Deepline subprocessors.

Deepline uses the subprocessors below to provide, secure, monitor, bill, and support the service. We review vendors before use, keep the list current, and provide required notice for material additions or replacements.

Last updated July 11, 2026. This page is provided for procurement and security review.

Core subprocessors.

Vercel, Inc.

Application hosting and deployment.

Website and app request metadata, hosted app content, diagnostics, and operational logs.

United States / global edge infrastructure

Infrastructure

Cloudflare, Inc.

Edge networking, Workers runtime, R2 artifact storage, and runtime harness infrastructure.

Request metadata, runtime traffic, staged files, artifacts, runtime payloads, and operational logs.

Global edge infrastructure

Infrastructure

Convex, Inc.

Application backend, realtime state, workflow metadata, run ledger, and dashboard state.

Account data, workspace and org identifiers, API key metadata, OAuth metadata, encrypted credential or token ciphertext, play and run metadata, bounded run logs, and summaries.

United States

Infrastructure

Neon, LLC, affiliate of Databricks

Managed Postgres data planes for runtime sheets, persisted row state, play outputs, and ingestion storage.

Customer data including row data, step outputs, dataset previews, provider or tool results, and tenant database metadata.

United States / selected cloud regions as configured

Infrastructure

Fly.io

Runtime worker infrastructure for scheduler profiles and receipt gateway services.

Customer data needed for play execution, scheduler metadata, run receipts, runtime logs, and operational metadata.

United States / selected Fly regions as configured

Infrastructure

Daytona Platforms Inc.

Sandbox and runtime infrastructure for supported workflow execution profiles.

Customer data made available to a sandboxed play run, bounded execution logs, and runtime authority metadata.

United States / selected runtime regions as configured

Infrastructure

OpenAI, L.L.C.

AI model and API services when Deepline AI features are used.

Prompts, instructions, inputs, outputs, and related metadata sent to AI features.

United States / provider infrastructure

AI provider

Anthropic, PBC

AI model and API services when Deepline AI features are used.

Prompts, instructions, inputs, outputs, and related metadata sent to AI features.

United States / provider infrastructure

AI provider

Google LLC

Gemini, Google AI, or Google API services where used by Deepline features.

Prompts, outputs, request metadata, or customer-authorized Google data, depending on the feature.

United States / global provider infrastructure

AI provider / integration provider

Business operations subprocessors.

Stripe

Billing, checkout, payment processing, invoices, subscription state, and billing webhooks.

Account data, billing contact details, payment method metadata, Stripe customer, subscription, and payment identifiers, invoice records, and transaction records. Deepline does not store raw card numbers.

United States

Business operations

Plus Five Five, Inc. (Resend)

Transactional email, magic links, onboarding, and service notifications.

Account data including recipient email, message metadata, and message content.

United States

Business operations

Axiom Inc.

Logs, observability, and operational diagnostics.

Request metadata, operational logs, error logs, and limited user or workspace identifiers where logged by application code.

United States / configured Axiom region

Business operations

RudderStack, Inc.

Browser and server-side product analytics.

Account data, anonymous identifiers, page and product event metadata, organization grouping events, and device or browser metadata.

United States / configured data plane

Business operations

HubSpot

CRM, website forms, sales/support workflows, partner intake, and customer communications.

Account data submitted through forms, business contact details, message content, and CRM metadata.

United States

Business operations

Drata

Compliance automation and control monitoring.

Account data for procurement/security review, employee and vendor evidence, and limited customer contact metadata during compliance workflows.

United States

Compliance

Sensiba

Independent SOC 2 audit and assurance services.

Account data and security/compliance evidence needed for audit review.

United States

Compliance / audit

How changes are handled.

Deepline may use general written authorization for subprocessors in customer DPAs. When Deepline adds or replaces a core subprocessor that materially processes customer data, Deepline provides notice through the contract, security portal, email, or this page with a reasonable period for customer objections.

For customer-enabled integrations, connecting or invoking the integration is the customer's instruction and authorization to transmit selected data to that provider, subject to the customer's agreement with that provider.

Questions about this list can be sent to team@deepline.com. See also the Privacy Policy.