Subprocessors and Service Providers
Last reviewed September 20, 2026
Nyrus Corp. uses the providers below to operate CATO. Some providers act as processors or service providers for customer data. Others, such as Stripe for certain payment and fraud functions, may also act as independent controllers under applicable law.
A vendor data processing agreement governs the relationship between Nyrus and that provider. It does not make a CATO user a party to the vendor agreement and does not mean that every provider has zero retention. See the Data Processing page for a plain-language explanation.
| Provider | Function | Data received | Retention posture | Processing location | DPA | Subprocessor list | Change notifications |
|---|---|---|---|---|---|---|---|
| Fireworks AI | Standard AI inference, daily memory maintenance, and selected scientific helper operations | Prompts, relevant conversation and tool context, human-readable conversation excerpts used for memory maintenance, model outputs, and request metadata | Reviewed Chat Completions paths are documented as zero data retention by default. Daily memory maintenance uses transient Batch API input and output datasets that CATO deletes after ingestion or terminal job handling. Service metadata and documented security or legal exceptions may remain. | United States and locations used by listed subprocessors | DPA | DPA schedules | Contract, account, and provider notice channels |
| Railway | Application hosting, PostgreSQL metadata, Redis cache and stream replay, Temporal workflow state, service logs, and transient trajectory delivery spooling | Accounts, conversation and project metadata, workflow and stream state, transient trajectory events, and technical logs. Railway is not the authoritative object store for user files or trajectories. | Retained while needed to provide CATO and removed through CATO deletion, ephemeral-storage, account-termination, and backup processes, subject to legal exceptions. | Primarily United States; configured service regions and provider subprocessors | DPA | Subprocessor list | Railway notice mechanism and email; DPA provides advance notice for changes |
| Google Cloud | Authoritative user-file and project-artifact object storage, the durable working filesystem of each project and its metadata store, separate operational and training-approved trajectory stores, isolated scientific sandbox execution, container registry, and infrastructure | Uploaded files, project artifacts, project filesystem contents, operational and approved trajectory records, user-selected analysis inputs, generated code, execution results, and infrastructure metadata | Controlled by separate Nyrus identities, storage lifecycle rules, sandbox workload cleanup, logging settings, and Google Cloud contractual deletion processes. | United States; CATO sandbox infrastructure is currently configured in us-central1 | Cloud DPA | Subprocessors | Google Cloud contractual and account notice channels |
| Sentry | Error and performance monitoring | Sanitized exceptions, stack and route data, release information, performance data, and opaque account identifiers | Events follow the configured Sentry retention period. CATO disables request bodies, session replay, contact details, default PII, and application logs. | United States and other locations identified by Sentry and its subprocessors | DPA | Subprocessors | Subscribe to Sentry legal and subprocessor updates |
| Stripe | Subscriptions, payments, fraud prevention, and metered billing | Contact and billing data, Stripe customer ID, subscription and invoice state, payment records, and numeric usage quantities | Transaction, fraud, tax, and compliance records are retained according to Stripe legal and operational requirements. CATO does not send prompts or datasets. | Global processing needed for payment, fraud, and financial services | DPA | Service providers | Subscribe through Stripe service-provider notification options |
| Resend | Transactional and support email delivery | Sender and recipient addresses, subject, message content, and delivery events | Email data is generally retained for 30 days, with account, security, and legal exceptions. CATO does not place research content in routine email. | United States and locations used by listed subprocessors | DPA | Subprocessors | Provider notices; the DPA provides advance notice for subprocessor changes |
Storage and sandbox boundaries
Google Cloud is the authoritative store for user files, project filesystems, and both trajectory stores; Railway holds application and workflow state but is not the authoritative store for those objects. Sandbox pods receive no cloud-storage credentials or application secrets. The Data Processing notice describes the trajectory store separation and the sandbox boundary in detail.
Public research services
Public literature, trial, patent, protein, pathway, chemical, and biomedical databases are external data sources rather than ordinary contracted CATO subprocessors. CATO may transmit search terms, public identifiers, filters, sequences, or structures needed for a requested lookup. Do not include personal or confidential information in those queries.
Changes
Nyrus reviews this list at least quarterly and before enabling a provider that will receive production user data. Material changes will be reflected here and communicated when required by applicable law or contract. Questions or objections may be sent to contact@nyrus.ai.