The Vendors Behind Aeion. Every One. Always Current.
Every sub-processor Aeion uses to deliver the platform — with location, purpose, DPA / BAA status, and pending changes. Customers get at least 30 days advance notice before any new sub-processor begins processing their data; the notice fires through your configured Aegis notification channels (email, Slack, webhook) and the admin-UI banner. This page is updated in lockstep with the platform's internal sub-processor change log.
Pending & Recent Changes
Sub-processor changes are announced here at least 30 days before they take effect. Changes of type "removed" may take effect immediately (when a vendor offboards without notice); changes of type "added" or "modified" are always at least 30 days out. The list below is the current state — for a snapshot at any point in time, contact legal@aeionos.com with the date you need.
Cloud Infrastructure (always present)
Cloudflare (US / Global)
DNS, CDN, DDoS protection. DPA in place. Active on every tenant.
Hetzner (Germany / Finland)
VPS hosting for EU-region tenants. DPA in place.
Contabo (Germany / US)
VPS hosting for cost-optimized tenants. DPA in place.
AWS (US / EU / multi-region)
Storage backbone, Aegis backup tier, AI inference via Bedrock. DPA in place; BAA available for HIPAA tenants.
Payment Processing (when commerce or billing is used)
Stripe (US / Global)
Card payment processing. DPA in place. Customer's own Stripe account.
Adyen (Netherlands / Global)
Alternative payment processor for Enterprise tenants. DPA in place.
AI Providers (when AI module is used)
OpenAI (US)
GPT family, DALL-E, Whisper. DPA in place. Opt-out from training applied per organization.
Anthropic (US)
Claude family. DPA in place. No training on customer data.
Google Cloud (US / EU)
Gemini family, Cloud Translation. DPA in place. HIPAA-aligned inference via Vertex available.
AWS Bedrock (US / Global)
BAA-signed AI inference for HIPAA tenants. Foundation models from Anthropic, AI21, Cohere, Meta, Mistral, Amazon.
Microsoft Azure OpenAI (US / EU)
GPT family with HIPAA-eligible BAA. Used when a tenant prefers Microsoft's compliance posture.
AWS Transcribe Medical (US)
Medical-grade speech-to-text for healthcare tenants. BAA-signed.
Plus 50+ additional AI providers
Invoked only when the tenant configures their own credentials. Full list in the admin UI under Account → AI Providers.
Communications (when notifications, marketing, or connect modules are used)
SendGrid, a Twilio product (US / Global)
Transactional and marketing email. DPA in place. BYO-account supported.
Twilio (US / Global)
SMS, voice, conversational messaging. DPA in place. BYO-account supported.
OneSignal (US / Global)
Push notifications for mobile and web. DPA in place.
AWS SES (US / EU / multi-region)
Alternative email delivery. DPA in place. BYO-account supported.
Monitoring & Observability
Sentry (US)
Error tracking. DPA in place. PII scrubbing enabled at the SDK layer.
Datadog (US / EU / multi-region)
APM and infrastructure metrics. DPA in place. Customer-data-free by configuration.
Compliance & Legal
DocuSign (US)
E-signature for legal documents (BAAs, DPAs, MSAs, sub-processor consent forms). DPA in place.
Specialty (only when specific modules are used)
LiveKit (US / global edge or self-hosted)
WebRTC infrastructure for `/platform/realtime`. DPA in place if managed by Aeion; tenant DPA applies if self-hosted.
pgBackRest (open-source library, no external party)
Aegis PITR. No data leaves your tenant's environment. Listed here for transparency, not because it processes PHI on a third party's infrastructure.
How the 30-Day Advance Notice Works
The policy commitment isn't aspirational — it's enforced by the platform itself.
Frequently Asked Questions
The list above is a snapshot of the platform's internal sub-processor change log. When operators announce a new sub-processor or modify an existing one, the change is recorded in a system the platform validates against the 30-day rule, then fanned out to every tenant. This page reflects the resulting state.
Yes — sub-processor change notifications fire through the Aegis notification system you configure on your tenant. Set up email / Slack / webhook destinations under Settings → Notifications → Aegis in the admin UI. You can also email `legal@aeionos.com` with "subscribe to sub-processor notifications" and we'll add you to the change-notification email list outside the admin UI.
Any third party that may process customer data on Aeion's behalf. Includes infrastructure (compute, storage, CDN), AI inference, payment processing, communications (email / SMS / push), monitoring, and compliance tooling. Does NOT include open-source libraries running entirely within Aeion's environment — those are listed under "Specialty" for transparency but not for compliance purposes.
A DPA (Data Processing Agreement) is the GDPR Article 28 contract between a controller (you) and a processor (the sub-processor). A BAA (Business Associate Agreement) is the HIPAA-specific contract that extends similar protections to Protected Health Information. Some sub-processors have both; some have only DPA; some don't process PHI and need only DPA.
No, with one nuance: when a tenant configures their own credentials for a vendor (e.g., bringing their own OpenAI account or their own SendGrid account), that vendor's relationship is between the tenant and the vendor — not between Aeion and the vendor. Aeion is the platform routing data on the tenant's behalf; the tenant is the data controller and the vendor is their direct processor. This is why the list above has "BYO-account supported" notes — those are still sub-processors from Aeion's perspective, just with simpler contractual posture because the tenant has the direct relationship.
Aeion's sub-processor list has been stable since the last expansion. We add new vendors only when a business need requires them (new module, new region, new compliance posture). When the next addition is announced, the "Pending & Recent Changes" section above will populate.
Yes — email `legal@aeionos.com` with the date you need. Audit history is permanent in the platform's change log.
You have until the effective date to send a written objection to `legal@aeionos.com`. Aeion's legal team reviews and either (a) configures the platform to route around the sub-processor for your tenant (if technically feasible), (b) negotiates an alternative sub-processor for your contractual scope, or (c) refunds the prorated subscription fee for the remainder of your term. Most objections are resolved via (a) or (b).