How we pick a vendor
Before signing on a vendor, we check (a) the security controls and certifications they hold, (b) whether the data they will see is necessary for what they do for us, (c) where they store and process that data, and (d) the lawful transfer mechanism we need if they sit outside the data-exporting region. Every vendor signs a written agreement that imposes substantially equivalent confidentiality, security, and data-protection obligations to those in our customer agreements, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply.
We re-check each vendor at least once a year, and we monitor for changes in their security posture, ownership, or location.
Current subprocessors
13 vendors · last reviewed May 16, 2026
United States
Anthropic
Model inference
Large language model inference for agent reasoning and approvals. Inputs are not used to train Anthropic's models.
United States
Cohere
Model inference
Embedding and reranking models for retrieval. Inputs are not used to train Cohere's models.
United States
Daytona
Code sandbox
Ephemeral, isolated sandboxes that run agent-generated code on a restricted toolchain.
United States
Finix
Payouts and KYC
Marketplace payment facilitator: KYC/KYB onboarding for sellers and payouts to seller bank accounts.
United States
Infisical
Secrets management
Encrypted secrets management for platform configuration (API keys for inference, payments, email).
United States
Neon
Database
Hosted Postgres for accounts, workspaces, agent manifests, audit-event chains, and billing metadata.
United States
OpenAI
Model inference
Large language model inference where the customer chooses an OpenAI model. Inputs are not used to train OpenAI's models when accessed via the platform.
United States
Qdrant Cloud
Vector retrieval
Vector database for retrieval-augmented generation over Customer Content (knowledge bases, prior runs).
United States
Resend
Email delivery
Transactional email delivery (verification, password reset, billing, audit notifications) and email outputs sent by agents on a Workspace's behalf.
United States
Global
Algolia
Search
Marketplace search index for the public agent catalog. Indexed data is non-tenant.
Global
CyberSource
Card acceptance
Card acceptance and 3-D Secure for billing payments. Raw card data is tokenized and never stored on our systems.
Global
Sinch
Messaging
Transactional SMS delivery (one-time codes for two-factor authentication, agent-sent notifications).
Global
Cross-border transfers
When personal information from the European Economic Area, the United Kingdom, or Switzerland is shared with a vendor located outside that region, we rely on (a) the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, (b) technical safeguards such as encryption in transit and at rest and tenant isolation, and (c) where appropriate, the EU–U.S. Data Privacy Framework with vendors self-certified to it. We document a transfer-impact assessment for each region.
Notice of changes
We give at least thirty (30) days advance notice before adding a new vendor that handles Customer Content, by updating this page and emailing the Workspace owner. Customers on enterprise plans can subscribe to a vendor-update mailing list and may object on reasonable grounds, as set out in our Data Processing Addendum.
Connectors you authorize
Separately from the vendors above, your Workspace can connect to third-party systems you already use (your CRM, your ticketing platform, your code host, etc.). Those third-party systems are not our subprocessors — they are independent providers with whom you have your own relationship. The Service acts on your behalf within the scopes you grant; your contracts with those providers govern what they do with the data they receive.
Contact
For privacy questions or to ask about a specific vendor, write to legal@mvsagents.ai. For security-specific concerns, contact security@mvsagents.ai. Our broader privacy practices are described in the Privacy Policy.
AgentHub is operated by MVS Holdings. Last reviewed: May 16, 2026.