Last updated: 6 September 2026
Subprocessors
A subprocessor is a third-party service that may process customer data on Korrali's behalf. Korrali Revenue and Korrali Trust are separate products with separate customer data — the "Used by" column shows which product sends data to each subprocessor. We use the smallest set needed to operate each service. This page is the canonical list and is updated whenever it changes.
| Subprocessor | Used by | Purpose | Data category | Region |
|---|---|---|---|---|
| Amazon Web Services | Revenue & Trust | Application hosting, PostgreSQL database, object storage, backups | All customer data | United States (us-east-1) |
| Stripe | Revenue & Trust | Revenue: the billing account being monitored, connected via Stripe Connect (charges, invoices, subscriptions, customers). Both: payment processing for Korrali's own subscription billing. | Revenue: connected Stripe account data. Both: billing email, company name, payment method (handled by Stripe directly) | United States |
| Anthropic | Revenue & Trust | Large language model API (Claude) — primary model for answer generation and detection reasoning | Revenue: relevant Stripe billing data for a finding. Trust: knowledge base excerpts + questionnaire text. Sent at request time only | United States |
| OpenAI | Revenue & Trust | Fallback large language model API + text embeddings | Same categories as Anthropic, sent only if the primary model is unavailable | United States |
| Groq | Revenue | Large language model API used specifically for AI-drafted dunning emails | Relevant billing/invoice data needed to draft a dunning email, sent at request time only | United States |
| Resend | Revenue & Trust | Transactional email delivery (magic-link login, receipts, dunning emails) | Email addresses of account holders and, for Revenue, of billed customers receiving dunning emails | United States |
| PostHog | Revenue & Trust | Product analytics, error tracking | Pseudonymous usage events, error logs, approximate location | United States / European Union (cloud region) |
| Google (OAuth) | Revenue & Trust | Sign-in with Google option (not required) | Email, name, profile picture URL — only if user chooses Google sign-in | United States |
| Calendly | Korrali (umbrella) | Booking founder discovery calls | Email + name of caller, only if call is booked | United States |
Notifications of changes
When we add a new subprocessor or replace one that processes customer-uploaded or connected data (Stripe account data, KB, questionnaires, answers), we will notify active customers by email at least 14 days in advance. Operational subprocessors (e.g., analytics, billing) may be updated with shorter notice.
Contact
Questions about subprocessors: privacy@korrali.com.