KKnown
Legal

Subprocessors

Known uses a small set of third-party subprocessors to deliver its services. We publish this list so our customers know exactly who touches their data. We never sell customer data, and we do not share customer data with any other Known customer.

Last updated: 2026-08-24

Active subprocessors

These vendors are in the production data path. Most are covered by a Data Processing Addendum governing how they may handle your data — in most cases the vendor’s published DPA, incorporated into the terms we accepted. Where that paperwork is still outstanding the row says so in its status, rather than the exception being left for you to find.

Anthropic, PBCUnited States
DPA active

Role: LLM provider for AI synthesis — customer email and transcript content is sent to the Anthropic API to produce the structured account records, stakeholder notes, sentiment signals, and commitment extractions shown in the product. Additionally, when you reach your data through an AI assistant (the MCP connector), the facts we retrieve for your question are delivered to that assistant so it can compose the answer.

Data accessed: Customer email content; transcript content; CRM event excerpts. Anthropic does not train its public models on data sent via the API.

Google LLCUnited States
Customer-granted

Role: The source systems Known reads from under the OAuth scopes the customer grants — Gmail API for email, Drive API for Meet transcripts, and OAuth identity for SSO authentication.

Data accessed: Customer email content; transcript content; user identity claims. Covered by the Google Workspace data-processing agreement that the customer maintains with Google as the controller.

Cloudflare, Inc.United States
DPA active

Role: Authoritative DNS for the knownintel.com domain, and the hosting of the public marketing website. Cloudflare answers the question "what address is app.knownintel.com?" — it does not carry the request that follows. The application itself runs on Google Cloud (see below).

Data accessed: None. The application hostnames resolve directly to Google Cloud, so customer data does not pass through Cloudflare. What Cloudflare sees is domain-name lookups, and the public marketing pages, which carry no customer data.

Google Cloud Platform (Google LLC)United States
Active — DPA not yet executed

Role: The infrastructure Known itself runs on. Cloud Run hosts the Known web application, its API, its scheduled jobs, and the AI-assistant connector; Cloud SQL and Secret Manager hold the production database and the keys that protect it. Known contracts with Google directly for this, which makes it a different relationship from the Google LLC entry above, where your own Gmail and Drive are your source systems under your own Google agreement. The two are easy to confuse and are not the same thing.

Data accessed: All customer data classes — email content, transcript content, CRM events, everything Known synthesizes from them, and the access log — are processed and rest here.

ResendUnited States
DPA active

Role: Transactional email delivery — invitation links for external recipients and the one-time codes used to sign in.

Data accessed: Recipient email addresses; one-time sign-in codes; single-use invitation links. No email or transcript content.

Stripe, Inc.United States
Disclosed — not yet processing

Role: Subscription billing. Payment is taken on a page hosted by Stripe — your card details go to Stripe directly and never pass through, or rest on, Known systems.

Data accessed: Billing identity and payment method — name, email address, card details (held by Stripe), billing address, and the subscription record. No email content, transcript content, CRM data, or anything Known synthesizes from them.

GitHub, Inc.Microsoft · United States
DPA active

Role: Two distinct roles. (1) Our own source-code hosting and private vulnerability reporting — listed for transparency. (2) If you connect a GitHub repository, Known reads that repository through your own OAuth grant and can create issues in it on your instruction.

Data accessed: Our source code and security reports. Additionally, for customers who connect a repository: repository contents read under your grant, and the text of any issue Known creates at your request. Connecting is optional and off unless you do it.

Pending — not yet in the production data path

Each entry below is either a category that still needs a vendor, or a vendor that has been selected but has not begun processing customer data. No production customer data is processed by anything in this section while it remains here; a vendor moves up to Active above when it enters the data path, and its row there states whether its DPA is executed. Where a vendor is already named, listing it here is the disclosure that starts the 30-day notice period described below — we publish the decision when we make it, not when we cut over.

Google Cloud Speech-to-Text — transcriptionPending

Server-side transcription of meeting and call audio, using Google Cloud Speech-to-Text. As with the Google Cloud Platform entry in the active list above, Known contracts with Google directly for this. Not live: the transcription route is disabled until the agreement and credentials are in place.

Vendor: Google Cloud Speech-to-Text (Google LLC)

Monitoring & error trackingPending

Receives operational telemetry and error traces. PII is filtered at the source.

Candidates: Sentry, Datadog, self-hosted OpenTelemetry

SMS / OTP deliveryPending

Delivers one-time passcodes for the optional second factor on magic-link invites.

Candidates: Twilio, AWS SNS

Subprocessor change process

When Known adds or replaces a subprocessor, existing customers are notified at least 30 days before the new subprocessor begins processing customer data, as required by the subprocessor-change clause of our Data Processing Addendum.

The notification gives customers the opportunity to object on reasonable data-protection grounds. If Known cannot accommodate the objection, the customer may terminate the affected service under the termination clause of their agreement.

Questions

For questions about our subprocessor list, data processing practices, or to request a copy of our Data Processing Addendum, contact us at hello@knownintel.com.