AI Reserve Developer Documentation

Trust & Disclosures

Subprocessors

This page maintains the current list of Subprocessors engaged by Audacity Advisory Corp (operating as AI Reserve) to process Personal Data on behalf of clients, including their functions and jurisdictions, as referenced in Annex 5 of our Data Processing Addendum. It also identifies model providers that act as independent controllers rather than subprocessors, as the DPA requires. This page may be updated from time to time.

Last reviewed: September 14, 2026

Definitions


A Subprocessor is a third party engaged by AI Reserve to process Personal Data on our clients' behalf, acting only on our documented instructions.

Under our Data Processing Addendum, a provider that processes data for its own purposes — for example, a model provider whose terms permit it to train or fine-tune on inputs — is an independent controller, not a subprocessor. Such providers are identified separately in the Independent controllers section below. Requests are only sent to those providers when a user or client explicitly selects one of their models.

Per-provider detail on training, retention, and processing region is on the Provider Data Handling page.

Infrastructure & platform subprocessors


These providers support the operation of the AI Reserve platform itself and may process Personal Data in the course of providing their services.

Subprocessor Function Jurisdiction
Google Cloud Platform Cloud hosting, compute, databases, object storage, secret management, and logging for all AI Reserve services United States
Google Firebase Authentication Identity and sign-in for the AI Reserve portal (web application) United States
Auth0 by Okta OIDC identity brokering for keyless desktop-application sign-in (e.g. Claude Desktop) United States
Resend Transactional email delivery for the AI Reserve portal (onboarding invitations, password resets, account and allocation notifications, and internal operational reports). Receives recipient names, email addresses, and notification content — never prompt or response content United States
IPinfo IP geolocation and anonymizer screening for the machine API. Receives request IP addresses only — never request content United States
GDPRLocal Ltd. / Instant EU GDPR Representative Ltd Article 27 EU/UK representative (GDPR Article 27 and UK GDPR Article 27). Receives privacy requests submitted through its portal on our behalf — requester identity and request content only; never prompt or response content Ireland / United Kingdom
Slack Technologies (Salesforce) Slack Connect shared channels for customer communications, created from the AI Reserve admin console. For customer organizations that enable a Slack Connect channel, Slack receives the customer admin's email address (used to send the Slack Connect channel invite), a shared channel named for the customer organization, and the messages participants post in that shared channel — including, where the organization uses the @aireserve mention agent, prompts addressed to the agent and the model completions the agent posts back. Slack also receives operational alert payloads that may reference customer organization names. Content sent through the API directly does not transit Slack United States

Model providers acting as subprocessors


When a user or client selects a model, the request content is processed by the model's provider. The following providers process request data only to deliver inference, do not train on API inputs under their current enterprise terms, and act as subprocessors. A request is sent to the provider serving the model selected — no provider receives traffic for models it does not serve. If that provider fails or is saturated, the platform may retry the request through a disclosed failover chain containing only deployments of the identical model weights hosted by another subprocessor on this page (for example, Anthropic Claude models on AWS Bedrock). The platform default never substitutes a different model; cross-model entries exist only where a client administrator has explicitly configured them for their own organization, and models with no second same-weights host fail with the provider's real error. Every response served by a fallback is disclosed per response via the x-aireserve-served-model header. Failover never sends a request to a provider not listed on this page, and never to an independent controller unless a client administrator has explicitly configured that for their own organization. See provider failover on the Data Handling page.

Subprocessor Function Jurisdiction
OpenAI, L.L.C. Model inference (GPT model family; embeddings; image generation) United States
Anthropic, PBC Model inference (Claude model family, direct API) United States
Amazon Web Services (Bedrock) Model inference for -bedrock routed models (Anthropic Claude, Meta Llama, Mistral, DeepSeek serverless) — model publishers do not receive request data United States
Google Cloud (Vertex AI) Model inference for -vertex routed models (Anthropic Claude partner models in Vertex AI Model Garden) — the model publisher does not receive request data United States (us-east5)
Google (Gemini API) Model inference (Gemini model family; image generation), paid tier United States (processing may occur globally — see data handling)
xAI Corp. Model inference (Grok model family); text-to-speech and customer-created custom voices — organization-gated, off by default for every organization; when enabled, uploaded reference audio is processed by xAI and the resulting voice model is stored by xAI until deleted (see data handling) United States
Perplexity AI, Inc. Model inference with web search grounding (Sonar model family) United States
Together Computer, Inc. (Together AI) Hosted inference of open-weight models (e.g. Qwen, DeepSeek V4 Pro, Kimi K2.7, MiniMax, GPT-OSS-20B) United States
Fireworks AI, Inc. Hosted inference of open-weight models (e.g. GLM, Qwen, Kimi K2.6, DeepSeek V4 Flash, GPT-OSS-120B) United States
DeepInfra, Inc. Hosted inference of open-weight and partner models (NVIDIA Nemotron 3 family, DeepSeek V4 Flash, Qwen 3.8 Max) United States (Delaware corporation, HQ Palo Alto, CA; SOC 2 and ISO 27001 certified; US data centers plus one Canadian site — Toronto)
Novita AI Hosted inference of open-weight and partner models (DeepSeek V4 Flash, Qwen 3.8 Max) United States (San Francisco HQ; SOC 2 Type II audited; processing regions vary — see data handling)
Baseten, Inc. Hosted inference of open-weight models (DeepSeek V4 Flash family, GPT-OSS 120B) United States (San Francisco HQ; SOC 2 Type II audited and HIPAA compliant per trust center; serving region for our account — see data handling)
Alibaba Cloud (Model Studio) Model inference (first-party Qwen models — Qwen 3.8 Max, direct Model Studio API) United States (Virginia) for Qwen chat models (dashscope-us endpoint), except qwen-3-coder-next, which is served from Singapore (dashscope-intl endpoint — the only region offering that model, effective September 1, 2026); Singapore for Wan video generation and Qwen image generation (qwen-image-3.0 / qwen-image-3.0-pro, dashscope-intl endpoint); request data stored in the selected region. The operator is a PRC-headquartered group, so the platform labels these models China-based and serves them only to organizations that have not opted out of PRC-affiliated models — see data handling
MuleRouter (mulerouter.ai — CarrotHub / SmartStudio ecosystem) Hosted video generation for the Wan video model families (Wan 3.0 / W3.0, and Wan 2.7 image-to-video), served without upstream content moderation. Requests carry the video prompt and any customer-supplied media inputs — source/keyframe images (a source image is required by the Wan 2.7 image-to-video model), reference images, and reference/driving audio or video, passed by URL or inline — only for organizations that are expressly allowlisted for adult-content models, whose administrator has enabled adult-content serving, and whose caller has accepted the third-party model policy; these models are never publicly listed. MuleRouter's documentation states generated outputs belong entirely to the user. No training use, and tasks are deletable on request — confirmed in writing by the Alibaba Cloud International partner team (August 26, 2026; written vendor confirmation, not yet published terms); no published fixed deletion window — see data handling Singapore — confirmed in writing by the Alibaba Cloud International partner team (August 25, 2026); the operator is an Alibaba Cloud–partnered entity serving PRC-developed (Wan) models; the platform labels these models China-based and serves them only to organizations that have not opted out of PRC-affiliated models
WaveSpeedAI PTE. LTD. (wavespeed.ai) Hosted video extension and prompt-driven image editing for the Wan 2.7 family (video extension continues an existing customer-supplied video clip, guided by a prompt and optional driving audio; image editing makes targeted changes to one to nine customer-supplied reference images, guided by a prompt; all media passed by URL). Video extension serving since September 1, 2026 (launch gate enabled by a reviewed change); image editing added September 2026 on the same account and launch gate. Requests are served only for organizations that are expressly allowlisted for adult-content models, whose administrator has enabled adult-content serving and — while the retention terms below are pending — the unverified-retention consent, and whose caller has accepted the third-party model policy; these models are never publicly listed. Training, retention, and deletion terms pending verification — see data handling Singapore-incorporated operator (WaveSpeedAI PTE. LTD., per its published privacy policy); serving region and upstream affiliations pending verification — conservatively labeled China-affiliated until verified, and served only to organizations that have not opted out of PRC-affiliated models
Mistral AI (La Plateforme) Model inference (first-party Mistral models — mistral-medium-3.5, codestral-2508, ministral-14b — direct La Plateforme API) European Union — France-headquartered provider; La Plateforme runs on EU-based infrastructure by default; serving region for our account pending verification — see data handling
OpenRouter, Inc. Routing layer for certain open-weight model routes (Meta Llama, Mistral). OpenRouter itself does not store request content by default; the downstream serving endpoint's policy applies — per-route endpoints pending verification United States (routing); downstream endpoint varies
fal — Features & Labels, Inc. (fal.ai) Hosted video and image generation United States
GMI Cloud Hosted inference of open-weight serving legs (DeepSeek V3.2/V4 family, GLM 5.2/5.3/5.3 Flash, Kimi K2.6/K2.7 Code — api.gmi-serving.com). No API-content training or retention terms published pending verification — GMI Cloud-served models are locked for every organization until its administrator enables the data-retention consent gate in the AI Reserve console; see data handling United States (San Jose, CA company); serving region for our account pending verification
Tensormesh (serverless inference) Model inference (open-weight serving legs, serverless.tensormesh.ai). Retention and training-use terms pending verification — Tensormesh-served models are locked for every organization until its administrator enables the data-retention consent gate in the AI Reserve console; see data handling United States pending verification
ByteDance (BytePlus ModelArk) Hosted image (Seedream) and video (Seedance) generation via the international ModelArk API. PRC-headquartered operator — models are labeled China-based and served only to organizations that have enabled PRC-hosted models; terms pending verification — see data handling Singapore (BytePlus international, ap-southeast); operator headquartered in the PRC
StreamLake (Kuaishou "Vanchin" international platform) Model inference (open-weight -streamlake serving legs, vanchin.streamlake.ai). StreamLake's international ToS (§4.6) license it to use inputs and outputs for model training with no published opt-out, and its parent Kuaishou is PRC-headquartered — StreamLake-served models are locked for every organization until its administrator enables both the PRC-hosted-models opt-in and the training consent gate in the AI Reserve console; see data handling Singapore (stated data-storage location); operator's parent headquartered in the PRC; inference hosting location unstated
Hugging Face, Inc. (Inference Endpoints) Dedicated GPU inference endpoints that enterprise administrators deploy one-click from the AI Reserve console (open-weight models, e.g. Meta Llama, Mistral, Qwen, Phi, Gemma, BGE embeddings). Endpoints are provisioned under AI Reserve's Hugging Face organization as token-protected, single-tenant deployments and process the prompts and completions sent to them; they receive traffic only for the organization that deployed them, are billed hourly at Hugging Face list price from that organization's wallet, and are separate from gateway chat routing — see data handling United States (New York HQ; endpoints in the current catalog provision on AWS us-east-1)

Model providers acting as independent controllers


The following model providers' current terms permit them to process request data for their own purposes (including using inputs to train or improve their services). Under our DPA they are therefore independent controllers, not subprocessors, and are identified as such. Requests reach these providers only when the organization's administrator has enabled the training consent gate in the AI Reserve console and a user or client explicitly selects one of their directly-served models — as the requested model, or as an entry the client's own administrator explicitly configured in that organization's fallback chain (chain entries hosted in the PRC are excluded for organizations that have opted out of PRC-hosted models, and every fallback serve is disclosed via the x-aireserve-served-model header). Absent that consent, these providers' models are locked for the organization — greyed out in the catalog and refused at the gateway. Open-weight DeepSeek, Moonshot, Qwen, and NVIDIA Nemotron models served by US aggregators (Fireworks, Together, DeepInfra, Novita) or AWS Bedrock do not send data to these companies — nor, for the Qwen serving variants, to Alibaba Cloud.

Provider Function Jurisdiction Why independent controller
Hangzhou DeepSeek Artificial Intelligence Co., Ltd. Model inference, direct DeepSeek API (deepseek-chat, deepseek-reasoner) China (PRC) — data collected, processed, and stored on servers in the PRC Privacy policy states inputs are used to train and improve its models and services
Moonshot AI (Kimi) Model inference, Moonshot's own API (kimi-k3, moonshot-v1-*) China (PRC-headquartered). International platform terms state Singapore-located servers; endpoint serving our account pending verification Platform privacy policy states user content is used to train and refine its models
NVIDIA Corporation (hosted NIM API catalog)
Opt-in only — organization training consent required
Model inference (Nemotron model family) — only via the separate, clearly-labeled NVIDIA-served options (nemotron-3-super-nvidia, nemotron-3-ultra-nvidia; a third option, nemotron-3-nano-nvidia, was retired by NVIDIA effective August 28, 2026), re-added behind the training consent gate on August 14, 2026. The default Nemotron models (nemotron-3-super, nemotron-3-nano, nemotron-3-ultra) route to DeepInfra under its no-training terms (see Subprocessors above) and never touch NVIDIA — between August 10 and August 14, 2026 no NVIDIA-served options existed at all, and no traffic reaches NVIDIA unless an administrator has opted the organization in. United States Published API-catalog trial terms permit NVIDIA to use inputs/outputs to improve its products and services, including AI models — NVIDIA-served options are therefore locked by default for every organization and exist only behind an organization administrator's explicit training consent.

Other service providers


Data enrichment (Harmonic). The platform's business-data features use a company-data enrichment provider that receives only public company identifiers (such as company names and website domains) — never client request content, prompts, completions, or personal data of client users.

Updates to this list


This list is maintained on the Platform per Annex 5 of our Data Processing Addendum and is reviewed periodically. When we engage a new subprocessor that will process Personal Data, we update this page and provide any notice required by the DPA. Items marked pending verification reflect characteristics we have not yet confirmed from official documentation — confirm before relying on them.

Questions about this list or our DPA: contact product@aireserve.com.