Skip to main content

Subprocessors

Effective date: 12 May 2026  ·  Last updated: 12 May 2026 A subprocessor is a third-party vendor Sumvin uses to deliver part of the platform. Each subprocessor on this list has been chosen for a specific function, contracted under a data processing agreement, and reviewed for security posture against the residency requirement that applies to its scope. The list is short by design — Sumvin’s architecture deliberately concentrates customer data in a small number of well-controlled places. This page is the canonical, dated list. Each entry shows the date the vendor was added; material changes (additions, removals, replacements) are recorded here with the date the change took effect and are notified to partners in advance under the partner DPA.

Selection criteria

Every subprocessor on this list satisfies the same baseline:
  • US data processing for customer data. Any vendor that holds or processes customer data — accounts, KYC, transactional history, key material, or operational telemetry derived from them — does so on US infrastructure. Vendors that route only non-customer data (for example, public blockchain RPC calls or short-lived signature-verification nonces) are listed separately under Edge services so the scope is explicit.
  • Independent security attestation appropriate to the function — typically SOC 2 Type II, ISO 27001, or equivalent.
  • Encryption in transit and at rest by default.
  • A signed data processing agreement with Sumvin.
  • A specific, scoped function — Sumvin does not adopt vendors speculatively. Each entry below names the function the vendor performs.

Infrastructure and data hosting

These are the vendors that hold or move customer data on Sumvin’s behalf.

Identity and KYC

Vendors that participate in identity verification and authentication.

Banking, cards, and payments

Vendors that perform regulated activity Sumvin does not perform itself. Card issuing runs on Visa Intelligent Commerce: a user’s verified Sumvin identity is carried onto a Visa card, with card issuing and cardholder-data processing performed by the regulated issuance partner named below. Sumvin does not store card numbers.

Cryptographic key custody

AI and assistive features

Vendors that participate in Sumvin’s AI-powered features (chat, insights, assistive flows). The specific large-language-model inference provider is named in the compliance pack provided under NDA; LLM providers are selected for US-hosted inference and contractual no-train-on-customer-data terms.

Observability and operations

Vendors that receive operational telemetry. Sensitive payloads are redacted before reaching these systems.

Hosting partners for partner-facing surfaces

Edge services (non-customer data)

The vendors below operate globally distributed networks. They are listed separately because their scope is restricted to traffic that does not carry Sumvin customer data — public blockchain RPC payloads, short-lived authentication nonces, and ERC-4337 bundler relay. They do not hold accounts, KYC, transactional records, key material, or any personally identifiable information. Sumvin’s contracts with both vendors include encryption-in-transit requirements and prohibit logging or retention of payload bodies beyond the operational minimum.

Updates to this list

When Sumvin adds, removes, or replaces a subprocessor:
  • This page is updated with the change and the date the change took effect.
  • Partners on a Data Processing Agreement that requires advance notice are notified ahead of the change, in line with the notice period in the DPA.
  • The change is reflected in the next compliance-pack revision provided to partners under NDA.
For the canonical list under your specific DPA, or to receive proactive change notifications, contact your account team.

Change log

See also