Skip to main content

Subprocessors

Subprocessors

This page identifies subprocessors and service providers that surgicAI may use to provide MARCUS. The specific subprocessors used may vary by deployment, customer agreement, feature configuration, geography, and workspace type.

PHI-enabled deployments require a PHI-approved vendor chain. Public demos, trial workspaces, and uncontracted deployments are not approved for PHI.

Last updated: May 20, 2026

Current Subprocessors and Service Providers

This table is intentionally conservative. Deployment-specific agreements, regions, and provider contracts may narrow or expand the list for a particular customer.

Current subprocessors and service providers
ProviderRoleData involvedPHI statusNotes
OpenAIModel answer generation and search representations where enabledPrompts, cited source passages, outputs, search representations, metadata depending on routePHI only under approved BAA-covered configurationDo not route PHI unless contract and endpoint configuration are approved
Amazon Web Services or S3-compatible storage providerHosting, storage, infrastructure, object storage, backupsUploaded documents, index artifacts, logs, application data depending on deploymentPHI only under approved deploymentProvider and region may vary by deployment
VercelFrontend hosting and edge delivery where usedFrontend delivery data, logs, request metadataNot approved for PHI unless specifically reviewed and contractedPHI payloads should not be sent to frontend logs
RailwayBackend hosting where usedAPI/runtime logs, application processing depending on deploymentNot approved for PHI unless specifically reviewed and contractedUsage may vary by environment
StripeBilling and payment processingBilling contact info, payment metadata, invoice detailsNo PHI should be submittedPayment processor
Email and support providersSupport and transactional emailContact details, support communicationsNo PHI unless specifically approvedUsers should not include PHI in support tickets
Monitoring and logging providersError monitoring, uptime, security logsLogs, error reports, request metadataNo PHI unless specifically approved and scrubbedConfigure scrubbing and retention

Subprocessor Change Notices

For enterprise customers with signed agreements requiring notice, we will provide notice of new subprocessors according to the applicable agreement. Customers may object to a new subprocessor as provided in their agreement.

Deployment-Specific Subprocessors

A customer's actual subprocessor list may differ based on:

  • Public website vs. authenticated app.
  • Trial vs. enterprise deployment.
  • PHI-off vs. PHI-enabled workspace.
  • Cloud-hosted vs. private deployment.
  • Enabled features such as SSO, support, analytics, logging, and model routing.

For a deployment-specific list, contact legal@surgic.ai.

Contact