Third Party Index

Snapshot 16881

Document
Trust center
URL
https://trust.parahelp.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
363521 bytes
SHA-256 (raw)
38244dfabbe54770ccc428b7978264c16a53d88a13654c553868c8428b6eb5da
SHA-256 (normalized text)
e0859bfa1689a3ae8776430c201ea43f64e1700bccbd4f5a89dc2ec5f6ecdb18

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Parahelp
Parahelp is your AI customer support team that builds and improves itself to resolve your most complex support tickets end-to-end.
We’re SOC 2 Type II certified and built with GDPR in mind from day one. We follow solid security practices, maintain strict access controls, and continuously monitor our systems to keep your data safe.
[email protected]
Compliance
SOC 2
GDPR
Subprocessors
View all
Anthropic
•
AI model inference
US
OpenAI
•
AI model inference
US
PlanetScale
•
Transactional SQL database (via Prisma) to store and query core app data
US
Google Cloud (Gemini)
•
AI model inference
US
Controls
View all
Infrastructure security
Encryption key access restricted
Unique account authentication enforced
Production application access restricted
View 14 more Infrastructure security controls
Organizational security
Anti-malware technology utilized
Employee background checks performed
Code of Conduct acknowledged by employees and enforced
View 7 more Organizational security controls
Product security
Control self-assessments conducted
Vulnerability and system monitoring procedures established
Penetration testing performed
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Configuration management system established
View 28 more Internal security procedures controls
Data and privacy
Data retention procedures established
Data classification policy established
Resources
View all
Audit reports
SOC 2 Type II
Penetration test
Penetration test
Security and risk management
Information Security Policy (AUP)
Risk Management Policy
Third-Party Management Policy
Technical security
Access Control Policy
Cryptography Policy
Operations Security Policy
Secure Development Policy
Data protection and privacy
Data Management Policy
GDPR Compliance Policy
Incident response and business continuity
Incident Response Plan
GDPR Incident Response Plan
Business Continuity and Disaster Recovery Plan
AI governance
AI Model Governance and Risk Management Policy
Updates
View all
General
New SOC 2 Type 2 report, updated policies, and changes to how we handle customer data
Published September 25, 2026
We have a few security and privacy updates to share this quarter. We’ve completed our latest SOC 2 Type 2 audit with A-LIGN, published an updated set of security and privacy policies, and made changes to our infrastructure and removed a subprocessor.
We’re also updating how Parahelp handles customer data as we introduce new product capabilities that let customers connect support channels directly to Parahelp, including chat widgets, email, Slack, and other channels. This change will take effect on November 1, 2026.
Details on each update are below.
New SOC 2 Type 2 report
Our latest SOC 2 Type 2 report, completed by A-LIGN, is now available. The report covers the Parahelp Customer Support Platform against the Security, Availability, and Confidentiality Trust Services Criteria for the period from April 1 through June 30, 2026.
You can request access to the report under Resources.
Updated security and privacy policies
As part of our continued investment in security and compliance, we’ve updated our security and privacy policy framework. The policies were approved in June 2026 and are reviewed at least annually.
The following policies are available under Resources:
Access Control Policy
AI Model Governance and Risk Management Policy
Business Continuity and Disaster Recovery Plan
Cryptography Policy
Data Management Policy
GDPR Compliance Policy
GDPR Incident Response Plan
Incident Response Plan
Information Security Policy (AUP)
Operations Security Policy
Risk Management Policy
Secure Development Policy
Third-Party Management Policy
Additional policies are available upon request.
Changes to how we store customer data
Parahelp is soon introducing new ways for customers to connect support channels directly to the platform, including chat widgets, email, Slack, and other channels.
To support these capabilities and improve how Parahelp handles conversations across the platform, Parahelp will begin storing conversation data and associated end-user personal data, including information such as names and email addresses. This applies both to conversations coming through channels connected directly to Parahelp and to conversations processed through existing help desk or ticketing system integrations.
This change will take effect for all customers on November 1, 2026.
All stored data will continue to be governed by your Cloud Services Agreement (CSA) and Data Processing Agreement (DPA). Data is encrypted in transit and at rest, and access is restricted to authorized personnel.
If you have any questions about this change, please contact [email protected].
Subprocessor changes
We’ve removed Railway as a subprocessor. The services previously hosted on Railway now run on AWS in the us-east-1 region.
You can find our full, up-to-date list of subprocessors in the Parahelp Trust Center, where you can also subscribe to receive notifications about future changes.
Privacy
Subprocessor Update: OpenRouter
Published August 26, 2026
We are updating our list of subprocessors to add OpenRouter. This change will take effect on September 10, 2026.
We are adding OpenRouter as a new subprocessor. OpenRouter provides a unified routing layer that gives us access to AI models from multiple underlying providers through a single API, helping us maintain flexibility and reliability in our model infrastructure.
All processing through OpenRouter will take place in the United States. We also have a zero data retention commitment in place with OpenRouter, meaning customer data is not retained after processing.
As part of providing these services, OpenRouter may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
We have reviewed the security and data protection practices of OpenRouter and have an appropriate data processing agreement in place. This agreement requires OpenRouter to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Cloudflare, Baseten, Together.ai, Pinecone, Algolia, and PostHog
Published June 30, 2026
We are updating our list of subprocessors as part of continued improvements to Parahelp’s infrastructure, reliability, and scalability. These changes will take effect on July 14, 2026.
We are adding Cloudflare as a new subprocessor to strengthen our compute infrastructure and improve platform resilience. Cloudflare will be used as a fallback container hosting provider and to host certain API surfaces, helping us maintain availability and support reliable scaling of the Parahelp platform.
We are also adding Baseten and Together.ai as subprocessors to support AI model inference. Baseten will act as an additional inference provider, while Together.ai will serve as a fallback provider to support continuity and reliability.
For Baseten and Together.ai, all processing will take place in either the United States or the European Union. We also have zero data retention commitments in place with both providers, meaning customer data is not retained after processing.
As part of providing these services, Cloudflare, Baseten, and Together.ai may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
Separately, we are removing Pinecone, Algolia, and PostHog from our list of subprocessors. These providers will no longer be used as subprocessors in connection with Parahelp.
We have reviewed the security and data protection practices of each new subprocessor and have appropriate data processing agreements in place. These agreements require each provider to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Modal and Pierre
Published May 1, 2026
We are adding Modal and Pierre as new subprocessors to support the release of CodeGen in the Internal Agent. These subprocessors will be taken into use as of May 11, 2026.
Modal is used as a serverless compute platform to run AI workloads such as inference and batch processing.
Pierre (operating code.storage) is used as a code hosting and version control platform to store source code repositories supporting the Internal Agent.
Modal and Pierre may store PII-redacted customer data as part of providing their functionality. Any such data is retained only for the duration of the customer contract and is deleted upon termination or upon request, in line with our data retention and deletion practices.
Each subprocessor has been evaluated to ensure appropriate technical and organizational measures are in place to protect customer data. We maintain data processing agreements with these subprocessors that ensure their security and data protection obligations are no less protective than those we commit to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Read more about Subprocessor Update: OpenRouter
Parahelp
Parahelp is your AI customer support team that builds and improves itself to resolve your most complex support tickets end-to-end.
We’re SOC 2 Type II certified and built with GDPR in mind from day one. We follow solid security practices, maintain strict access controls, and continuously monitor our systems to keep your data safe.
[email protected]
Compliance
SOC 2
GDPR
Subprocessors
View all
Anthropic
•
AI model inference
US
OpenAI
•
AI model inference
US
PlanetScale
•
Transactional SQL database (via Prisma) to store and query core app data
US
Google Cloud (Gemini)
•
AI model inference
US
Controls
View all
Infrastructure security
Encryption key access restricted
Unique account authentication enforced
Production application access restricted
View 14 more Infrastructure security controls
Organizational security
Anti-malware technology utilized
Employee background checks performed
Code of Conduct acknowledged by employees and enforced
View 7 more Organizational security controls
Product security
Control self-assessments conducted
Vulnerability and system monitoring procedures established
Penetration testing performed
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Configuration management system established
View 28 more Internal security procedures controls
Data and privacy
Data retention procedures established
Data classification policy established
Resources
View all
Audit reports
SOC 2 Type II
Penetration test
Penetration test
Security and risk management
Information Security Policy (AUP)
Risk Management Policy
Third-Party Management Policy
Technical security
Access Control Policy
Cryptography Policy
Operations Security Policy
Secure Development Policy
Data protection and privacy
Data Management Policy
GDPR Compliance Policy
Incident response and business continuity
Incident Response Plan
GDPR Incident Response Plan
Business Continuity and Disaster Recovery Plan
AI governance
AI Model Governance and Risk Management Policy
Updates
View all
General
New SOC 2 Type 2 report, updated policies, and changes to how we handle customer data
Published September 25, 2026
We have a few security and privacy updates to share this quarter. We’ve completed our latest SOC 2 Type 2 audit with A-LIGN, published an updated set of security and privacy policies, and made changes to our infrastructure and removed a subprocessor.
We’re also updating how Parahelp handles customer data as we introduce new product capabilities that let customers connect support channels directly to Parahelp, including chat widgets, email, Slack, and other channels. This change will take effect on November 1, 2026.
Details on each update are below.
New SOC 2 Type 2 report
Our latest SOC 2 Type 2 report, completed by A-LIGN, is now available. The report covers the Parahelp Customer Support Platform against the Security, Availability, and Confidentiality Trust Services Criteria for the period from April 1 through June 30, 2026.
You can request access to the report under Resources.
Updated security and privacy policies
As part of our continued investment in security and compliance, we’ve updated our security and privacy policy framework. The policies were approved in June 2026 and are reviewed at least annually.
The following policies are available under Resources:
Access Control Policy
AI Model Governance and Risk Management Policy
Business Continuity and Disaster Recovery Plan
Cryptography Policy
Data Management Policy
GDPR Compliance Policy
GDPR Incident Response Plan
Incident Response Plan
Information Security Policy (AUP)
Operations Security Policy
Risk Management Policy
Secure Development Policy
Third-Party Management Policy
Additional policies are available upon request.
Changes to how we store customer data
Parahelp is soon introducing new ways for customers to connect support channels directly to the platform, including chat widgets, email, Slack, and other channels.
To support these capabilities and improve how Parahelp handles conversations across the platform, Parahelp will begin storing conversation data and associated end-user personal data, including information such as names and email addresses. This applies both to conversations coming through channels connected directly to Parahelp and to conversations processed through existing help desk or ticketing system integrations.
This change will take effect for all customers on November 1, 2026.
All stored data will continue to be governed by your Cloud Services Agreement (CSA) and Data Processing Agreement (DPA). Data is encrypted in transit and at rest, and access is restricted to authorized personnel.
If you have any questions about this change, please contact [email protected].
Subprocessor changes
We’ve removed Railway as a subprocessor. The services previously hosted on Railway now run on AWS in the us-east-1 region.
You can find our full, up-to-date list of subprocessors in the Parahelp Trust Center, where you can also subscribe to receive notifications about future changes.
Privacy
Subprocessor Update: OpenRouter
Published August 26, 2026
We are updating our list of subprocessors to add OpenRouter. This change will take effect on September 10, 2026.
We are adding OpenRouter as a new subprocessor. OpenRouter provides a unified routing layer that gives us access to AI models from multiple underlying providers through a single API, helping us maintain flexibility and reliability in our model infrastructure.
All processing through OpenRouter will take place in the United States. We also have a zero data retention commitment in place with OpenRouter, meaning customer data is not retained after processing.
As part of providing these services, OpenRouter may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
We have reviewed the security and data protection practices of OpenRouter and have an appropriate data processing agreement in place. This agreement requires OpenRouter to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Cloudflare, Baseten, Together.ai, Pinecone, Algolia, and PostHog
Published June 30, 2026
We are updating our list of subprocessors as part of continued improvements to Parahelp’s infrastructure, reliability, and scalability. These changes will take effect on July 14, 2026.
We are adding Cloudflare as a new subprocessor to strengthen our compute infrastructure and improve platform resilience. Cloudflare will be used as a fallback container hosting provider and to host certain API surfaces, helping us maintain availability and support reliable scaling of the Parahelp platform.
We are also adding Baseten and Together.ai as subprocessors to support AI model inference. Baseten will act as an additional inference provider, while Together.ai will serve as a fallback provider to support continuity and reliability.
For Baseten and Together.ai, all processing will take place in either the United States or the European Union. We also have zero data retention commitments in place with both providers, meaning customer data is not retained after processing.
As part of providing these services, Cloudflare, Baseten, and Together.ai may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
Separately, we are removing Pinecone, Algolia, and PostHog from our list of subprocessors. These providers will no longer be used as subprocessors in connection with Parahelp.
We have reviewed the security and data protection practices of each new subprocessor and have appropriate data processing agreements in place. These agreements require each provider to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Modal and Pierre
Published May 1, 2026
We are adding Modal and Pierre as new subprocessors to support the release of CodeGen in the Internal Agent. These subprocessors will be taken into use as of May 11, 2026.
Modal is used as a serverless compute platform to run AI workloads such as inference and batch processing.
Pierre (operating code.storage) is used as a code hosting and version control platform to store source code repositories supporting the Internal Agent.
Modal and Pierre may store PII-redacted customer data as part of providing their functionality. Any such data is retained only for the duration of the customer contract and is deleted upon termination or upon request, in line with our data retention and deletion practices.
Each subprocessor has been evaluated to ensure appropriate technical and organizational measures are in place to protect customer data. We maintain data processing agreements with these subprocessors that ensure their security and data protection obligations are no less protective than those we commit to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Read more about Subprocessor Update: Cloudflare, Baseten, Together.ai, Pinecone, Algolia, and PostHog
Parahelp
Parahelp is your AI customer support team that builds and improves itself to resolve your most complex support tickets end-to-end.
We’re SOC 2 Type II certified and built with GDPR in mind from day one. We follow solid security practices, maintain strict access controls, and continuously monitor our systems to keep your data safe.
[email protected]
Compliance
SOC 2
GDPR
Subprocessors
View all
Anthropic
•
AI model inference
US
OpenAI
•
AI model inference
US
PlanetScale
•
Transactional SQL database (via Prisma) to store and query core app data
US
Google Cloud (Gemini)
•
AI model inference
US
Controls
View all
Infrastructure security
Encryption key access restricted
Unique account authentication enforced
Production application access restricted
View 14 more Infrastructure security controls
Organizational security
Anti-malware technology utilized
Employee background checks performed
Code of Conduct acknowledged by employees and enforced
View 7 more Organizational security controls
Product security
Control self-assessments conducted
Vulnerability and system monitoring procedures established
Penetration testing performed
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Configuration management system established
View 28 more Internal security procedures controls
Data and privacy
Data retention procedures established
Data classification policy established
Resources
View all
Audit reports
SOC 2 Type II
Penetration test
Penetration test
Security and risk management
Information Security Policy (AUP)
Risk Management Policy
Third-Party Management Policy
Technical security
Access Control Policy
Cryptography Policy
Operations Security Policy
Secure Development Policy
Data protection and privacy
Data Management Policy
GDPR Compliance Policy
Incident response and business continuity
Incident Response Plan
GDPR Incident Response Plan
Business Continuity and Disaster Recovery Plan
AI governance
AI Model Governance and Risk Management Policy
Updates
View all
General
New SOC 2 Type 2 report, updated policies, and changes to how we handle customer data
Published September 25, 2026
We have a few security and privacy updates to share this quarter. We’ve completed our latest SOC 2 Type 2 audit with A-LIGN, published an updated set of security and privacy policies, and made changes to our infrastructure and removed a subprocessor.
We’re also updating how Parahelp handles customer data as we introduce new product capabilities that let customers connect support channels directly to Parahelp, including chat widgets, email, Slack, and other channels. This change will take effect on November 1, 2026.
Details on each update are below.
New SOC 2 Type 2 report
Our latest SOC 2 Type 2 report, completed by A-LIGN, is now available. The report covers the Parahelp Customer Support Platform against the Security, Availability, and Confidentiality Trust Services Criteria for the period from April 1 through June 30, 2026.
You can request access to the report under Resources.
Updated security and privacy policies
As part of our continued investment in security and compliance, we’ve updated our security and privacy policy framework. The policies were approved in June 2026 and are reviewed at least annually.
The following policies are available under Resources:
Access Control Policy
AI Model Governance and Risk Management Policy
Business Continuity and Disaster Recovery Plan
Cryptography Policy
Data Management Policy
GDPR Compliance Policy
GDPR Incident Response Plan
Incident Response Plan
Information Security Policy (AUP)
Operations Security Policy
Risk Management Policy
Secure Development Policy
Third-Party Management Policy
Additional policies are available upon request.
Changes to how we store customer data
Parahelp is soon introducing new ways for customers to connect support channels directly to the platform, including chat widgets, email, Slack, and other channels.
To support these capabilities and improve how Parahelp handles conversations across the platform, Parahelp will begin storing conversation data and associated end-user personal data, including information such as names and email addresses. This applies both to conversations coming through channels connected directly to Parahelp and to conversations processed through existing help desk or ticketing system integrations.
This change will take effect for all customers on November 1, 2026.
All stored data will continue to be governed by your Cloud Services Agreement (CSA) and Data Processing Agreement (DPA). Data is encrypted in transit and at rest, and access is restricted to authorized personnel.
If you have any questions about this change, please contact [email protected].
Subprocessor changes
We’ve removed Railway as a subprocessor. The services previously hosted on Railway now run on AWS in the us-east-1 region.
You can find our full, up-to-date list of subprocessors in the Parahelp Trust Center, where you can also subscribe to receive notifications about future changes.
Privacy
Subprocessor Update: OpenRouter
Published August 26, 2026
We are updating our list of subprocessors to add OpenRouter. This change will take effect on September 10, 2026.
We are adding OpenRouter as a new subprocessor. OpenRouter provides a unified routing layer that gives us access to AI models from multiple underlying providers through a single API, helping us maintain flexibility and reliability in our model infrastructure.
All processing through OpenRouter will take place in the United States. We also have a zero data retention commitment in place with OpenRouter, meaning customer data is not retained after processing.
As part of providing these services, OpenRouter may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
We have reviewed the security and data protection practices of OpenRouter and have an appropriate data processing agreement in place. This agreement requires OpenRouter to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Cloudflare, Baseten, Together.ai, Pinecone, Algolia, and PostHog
Published June 30, 2026
We are updating our list of subprocessors as part of continued improvements to Parahelp’s infrastructure, reliability, and scalability. These changes will take effect on July 14, 2026.
We are adding Cloudflare as a new subprocessor to strengthen our compute infrastructure and improve platform resilience. Cloudflare will be used as a fallback container hosting provider and to host certain API surfaces, helping us maintain availability and support reliable scaling of the Parahelp platform.
We are also adding Baseten and Together.ai as subprocessors to support AI model inference. Baseten will act as an additional inference provider, while Together.ai will serve as a fallback provider to support continuity and reliability.
For Baseten and Together.ai, all processing will take place in either the United States or the European Union. We also have zero data retention commitments in place with both providers, meaning customer data is not retained after processing.
As part of providing these services, Cloudflare, Baseten, and Together.ai may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
Separately, we are removing Pinecone, Algolia, and PostHog from our list of subprocessors. These providers will no longer be used as subprocessors in connection with Parahelp.
We have reviewed the security and data protection practices of each new subprocessor and have appropriate data processing agreements in place. These agreements require each provider to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Modal and Pierre
Published May 1, 2026
We are adding Modal and Pierre as new subprocessors to support the release of CodeGen in the Internal Agent. These subprocessors will be taken into use as of May 11, 2026.
Modal is used as a serverless compute platform to run AI workloads such as inference and batch processing.
Pierre (operating code.storage) is used as a code hosting and version control platform to store source code repositories supporting the Internal Agent.
Modal and Pierre may store PII-redacted customer data as part of providing their functionality. Any such data is retained only for the duration of the customer contract and is deleted upon termination or upon request, in line with our data retention and deletion practices.
Each subprocessor has been evaluated to ensure appropriate technical and organizational measures are in place to protect customer data. We maintain data processing agreements with these subprocessors that ensure their security and data protection obligations are no less protective than those we commit to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Read more about Subprocessor Update: Modal and Pierre
Parahelp
Parahelp is your AI customer support team that builds and improves itself to resolve your most complex support tickets end-to-end.
We’re SOC 2 Type II certified and built with GDPR in mind from day one. We follow solid security practices, maintain strict access controls, and continuously monitor our systems to keep your data safe.
[email protected]
Compliance
SOC 2
GDPR
Subprocessors
View all
Anthropic
•
AI model inference
US
OpenAI
•
AI model inference
US
PlanetScale
•
Transactional SQL database (via Prisma) to store and query core app data
US
Google Cloud (Gemini)
•
AI model inference
US
Controls
View all
Infrastructure security
Encryption key access restricted
Unique account authentication enforced
Production application access restricted
View 14 more Infrastructure security controls
Organizational security
Anti-malware technology utilized
Employee background checks performed
Code of Conduct acknowledged by employees and enforced
View 7 more Organizational security controls
Product security
Control self-assessments conducted
Vulnerability and system monitoring procedures established
Penetration testing performed
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Configuration management system established
View 28 more Internal security procedures controls
Data and privacy
Data retention procedures established
Data classification policy established
Resources
View all
Audit reports
SOC 2 Type II
Penetration test
Penetration test
Security and risk management
Information Security Policy (AUP)
Risk Management Policy
Third-Party Management Policy
Technical security
Access Control Policy
Cryptography Policy
Operations Security Policy
Secure Development Policy
Data protection and privacy
Data Management Policy
GDPR Compliance Policy
Incident response and business continuity
Incident Response Plan
GDPR Incident Response Plan
Business Continuity and Disaster Recovery Plan
AI governance
AI Model Governance and Risk Management Policy
Updates
View all
General
New SOC 2 Type 2 report, updated policies, and changes to how we handle customer data
Published September 25, 2026
We have a few security and privacy updates to share this quarter. We’ve completed our latest SOC 2 Type 2 audit with A-LIGN, published an updated set of security and privacy policies, and made changes to our infrastructure and removed a subprocessor.
We’re also updating how Parahelp handles customer data as we introduce new product capabilities that let customers connect support channels directly to Parahelp, including chat widgets, email, Slack, and other channels. This change will take effect on November 1, 2026.
Details on each update are below.
New SOC 2 Type 2 report
Our latest SOC 2 Type 2 report, completed by A-LIGN, is now available. The report covers the Parahelp Customer Support Platform against the Security, Availability, and Confidentiality Trust Services Criteria for the period from April 1 through June 30, 2026.
You can request access to the report under Resources.
Updated security and privacy policies
As part of our continued investment in security and compliance, we’ve updated our security and privacy policy framework. The policies were approved in June 2026 and are reviewed at least annually.
The following policies are available under Resources:
Access Control Policy
AI Model Governance and Risk Management Policy
Business Continuity and Disaster Recovery Plan
Cryptography Policy
Data Management Policy
GDPR Compliance Policy
GDPR Incident Response Plan
Incident Response Plan
Information Security Policy (AUP)
Operations Security Policy
Risk Management Policy
Secure Development Policy
Third-Party Management Policy
Additional policies are available upon request.
Changes to how we store customer data
Parahelp is soon introducing new ways for customers to connect support channels directly to the platform, including chat widgets, email, Slack, and other channels.
To support these capabilities and improve how Parahelp handles conversations across the platform, Parahelp will begin storing conversation data and associated end-user personal data, including information such as names and email addresses. This applies both to conversations coming through channels connected directly to Parahelp and to conversations processed through existing help desk or ticketing system integrations.
This change will take effect for all customers on November 1, 2026.
All stored data will continue to be governed by your Cloud Services Agreement (CSA) and Data Processing Agreement (DPA). Data is encrypted in transit and at rest, and access is restricted to authorized personnel.
If you have any questions about this change, please contact [email protected].
Subprocessor changes
We’ve removed Railway as a subprocessor. The services previously hosted on Railway now run on AWS in the us-east-1 region.
You can find our full, up-to-date list of subprocessors in the Parahelp Trust Center, where you can also subscribe to receive notifications about future changes.
Privacy
Subprocessor Update: OpenRouter
Published August 26, 2026
We are updating our list of subprocessors to add OpenRouter. This change will take effect on September 10, 2026.
We are adding OpenRouter as a new subprocessor. OpenRouter provides a unified routing layer that gives us access to AI models from multiple underlying providers through a single API, helping us maintain flexibility and reliability in our model infrastructure.
All processing through OpenRouter will take place in the United States. We also have a zero data retention commitment in place with OpenRouter, meaning customer data is not retained after processing.
As part of providing these services, OpenRouter may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
We have reviewed the security and data protection practices of OpenRouter and have an appropriate data processing agreement in place. This agreement requires OpenRouter to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Cloudflare, Baseten, Together.ai, Pinecone, Algolia, and PostHog
Published June 30, 2026
We are updating our list of subprocessors as part of continued improvements to Parahelp’s infrastructure, reliability, and scalability. These changes will take effect on July 14, 2026.
We are adding Cloudflare as a new subprocessor to strengthen our compute infrastructure and improve platform resilience. Cloudflare will be used as a fallback container hosting provider and to host certain API surfaces, helping us maintain availability and support reliable scaling of the Parahelp platform.
We are also adding Baseten and Together.ai as subprocessors to support AI model inference. Baseten will act as an additional inference provider, while Together.ai will serve as a fallback provider to support continuity and reliability.
For Baseten and Together.ai, all processing will take place in either the United States or the European Union. We also have zero data retention commitments in place with both providers, meaning customer data is not retained after processing.
As part of providing these services, Cloudflare, Baseten, and Together.ai may process limited customer data necessary to provide, secure, and maintain the relevant services. This may include request metadata, data transmitted through relevant API surfaces, and data processed through model inference workflows.
Separately, we are removing Pinecone, Algolia, and PostHog from our list of subprocessors. These providers will no longer be used as subprocessors in connection with Parahelp.
We have reviewed the security and data protection practices of each new subprocessor and have appropriate data processing agreements in place. These agreements require each provider to maintain security and data protection obligations that are at least as protective as the commitments we make to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].
Privacy
Subprocessor Update: Modal and Pierre
Published May 1, 2026
We are adding Modal and Pierre as new subprocessors to support the release of CodeGen in the Internal Agent. These subprocessors will be taken into use as of May 11, 2026.
Modal is used as a serverless compute platform to run AI workloads such as inference and batch processing.
Pierre (operating code.storage) is used as a code hosting and version control platform to store source code repositories supporting the Internal Agent.
Modal and Pierre may store PII-redacted customer data as part of providing their functionality. Any such data is retained only for the duration of the customer contract and is deleted upon termination or upon request, in line with our data retention and deletion practices.
Each subprocessor has been evaluated to ensure appropriate technical and organizational measures are in place to protect customer data. We maintain data processing agreements with these subprocessors that ensure their security and data protection obligations are no less protective than those we commit to our customers.
If you have any questions or wish to raise an objection in accordance with your agreement, please contact us at [email protected].