Third Party Index

Snapshot 44977

Document
Subprocessor list
URL
https://www.morphed.io/sub-processors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
29849 bytes
SHA-256 (raw)
e0ccbabc8bcdb453ee92ff46e41c459408bd6c6e30cab6a5ee68450d3a937b57
SHA-256 (normalized text)
847aa4cbd52ed527888ab160f8e7af500a6a13055ceeac4a17ec6a4f61e2554a

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data processing
Sub-processors
Last updated: October 2026
This page lists the vendors that may process Morphed customer data on our behalf. We give 30 days' notice before adding or replacing a public sub-processor. Partner-specific notice periods, including 14 days for BEE where signed, can be set in a DPA addendum.
Customer enabled external MCP providers are controlled by the customer through their own account with that vendor. Morphed governs access, approvals, and audit logs between the agent and the customer enabled provider.
Infrastructure
Hosting, networking, and storage providers that run the Morphed application.
Vendor	Purpose	Region	Transfer mechanism
Supabase	Postgres database, authentication, file storage, and pgvector retrieval where enabled	Frankfurt, Germany or selected EU region	EU hosted, no transfer required for primary storage
Render	Backend application hosting for the Morphed API and worker services	Frankfurt, Germany for the EU deployment profile	EU hosted for EU profile, SCCs where applicable
Vercel	Frontend hosting, static assets, and edge delivery	EU primary region with global edge delivery	SCCs, EU-US Data Privacy Framework
Cloudflare	CDN, DDoS protection, DNS, and network security	Global network with EU controls where available	SCCs, EU-US Data Privacy Framework
AI and model providers
Models are called only with the minimum context required for the approved task. Customer credentials, OAuth tokens, bearer tokens, and API keys are never sent to a model. API data is not used for model training under the applicable provider terms.
Vendor	Purpose	Region	Transfer mechanism
OpenAI
OpenAI EU data residency ↗	LLM inference for governed agent reasoning and document generation where selected	EU routing where enabled, including Amazon Bedrock EU geo inference for the BEE workspace; otherwise United States with minimised payloads	SCCs, EU-US Data Privacy Framework, no training use for API data
Amazon Web Services Bedrock
AWS Bedrock EU geo inference ↗	Claude and OpenAI model inference for the BEE workspace where the Bedrock route is enabled	EU geo inference profile, starting from Frankfurt	EU geo inference route under AWS terms, with no training use of customer data
Anthropic	Claude model provider behind Amazon Bedrock for the BEE EU route, or direct inference where selected	BEE route uses Amazon Bedrock EU geo inference; United States for direct inference unless an approved EU path is selected	AWS Bedrock EU route for BEE; SCCs and EU-US Data Privacy Framework where direct
Pinecone	Vector database for embeddings and retrieval where selected instead of Supabase pgvector	EU region where selected	EU hosted where selected, SCCs where applicable
Supporting services
Transactional email and customer authorised integration services.
Vendor	Purpose	Region	Transfer mechanism
Resend	Transactional email for approvals, alerts, sign-in, and service notifications	European Union	EU hosted, no transfer required for primary email processing
HubSpot	Customer-facing CRM integration, UI extension surface, and customer authorised CRM operations	United States or EU depending on the customer portal	SCCs, EU-US Data Privacy Framework
Customer-connected MCP providers
When a customer connects an external MCP server such as Salesforce, n8n, Slack, Stripe, Gong, Gainsight, Aircall, WhatsApp, SMS, or another provider, that vendor processes data through the customer's own account and contract. Morphed records connector metadata, approval events, tool calls, and verification outcomes.
Notification and objection
To receive notice of sub-processor changes or to request the DPA, SCCs, AI routing posture, connector list, or Article 30 extract, email [email protected].