Krites

Subprocessors

Last updated 21 September 2026

Third-party services that process customer data in the unbilled pilot today. This list is not a DPA schedule. Payment processing is not listed because the pilot is unbilled and no payment processor handles customer data.

Railway
Application hosting and compute

All request traffic in transit; application logs containing metadata only.

Supabase (managed PostgreSQL)
Primary database

Accounts, enterprise and team records, usage and cost metadata, audit logs, and readable chat content (messages, responses, uploaded files) retained for your enterprise retention window — default 365 days.

Used only as managed Postgres. No Supabase Auth, Storage, Realtime or Edge Functions.

OpenRouter
The active model-routing path — forwards each request to the underlying inference provider it selects

Prompt and response content for requests routed through it.

Every request sends provider.data_collection: "deny", which excludes endpoints that train on or retain your content. Zero Data Retention is additionally required when your enterprise enables it.

DeepSeek
Model inference — a provider currently reached through OpenRouter for routine requests

Prompt and response content for requests routed to its models.

Reached via OpenRouter under the data_collection: "deny" setting above; other providers may be selected by OpenRouter per request.

Anthropic
Model inference (Claude models)

Prompt and response content for requests routed to Claude models.

Currently reached only through OpenRouter. The direct Anthropic path is enabled only when an Anthropic API key is configured for the deployment, which is not the case in the current pilot.

Tavily
Web search, when that feature is used

A search query derived from the user prompt, and returned result snippets. The full conversation is not sent.

Used only when external-data tools / web search are enabled for the enterprise and the request. Ordinary chat turns that do not search do not send data to Tavily. Provider Zero Data Retention does not cover Tavily; search text leaves Krites to api.tavily.com under Tavily's own retention. The search string can include sensitive wording from the prompt.

Resend
Transactional email (account setup, invitations)

Recipient email address and the message body, which contains a single-use link.

WorkOS
Enterprise single sign-on, when an organization configures SSO

Work email, identity-provider subject identifiers, and organization membership used to sign the person in.

Used only when enterprise SSO is configured. Krites mints its own session cookie after a successful handshake; WorkOS sealed sessions are not used. Directory sync (SCIM) is not enabled.

Calendly
Demo scheduling on the public marketing site

Name, email address and the chosen meeting time of a visitor who books a demo; Calendly then issues the calendar invite and Google Meet link.

Marketing-site visitors only. Never receives any customer workspace content, prompts, or usage data.

Changes

We update this list when a subprocessor is added or removed. There is no published advance-notice period or customer objection process until counsel supplies one.

Questions: [email protected].