Legal

Policies governing use of the CATO platform

Subprocessors and Service Providers

Last reviewed July 21, 2026

Nyrus Corp. uses the providers below to operate CATO. Some providers act as processors or service providers for customer data. Others, such as Stripe for certain payment and fraud functions, may also act as independent controllers under applicable law.

A vendor data processing agreement governs the relationship between Nyrus and that provider. It does not make a CATO user a party to the vendor agreement and does not mean that every provider has zero retention. See the Data Processing page for a plain-language explanation.

ProviderFunctionData receivedRetention postureProcessing locationDPASubprocessor listChange notifications
Fireworks AIStandard AI inference, daily memory maintenance, and selected scientific helper operationsPrompts, relevant conversation and tool context, human-readable conversation excerpts used for memory maintenance, model outputs, and request metadataReviewed Chat Completions paths are documented as zero data retention by default. Daily memory maintenance uses transient Batch API input and output datasets that CATO deletes after ingestion or terminal job handling. Service metadata and documented security or legal exceptions may remain.United States and locations used by listed subprocessorsDPADPA schedulesContract, account, and provider notice channels
AnthropicResearch-mode inference and selected literature, reviewer, and coding operationsPrompts, relevant conversation and tool evidence, generated code, and model outputsCommercial API inputs and outputs are generally deleted within 30 days, subject to documented safety, legal, and separately configured retention exceptions. No training by default.United States and locations used by listed subprocessorsDPATrust CenterSubscribe through the Anthropic Trust Center where available
RailwayApplication hosting, PostgreSQL metadata, Redis cache and stream replay, Temporal workflow state, service logs, and transient trajectory delivery spoolingAccounts, conversation and project metadata, workflow and stream state, transient trajectory events, and technical logs. Railway is not the authoritative object store for user files or trajectories.Retained while needed to provide CATO and removed through CATO deletion, ephemeral-storage, account-termination, and backup processes, subject to legal exceptions.Primarily United States; configured service regions and provider subprocessorsDPASubprocessor listRailway notice mechanism and email; DPA provides advance notice for changes
Google CloudAuthoritative user-file and project-artifact object storage, separate operational and training-approved trajectory stores, isolated scientific sandbox execution, container registry, and infrastructureUploaded files, project artifacts, operational and approved trajectory records, user-selected analysis inputs, generated code, execution results, and infrastructure metadataControlled by separate Nyrus identities, storage lifecycle rules, sandbox workload cleanup, logging settings, and Google Cloud contractual deletion processes.United States; CATO sandbox infrastructure is currently configured in us-central1Cloud DPASubprocessorsGoogle Cloud contractual and account notice channels
SentryError and performance monitoringSanitized exceptions, stack and route data, release information, performance data, and opaque account identifiersEvents follow the configured Sentry retention period. CATO disables request bodies, session replay, contact details, default PII, and application logs.United States and other locations identified by Sentry and its subprocessorsDPASubprocessorsSubscribe to Sentry legal and subprocessor updates
StripeSubscriptions, payments, fraud prevention, and metered billingContact and billing data, Stripe customer ID, subscription and invoice state, payment records, and numeric usage quantitiesTransaction, fraud, tax, and compliance records are retained according to Stripe legal and operational requirements. CATO does not send prompts or datasets.Global processing needed for payment, fraud, and financial servicesDPAService providersSubscribe through Stripe service-provider notification options
ResendTransactional and support email deliverySender and recipient addresses, subject, message content, and delivery eventsEmail data is generally retained for 30 days, with account, security, and legal exceptions. CATO does not place research content in routine email.United States and locations used by listed subprocessorsDPASubprocessorsProvider notices; the DPA provides advance notice for subprocessor changes

Storage and sandbox boundaries

Google Cloud is the authoritative object store for user files, project artifacts, operational trajectories, and training-approved trajectories. Railway hosts application and workflow services and may hold a transient trajectory delivery spool, but it is not the authoritative store for those objects. Operational and training-approved trajectories use separate storage and identities. A restricted cleaning and approval pipeline must create an approved copy before the training identity can read it.

A trusted controller stages required files into a temporary sandbox workspace. Sandbox pods receive no cloud-storage credentials, application secrets, or mounted object storage, and the staged copy is removed during sandbox cleanup. Raw uploaded files are not automatically copied wholesale into trajectories, although excerpts and tool outputs surfaced to the agent may be.

Public research services

Public literature, trial, patent, protein, pathway, chemical, and biomedical databases are external data sources rather than ordinary contracted CATO subprocessors. CATO may transmit search terms, public identifiers, filters, sequences, or structures needed for a requested lookup. Do not include personal or confidential information in those queries.

Changes

Nyrus reviews this list at least quarterly and before enabling a provider that will receive production user data. Material changes will be reflected here and communicated when required by applicable law or contract. Questions or objections may be sent to contact@nyrus.ai.