Last updated: 28 August 2026
This page lists the sub-processors Syntrum engages to process customer data, as described in our Privacy Policy and Data Processing Addendum. A sub-processor is a third party that processes personal data on our behalf in order to deliver the Services.
We review each sub-processor before engaging them and require contractual commitments consistent with our obligations to you.
Current sub-processors
| Name | Purpose | Data processed | Location |
|---|---|---|---|
| Cloudflare (cloudflare.com) | CDN and reverse proxy fronting the application and API | Request and response traffic in transit, source IP addresses | USA |
| Composio (composio.dev) | Integration and authentication infrastructure for connected tools | Authorisation credentials for your connected accounts; message and record content passing to and from those tools | USA |
| Contabo (contabo.com) | Cloud hosting, compute, and storage | All customer data at rest and in processing | United Kingdom |
| Google (google.com) | Identity provider for Sign in with Google; advertising conversion measurement and remarketing on our public website | Email address, verified-email flag, account identifier; for advertising, a cookieless measurement signal from every website visitor, and website interaction data with advertising identifiers from visitors who accept cookies | USA |
| OpenRouter (openrouter.ai) | AI model routing and inference | Prompts and task context, which may include message bodies, contact details, agent memory, and task content | USA |
| PostHog (posthog.com) | Product analytics and error tracking | User and workspace identifiers, product events, exception data | USA |
| Stripe (stripe.com) | Payment processing and subscription billing | Name, email, billing address, subscription and transaction history | USA |
Payment card details are never processed by Syntrum. Payment is handled through Stripe's hosted checkout, so cardholder data passes directly to Stripe and we retain only customer and subscription identifiers.
Model inference
All platform inference is routed through OpenRouter, which forwards each request to a downstream inference operator. We configure routing so that requests are served only by operators that do not retain prompts or use them to train models, and we restrict routing to a defined set of operators rather than allowing dynamic selection across the full network.
Conditional sub-processors
The following are engaged only where a customer chooses to use them. They do not process data for customers who have not made that election.
| Name | Purpose | When engaged | Location |
|---|---|---|---|
| OpenAI (openai.com) | AI model inference | Only where the customer supplies their own OpenAI API key | USA |
| Anthropic (anthropic.com) | AI model inference | Only where the customer supplies their own Anthropic API key | USA |
Where a customer supplies their own API key, inference runs against that customer's own account with the provider, under the customer's own agreement with that provider. Syntrum does not hold a contractual relationship with the provider in respect of that processing.
Customer-supplied keys are held encrypted on Syntrum infrastructure. No third-party credential custodian is involved, and keys are not retrievable in readable form after submission.
If a customer-supplied key fails, expires, or exhausts its quota, inference does not proceed on that key. Workspaces may be configured either to stop and notify the workspace owner, or to continue using Syntrum's platform models via the routing described above. Where the second option is selected, the workspace owner is notified.
Infrastructure operated by Syntrum
The following components run on Syntrum's own infrastructure and are not third-party sub-processors. Data held in them sits with our hosting provider and no other party.
| Component | Purpose |
|---|---|
| PostgreSQL with pgvector | Primary database, vector search and retrieval |
| Redis | Queuing and caching |
| LiteLLM | Custody of customer-supplied API keys |
Changes to this list
We may add or replace sub-processors as the Services develop. To be notified in advance of changes, email contact@syntrum.io with the subject "Subprocessor notifications" and we will add you to the notification list.
Customers with a Data Processing Addendum in place may object to a new sub-processor on reasonable data protection grounds, in accordance with that agreement.
Questions about this page: contact@syntrum.io

