Sub-processors
Version: v1.0 β 2026-07-23
Effective date: 2026-07-23
Some vendors below are optional or "when configured" integrations
rather than active on every deployment; those rows are marked
(optional / when configured). We list them for transparency even
where they are not engaged by default.
Vestibo ("Vestibo") uses a small set of
sub-processors to provide the Service. This page is the
authoritative list. Customers can subscribe to change notifications by
emailing privacy@vestibo.com; we will give at least thirty (30)
days' notice before adding or replacing a sub-processor, as set out
in Β§ 6 of the DPA.
This list is reviewed and republished at least quarterly.
1. Infrastructure
| Vendor | Purpose | Data processed | Region | DPA / BAA / DPF |
|---|
| Amazon Web Services, Inc. (AWS) | Compute, application load balancer (edge / TLS termination), Route 53 (DNS), managed database (RDS Postgres), managed cache (ElastiCache Redis), KMS, CloudWatch, and Amazon SES (transactional email). Object storage (S3) is not currently in use; no Customer Data is stored in S3 today. | Account data and conversation data (transcripts, records) in the managed database; email content via SES. | us-east-1 | AWS DPA + SCCs, BAA (HIPAA tier), DPF certified. |
| Sentry (Functional Software, Inc.) | Application error monitoring. | Stack traces, request IDs, optionally tenant IDs (no Customer-Content). | US (data-residency add-on available for EU). | Sentry DPA + SCCs. |
2. Large Language Model (LLM) providers
| Vendor | Purpose | Data processed | Region | DPA / BAA / training opt-out |
|---|
| Anthropic, PBC | Text generation (Claude-class) β Vestibo's default model provider, used directly and, on some deployments, via AWS Bedrock. | Prompt + completion content (which may include conversation excerpts). | US. | Anthropic DPA, training-on-customer-data disabled. |
| OpenAI, LLC (optional / when configured) | Text generation, where a tenant enables it. Also embeddings for semantic knowledge search β but only where a deployment explicitly opts in to the hosted embeddings path; by default semantic search either runs on our own self-hosted embeddings server or stays inert (keyword-only), and no knowledge content is sent to OpenAI. | Prompt + completion content (which may include conversation excerpts); knowledge-base text where hosted embeddings are opted in. | US. | OpenAI DPA, BAA (HIPAA tier; via OpenAI's Enterprise plan), zero-data-retention available for eligible endpoints β training-on-customer-data is disabled. |
| (Optional, configurable per tenant) Other LLM providers as the customer enables them in their Model Router. | per-vendor. | per-vendor. | per-vendor. | per-vendor β Vestibo ships only providers with a training opt-out. |
3. Voice (STT + TTS)
On the default telephony path, speech recognition is provided by
Twilio (see Β§ 4 β the active voice sub-processor by default). When
the self-hosted voice runtime is enabled, speech-to-text and
text-to-speech run on Vestibo's own infrastructure with no third-party
voice sub-processor. The vendors below are optional and engaged
only where a deployment explicitly configures them.
| Vendor | Purpose | Data processed | Region | DPA / BAA |
|---|
| Deepgram, Inc. (optional / when configured) | Speech-to-text. | Voice audio, transcript. | US (residency options available). | Deepgram DPA, BAA (HIPAA tier). |
| ElevenLabs, Inc. (optional / when configured) | Text-to-speech. | Generated audio + synthesis text. | US. | ElevenLabs DPA; not used on the HIPAA path (no PHI). |
| OpenAI, LLC (optional / when configured) | Optional TTS and optional Realtime API for low-latency voice. | Voice audio + transcript. | US. | See Β§ 2. |
4. Telephony and messaging
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Twilio Inc. | Voice trunking, SMS + WhatsApp in/out, phone-number provisioning. | Caller ID, phone numbers, call/SMS/WhatsApp content. | US (data-residency options available). | Twilio DPA + SCCs. |
5. Email
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Amazon SES (via AWS) | Transactional email (account, magic link, billing, agent-sent email). | Email addresses, message content. | Same as AWS row. | AWS DPA. |
| (Optional) Customer-supplied SMTP provider | Outbound email when the customer connects their own provider. | Email addresses, message content. | per-vendor. | Customer-owned. |
6. Integrations you connect (calendaring, CRM, messaging)
These are engaged only when a tenant chooses to connect them.
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Google LLC | Google sign-in, Google Calendar booking, and (optional) Gmail triage. | Profile email, calendar events, email content where Gmail is connected, OAuth tokens (encrypted at rest). | US / EU. | Google Cloud DPA. |
| Acuity Scheduling, Inc. (optional / when connected) | Acuity OAuth for booking appointments. | Booking records, OAuth tokens. | US. | Acuity DPA. |
| HubSpot, Inc. / Salesforce, Inc. (optional / when connected) | CRM sync where a tenant connects one. | Contact records, OAuth tokens (encrypted at rest). | US / EU. | per-vendor DPA. |
| Telegram FZ-LLC (optional / when configured) | Optional messaging channel. | Message content, chat/user IDs. | Global. | per-vendor terms. |
7. Documents and signatures
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| DocuSign / HelloSign (planned / when enabled) | E-signature for the Clinic/HIPAA BAA and DPA. Not yet engaged β no signer data flows today. | Signer name, email, IP (once enabled). | US / EU. | per-vendor DPA. |
8. Payments
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Stripe, Inc. | Subscription billing for your Vestibo plan, and β where enabled β Stripe Connect (Express) so a business can collect payments from its own customers via Stripe-hosted links. Stripe Connect is built but off by default, enabled per tenant via a feature flag. | Cardholder data (tokenised β Vestibo never sees raw card numbers), billing address, last-4. | US / EU. | Stripe DPA, PCI DSS Level 1. |
9. Customer support
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| None today | Support runs over email (support@vestibo.com) through our own email infrastructure; we do not use a third-party ticketing vendor. If we adopt one we will list it here and give the notice required by Β§ 6 of the DPA. | β | β | β |
10. Sub-processors no longer in use
| Vendor | Purpose | End date |
|---|
| (none) | | |
Change history
- 2026-07-23 β v1.0 β first published version; rebranded to Vestibo and refreshed to match the current stack (Anthropic as default LLM, Stripe Connect built but off by default, no S3 in use yet, added CRM/messaging integrations, and the opt-in-only hosted-embeddings path for semantic knowledge search).
- 2026-05-16 β v0.1 β initial internal draft.
How to subscribe to changes: email privacy@vestibo.com.