Trust Center
Subprocessors.
We list every third party that processes Hub data. All subprocessors operate under a written Data Processing Agreement. Additions are announced 30 days in advance.
Current subprocessors
| Vendor | Service | Data categories | Hosted | DPA | Effective | Status |
|---|---|---|---|---|---|---|
Microsoft Azure | Cloud infrastructure | Hub configurationSeat identityBriefing contentFinancial metricsAudit logs | US East (Azure) | View DPA | Jan 1, 2026 | Active |
Anthropic | AI provider | Briefing section contextHub voice profileNCUA peer statisticsAI system prompts | US (via Azure AI Foundry) | View DPA | Jan 1, 2026 | Active |
Stripe | Payments | Billing contact name and emailPayment method tokensInvoice records | US | View DPA | Jan 1, 2026 | Active |
Amazon SES | Recipient email addressEmail subject and bodyDelivery metadata | US East (AWS) | View DPA | Jan 1, 2026 | Active | |
Sentry | Observability | Error traces (PII-scrubbed)Performance metricsSession replays (disabled by default) | US | View DPA | Jan 1, 2026 | Active |
30-day advance notice
HelmXP provides at least 30 days written notice before adding a new subprocessor that will process Hub data. Notice is sent to the hub administrator email on record. During the notice period, a hub may object by contacting privacy@helmxp.com. This page is updated at the time of announcement and reflects the current list at all times.
Questions about subprocessors
To object to a subprocessor addition, request a copy of a subprocessor DPA, or ask about data categories processed, contact privacy@helmxp.com.