Service providers
Subprocessors
Providers that may process customer data for the hosted Termnova public beta, plus customer-controlled provider categories.
Not every provider below receives every document. Actual processing depends on enabled features, selected routing, region, identity provider, and storage configuration.
Operator-selected providers
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Render | Application hosting, managed PostgreSQL, Redis, network delivery, and operational logs | Customer Content, account, usage, audit, and request data | United States; selected hosting region |
| OpenCode Zen | Primary language-model inference when configured | Prompts and the document passages or structured context needed for a request | Subject to provider routing |
| OpenRouter | Fallback language-model inference and hosted embeddings when configured | Prompts, relevant document passages, and text submitted for embeddings | Subject to provider and model routing |
Provider terms, model availability, routing, logging, retention, and training policies can change. Enterprise customers should confirm approved models and data controls in their Order Form rather than relying only on this public list.
Customer-selected providers
| Category | Purpose | Selected by |
|---|---|---|
| OIDC identity provider | Enterprise authentication and identity claims | Customer or deployment operator |
| S3-compatible storage provider | Durable original-document and evidence storage | Customer or deployment operator |
| Alternative model provider | LLM, embedding, translation, or related inference | Customer or deployment operator |
| Connector provider | Import, synchronization, notifications, or outbound workflow actions | Customer administrator |
Customer-selected providers are not subprocessors appointed solely by Termnova to the extent the customer directly contracts with and instructs them.
Changes and objections
Material updates will be posted on this page with a revised date. Customers requiring advance notice or a defined objection process should include that requirement in a signed agreement. A reasonable privacy objection should explain the specific risk; the parties will work in good faith on a commercially reasonable alternative, which may include disabling an affected feature.
Questions
For provider-specific security documentation, transfer information, or a signed DPA, use the operator contact form without including customer documents in the initial request.