context, request metadata, and user identifiers to diagnose failures. Session replay records a masked reconstruction of a sampled share of browser sessions: text, form inputs, and media are masked at capture, so a replay shows layout and interaction rather than readable customer contentUSrestricted, confidential, internal
GranolaMeeting-notes provider: when a firm connects Granola, we read meeting notes and transcripts on the firm's behalf to generate briefs, notes, and tasksUSrestricted, confidential
HunterEmail finding: when sourcing or contact enrichment is used, we send a contact name and company domain to retrieve a likely business email addressEUconfidential
IgnitePostPhysical mail (default provider): when a firm sends a handwritten-style letter, we send the recipient name and mailing address to print and post itUSconfidential
PostGridPhysical mail (alternate provider): when selected, we send the recipient name and mailing address to print and post a letterUS / Canadaconfidential
HandwryttenPhysical mail (alternate provider): when selected, we send the recipient name and mailing address to write and post a cardUSconfidential
DocuSignE-signature: when a firm connects DocuSign, we send document and signer details to send agreements for signature (available only when the DocuSign integration is enabled)USrestricted, confidential
SlackNotifications: when a firm connects Slack, we send deal and task notification content to the firm's chosen Slack workspaceUSconfidential, internal
Google Maps Platform (Places)Geocoding: company and address lookups send business names and addresses to Google to normalize and geocode them; distinct from the Google Workspace OAuth grant aboveGlobal (Google)internal, public

Notifications and questions

To be notified of changes to this list, or to request our full vendor diligence bundle (including subprocessor DPA and SOC 2 status), contact jack@helmiq.net. The full security posture, including framework mappings, is on our Security & Trust Center.