Pre-launch counsel-review draft
Subprocessors and other recipients
The eight-provider set declared by the product architecture, with the purpose and data boundary for each provider and a clear M28 activation gate.
Professional legal review required before publication
This draft is not effective, has not been approved by counsel, and is not legal advice. Bracketed decisions and review markers must be resolved before publication.
- Effective date
- To be set after professional legal approval
- Last revised
- To be set after professional legal approval
- Draft record
- M27 counsel-review draft 1, prepared August 27, 2026
Pre-launch status and scope
This page identifies the eight providers currently declared for the NoirGen Agent QA production design. It does not claim that any provider is processing production customer data today. Live production confirmation remains pending the separately approved M28 deployment and recovery milestone.
A provider's inclusion describes an intended service purpose and potential data flow. It does not establish that a contract, data-processing addendum, region, account setting, retention option, transfer mechanism, or production integration has been completed.
Eight planned production providers
Google Cloud
Planned — M28 confirmation pending- Purpose
- Planned production hosting, database, private storage, task delivery, scheduling, secrets, load balancing, logging, and monitoring.
- Data boundary
- Account, organization, customer-content, encrypted-credential, usage, operational, upload, and backup data as required by the enabled Google Cloud services.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
Cloudflare
Planned — M28 confirmation pending- Purpose
- Planned authoritative DNS, reverse proxy, TLS, web-application firewall, rate, and cache controls.
- Data boundary
- Network, device, request-routing, security-event, and request data necessary to proxy and protect traffic.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
OpenAI
Planned — M28 confirmation pending- Purpose
- Responses API test-draft generation and model-assisted evaluation when those modes are enabled.
- Data boundary
- Selected knowledge excerpts, test definitions, customer-agent responses, rubrics, and related evaluation inputs. Connector credentials are excluded. Requests set store to false, which is not a zero-retention representation.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
Stripe
Planned — M28 confirmation pending- Purpose
- Hosted Checkout, subscription management, invoices, payment methods, and billing lifecycle.
- Data boundary
- Billing contact, customer, subscription, invoice, payment, and transaction data. Payment-card details are collected on Stripe-hosted surfaces rather than by the application.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
Resend
Planned — M28 confirmation pending- Purpose
- Passwordless authentication email and transactional alert delivery.
- Data boundary
- Email address, authentication-link content, and bounded transactional alert content.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
PostHog
Planned — M28 confirmation pending- Purpose
- Server-side product analytics with person profiles and GeoIP disabled.
- Data boundary
- Pseudonymous user and organization identifiers plus an allowlisted set of bounded product-event metadata. Customer prompts, responses, knowledge, credentials, email addresses, and Stripe identifiers are excluded by the application contract.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
Sentry
Planned — M28 confirmation pending- Purpose
- Application error monitoring and diagnostics.
- Data boundary
- Scrubbed error, stack-location, trace, correlation, and allowlisted diagnostic metadata. Request bodies, cookies, headers, user objects, database values, and generative-AI inputs and outputs are disabled or removed by the application contract.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
Zoho Mail
Planned — M28 confirmation pending- Purpose
- Mailbox service for [email protected]; mailbox activation, monitoring, retention, and response targets require owner verification before launch.
- Data boundary
- Support-contact email address, message content, attachments, and mail-delivery metadata supplied by the sender.
- Activation status
- Declared in the production design; live account, configuration, and data-flow verification remain pending M28.
Other recipients are not represented as subprocessors
The following destinations can receive information through a user choice or a customer's configuration. They are listed separately so this draft does not inaccurately represent a customer-controlled destination as a NoirGen subprocessor.
Google OAuth
- Relationship and purpose
- Optional third-party sign-in. The user's relationship with Google is also governed by Google's terms and privacy notice.
- Data involved
- Profile and authentication information selected by the user and OAuth account/session tokens stored by the application.
Customer-configured agent endpoint
- Relationship and purpose
- A customer-directed destination used to execute tests. It is selected and controlled by the customer and is not represented as a NoirGen subprocessor.
- Data involved
- Test prompts, configured authorization headers, request templates, and the data returned by the endpoint.
Customers should review the privacy, security, authorization, and retention terms for their own agent endpoint. A configured endpoint receives the prompts, authorization headers, and request template needed to execute the test, and returns response data to the application.
What M28 must confirm
Before this list can be treated as a current production register, M28 must verify:
- the provider accounts, legal entities, products, regions, and enabled features;
- the exact production hostnames, projects, domains, keys, and service integrations;
- that Google Cloud, Cloudflare, OpenAI, Stripe, Resend, PostHog, Sentry, and Zoho Mail are configured only for the documented purposes and data boundaries;
- that the live Stripe configuration and catalog behavior match the approved billing terms; the application supports fail-closed live mode, but repository support is not live-provider evidence;
- that the Resend sending domain and Zoho support mailbox are active and do not conflict;
- that hosted telemetry receives only the application's allowlisted, privacy-filtered data;
- applicable provider retention, data-residency, transfer, deletion, and incident-notice settings; and
- the final privacy policy, security page, and customer contract match that readback.
The current store: false OpenAI request setting is a request-level control, not a representation of zero retention. Likewise, staged infrastructure declarations and local provider fixtures do not prove that a hosted service is active.
Provider changes and customer notice
The repository does not yet define a contractual advance-notice period, objection process, emergency-replacement procedure, or archival register for provider changes. No notice period should be inferred from this draft.
Related handling details appear in the Privacy Policy and the Security page.
Questions about providers
Questions may be sent to [email protected]. Do not send passwords, API keys, connector credentials, session tokens, or payment-card details. The support mailbox's activation, monitoring, retention, and response target still require owner verification before launch.