# Count

Count (count.co): subprocessors, data processing agreement, security documents and changes, as monitored by Third Party Index.

- Page: https://thirdpartyindex.com/vendors/count
- Documents last verified: 2026-10-01
- Transparency rating: 77/100 (how much it publishes, not how secure it is): Subprocessor list 30/30; Processing locations 8/8; Purposes 7/7; Data processing addendum 0/12 (not found); Trust center 8/8; Privacy policy 6/6; security.txt 0/6 (not found); Security page 5/5; Status page 5/5; Vulnerability disclosure 0/5 (not found); Pages still reachable 8/8
- Supply chain: relies on 11 tracked vendors directly, 99 within two hops, 293 within three; 1 tracked vendors rely on it directly, 1 within two hops, 1 within three
- Cite as: Count, Third Party Index, https://thirdpartyindex.com/vendors/count (data CC BY 4.0)

## Documents

| Document | URL | Last verified | Last changed |
|---|---|---|---|
| Trust center | https://trust.count.co/ | 2026-10-01 | 2026-10-01 |
| Subprocessor list | https://trust.count.co/subprocessors | 2026-10-01 | 2026-10-01 |
| Privacy policy | https://count.co/legal/privacy-policy | 2026-10-01 | 2026-10-01 |
| Terms | https://count.co/legal/terms-of-use | 2026-10-01 | 2026-10-01 |
| Security page | https://count.co/legal/security | 2026-10-01 | 2026-10-01 |
| Status page | https://status.count.co/ | 2026-10-01 | 2026-10-01 |

## Subprocessors (11)

As its own list states them.

| Subprocessor | Purpose | Location | Listed since |
|---|---|---|---|
| [Anthropic](https://thirdpartyindex.com/vendors/anthropic.md) (AI model provider: Anthropic) | In-app AI services provider; This subprocessor has two modes of operation: - Disabled: No data is processed by Count AI providers. - Enabled: Row-level query data, dynamic text, CSVs, and other content (e.g. Canvas objects, query metadata, Catalog definitions) may be processed. Your chosen mode can be configured in your Workspace AI settings. Privacy policy:  DPA: | US | 2026-10-01 |
| [Brave](https://thirdpartyindex.com/vendors/brave.md) | Data processed: This sub-processor has two modes of operation: - Disabled: No data is processed by Brave. (Default for workspaces created before 23rd July 2026) - Enabled: Search queries, dynamic text, and context required for web-search grounding may be processed when using AI-driven search features. Your chosen mode can be configured in your Workspace AI settings. Privacy policy: \[; In-app Web Search provider for AI services | US | 2026-10-01 |
| [Cloudflare](https://thirdpartyindex.com/vendors/cloudflare.md) | Count’s Python Request worker provider; Data processed: Requests sent to  Privacy policy:  GDPR policy: | EU,US (Customer traffic is processed globally at the data center closest to the tenant) | 2026-10-01 |
| [Fireworks](https://thirdpartyindex.com/vendors/fireworks.md) (AI model provider: Fireworks) | In-app AI services provider; This subprocessor has two modes of operation: - Disabled: No data is processed by Count AI providers. (Default for workspaces created before 23rd July 2026) - Enabled: Row-level query data, dynamic text, CSVs, and other content (e.g. Canvas objects, query metadata, Catalog definitions) may be processed. Your chosen mode can be configured in your Workspace AI settings. Privacy policy:  DPA: | US | 2026-10-01 |
| [Google Cloud Platform](https://thirdpartyindex.com/vendors/google-cloud.md) | Count's cloud platform provider and email server provider; Data processed: Account data + Application data Location: eu.count.co (EU) app.count.co (US) Privacy policy: | EU/US | 2026-10-01 |
| [Microsoft 365](https://thirdpartyindex.com/vendors/microsoft.md) | Communication and app notifications (Teams); Count's internal and external messaging platform provider. Application data containing personal data is optionally processed if sent by the user (e.g. screenshots of count.co application containing Personal data). Count encourages users not to send sensitive information in this way. Users may optionally set up a Microsoft Teams integration within Count for the purpose of app notifications e.g. notifications of sharing and commenting. Microsoft Teams app notifications may optionally include application data containing personal data if the user creates a canvas alert containing Personal data. Privacy statement: | US | 2026-10-01 |
| [OpenAI](https://thirdpartyindex.com/vendors/openai.md) (AI model provider: OpenAI) | In-app AI services provider; This subprocessor has two modes of operation: - Disabled: No data is processed by Count AI providers. - Enabled: Row-level query data, dynamic text, CSVs, and other content (e.g. Canvas objects, query metadata, Catalog definitions) may be processed. Your chosen mode can be configured in your Workspace AI settings. Privacy policy: \[ DPA: \[ | US | 2026-10-01 |
| [Pylon](https://thirdpartyindex.com/vendors/pylon.md) | Customer operations platform provider.; Data Processed: Communication data. Count leverages Pylon to provide unified customer support across all communication channels. Application data containing personal data is optionally processed if sent by the user (e.g. screenshots of application containing Personal data). Count encourages users not to send sensitive information in this way. Trust platform: | US | 2026-10-01 |
| [Salesforce](https://thirdpartyindex.com/vendors/salesforce.md) | CRM software; Communication and app notifications (Slack): Count's internal, external, and community messaging platform provider. Application data containing personal data is optionally processed if sent by the user (e.g. screenshots of count.co application containing Personal data). Count encourages users not to send sensitive information in this way. Users may optionally set up a Slack integration within Count for the purpose of app notifications e.g. notifications of sharing and commenting. Slack app notifications may optionally include application data containing personal data if the user creates a canvas alert containing Personal data. Users may choose to use email/intercom support instead of slack. Privacy policy: \[ DPA: \[ | US | 2026-10-01 |
| [Sendgrid](https://thirdpartyindex.com/vendors/sendgrid.md) | Communication platform; Count’s application email server provider for app based email notification and alerts. Email messages may be sent to the user e.g. notifications of sharing and commenting. Email messages may optionally include Personal data if the user creates a canvas alert containing Personal data. Privacy policy: \[ DPA: \[ | EU | 2026-10-01 |
| [Sentry](https://thirdpartyindex.com/vendors/sentry.md) | Cloud monitoring; Privacy policy: \[ DPA: \[ | EU | 2026-10-01 |

Read from ([evidence](https://thirdpartyindex.com/evidence/27029)). CSV: https://thirdpartyindex.com/vendors/count/subprocessors.csv

AI model providers (or a cloud provider's AI model service) among these entries: 3. All vendors that list one: https://thirdpartyindex.com/ai

## Compliance

As its trust center lists them.

- Audited: SOC 2 Type II ([evidence](https://thirdpartyindex.com/evidence/27028))

## Listed as a subprocessor by (1)

Tracked vendors whose own subprocessor lists name it, and what they say they use it for.

- [Trainual](https://thirdpartyindex.com/vendors/trainual.md): Data visualization and dashboard prototyping

## Service status

Incidents it reported on its own status page.

- Last 90 days: 0 reported incidents (0 major or critical, 0 minor, 0 with no impact stated)
- Status page last read: 2026-10-01
- No incidents reported since Jun 19, 2026
- 2026-06-19: Degraded AI and API operations (major)

---

Third Party Index (https://thirdpartyindex.com) monitors vendors' public security and privacy documents and keeps each version as evidence. Data CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/); vendors' own documents are theirs. API: https://thirdpartyindex.com/api
