The Vendors Behind Aeion. Every One. Always Current.

Every sub-processor Aeion uses to deliver the platform — with location, purpose, DPA / BAA status, and pending changes. Customers get at least 30 days advance notice before any new sub-processor begins processing their data; the notice fires through your configured Aegis notification channels (email, Slack, webhook) and the admin-UI banner. This page is updated in lockstep with the platform's internal sub-processor change log.

30-day advance notice before any new sub-processor activation
Enforced at the platform layer — back-dating is rejected
Notice fans out per-tenant via email, Slack, webhook + in-product banner
Every sub-processor with location and BAA / DPA status
Public read · no signup or NDA required
Updated within 24 hours of any internal change record
Right to object on Enterprise · prorated refund if no alternative
Vendor offboarding is reflected the same day

Pending & Recent Changes

Sub-processor changes are announced here at least 30 days before they take effect. Changes of type "removed" may take effect immediately (when a vendor offboards without notice); changes of type "added" or "modified" are always at least 30 days out. The list below is the current state — for a snapshot at any point in time, contact legal@aeionos.com with the date you need.

Cloud Infrastructure (always present)

Cloudflare (US / Global)

DNS, CDN, DDoS protection. DPA in place. Active on every tenant.

Hetzner (Germany / Finland)

VPS hosting for EU-region tenants. DPA in place.

Contabo (Germany / US)

VPS hosting for cost-optimized tenants. DPA in place.

AWS (US / EU / multi-region)

Storage backbone, Aegis backup tier, AI inference via Bedrock. DPA in place; BAA available for HIPAA tenants.

Payment Processing (when commerce or billing is used)

Stripe (US / Global)

Card payment processing. DPA in place. Customer's own Stripe account.

Adyen (Netherlands / Global)

Alternative payment processor for Enterprise tenants. DPA in place.

AI Providers (when AI module is used)

OpenAI (US)

GPT family, DALL-E, Whisper. DPA in place. Opt-out from training applied per organization.

Anthropic (US)

Claude family. DPA in place. No training on customer data.

Google Cloud (US / EU)

Gemini family, Cloud Translation. DPA in place. HIPAA-aligned inference via Vertex available.

AWS Bedrock (US / Global)

BAA-signed AI inference for HIPAA tenants. Foundation models from Anthropic, AI21, Cohere, Meta, Mistral, Amazon.

Microsoft Azure OpenAI (US / EU)

GPT family with HIPAA-eligible BAA. Used when a tenant prefers Microsoft's compliance posture.

AWS Transcribe Medical (US)

Medical-grade speech-to-text for healthcare tenants. BAA-signed.

Plus 50+ additional AI providers

Invoked only when the tenant configures their own credentials. Full list in the admin UI under Account → AI Providers.

Communications (when notifications, marketing, or connect modules are used)

SendGrid, a Twilio product (US / Global)

Transactional and marketing email. DPA in place. BYO-account supported.

Twilio (US / Global)

SMS, voice, conversational messaging. DPA in place. BYO-account supported.

OneSignal (US / Global)

Push notifications for mobile and web. DPA in place.

AWS SES (US / EU / multi-region)

Alternative email delivery. DPA in place. BYO-account supported.

Monitoring & Observability

Sentry (US)

Error tracking. DPA in place. PII scrubbing enabled at the SDK layer.

Datadog (US / EU / multi-region)

APM and infrastructure metrics. DPA in place. Customer-data-free by configuration.

Compliance & Legal

DocuSign (US)

E-signature for legal documents (BAAs, DPAs, MSAs, sub-processor consent forms). DPA in place.

Specialty (only when specific modules are used)

LiveKit (US / global edge or self-hosted)

WebRTC infrastructure for `/platform/realtime`. DPA in place if managed by Aeion; tenant DPA applies if self-hosted.

pgBackRest (open-source library, no external party)

Aegis PITR. No data leaves your tenant's environment. Listed here for transparency, not because it processes PHI on a third party's infrastructure.

How the 30-Day Advance Notice Works

The policy commitment isn't aspirational — it's enforced by the platform itself.

Frequently Asked Questions

The list above is a snapshot of the platform's internal sub-processor change log. When operators announce a new sub-processor or modify an existing one, the change is recorded in a system the platform validates against the 30-day rule, then fanned out to every tenant. This page reflects the resulting state.

Yes — sub-processor change notifications fire through the Aegis notification system you configure on your tenant. Set up email / Slack / webhook destinations under Settings → Notifications → Aegis in the admin UI. You can also email `legal@aeionos.com` with "subscribe to sub-processor notifications" and we'll add you to the change-notification email list outside the admin UI.

Any third party that may process customer data on Aeion's behalf. Includes infrastructure (compute, storage, CDN), AI inference, payment processing, communications (email / SMS / push), monitoring, and compliance tooling. Does NOT include open-source libraries running entirely within Aeion's environment — those are listed under "Specialty" for transparency but not for compliance purposes.

A DPA (Data Processing Agreement) is the GDPR Article 28 contract between a controller (you) and a processor (the sub-processor). A BAA (Business Associate Agreement) is the HIPAA-specific contract that extends similar protections to Protected Health Information. Some sub-processors have both; some have only DPA; some don't process PHI and need only DPA.

No, with one nuance: when a tenant configures their own credentials for a vendor (e.g., bringing their own OpenAI account or their own SendGrid account), that vendor's relationship is between the tenant and the vendor — not between Aeion and the vendor. Aeion is the platform routing data on the tenant's behalf; the tenant is the data controller and the vendor is their direct processor. This is why the list above has "BYO-account supported" notes — those are still sub-processors from Aeion's perspective, just with simpler contractual posture because the tenant has the direct relationship.

Aeion's sub-processor list has been stable since the last expansion. We add new vendors only when a business need requires them (new module, new region, new compliance posture). When the next addition is announced, the "Pending & Recent Changes" section above will populate.

Yes — email `legal@aeionos.com` with the date you need. Audit history is permanent in the platform's change log.

You have until the effective date to send a written objection to `legal@aeionos.com`. Aeion's legal team reviews and either (a) configures the platform to route around the sub-processor for your tenant (if technically feasible), (b) negotiates an alternative sub-processor for your contractual scope, or (c) refunds the prorated subscription fee for the remainder of your term. Most objections are resolved via (a) or (b).