We publish every third-party service that processes customer data on our behalf. Material changes (additions, removals, replacement) are announced 30 days in advance via the changelog. Subscribe to changelog RSS to get the heads-up automatically.
How this list is maintained
- Cadence: Reviewed quarterly + on every infrastructure change.
- Last review: May 19, 2026.
- Next review: August 19, 2026.
- Source of truth: the SaaS console at
/saas/sub-processors(root-only).
If a sub-processor you require isn’t here, contact legal@heliosworks.com — for Enterprise tier we’ll work with you on the contract change.
Sub-processors in active use
| Sub-processor | Country | Purpose | Contract |
|---|---|---|---|
| Cloudflare | US / Global | CDN, DDoS protection, R2 object storage | DPA + SCCs |
| AWS (S3, RDS-compatible) | Region per tenant | Object storage, Postgres hosting | DPA + SCCs |
| Anthropic | US | AI inference (default LLM provider) | DPA |
| OpenAI | US | AI inference (alternate per tenant) | DPA |
| Google Gemini | US | AI inference (alternate per tenant) | DPA |
| Postmark | US | Default outbound email provider | DPA + SCCs |
| Amazon SES | Region per tenant | Alternate outbound email provider | DPA + SCCs |
| Resend | US | Alternate outbound email provider | DPA + SCCs |
| Mailgun | US / EU | Alternate outbound email provider | DPA + SCCs |
| Plausible Analytics | EU (Germany) | Privacy-preserving website analytics | DPA |
| Sentry | US | Application error tracking | DPA + SCCs |
| Inngest | US | Background-job orchestration | DPA + SCCs |
| Cloudflare Turnstile | US / Global | Bot mitigation on forms | DPA |
| Better-Auth (self-hosted) | n/a | Authentication library | not a processor |
| Stripe (when Payment Gateway enabled) | US / Region | Subscription billing for SaaS tenants who buy Helios | DPA + SCCs |
Per-tenant configurable
Some sub-processors are selected per tenant in the SaaS console. The default is conservative; tenants can switch to a provider in their region for compliance reasons:
- Outbound email provider: Postmark (default) / SES / Resend / Mailgun.
- LLM provider per use-case: Anthropic / OpenAI / Google Gemini (per use-case routing).
- Object storage region: US / EU / APAC depending on the AWS region selected.
Removed in the last 12 months
(None yet — this is the inaugural list.)
Customer rights
You may object to the addition of a new sub-processor by emailing legal@heliosworks.com within the 30-day notice window. Per Section 11 of the DPA, the resolution path is:
- We discuss alternative measures.
- If no measures can address your concern, you may terminate the affected portion of the service for material breach of the DPA, with a refund pro-rated to the date of termination.
Contact
- Legal questions: legal@heliosworks.com
- Security questions: security@heliosworks.com
- Subscribe to changelog RSS to be alerted to changes.