1. Overview
This page lists the sub-processors AgentLoka, Inc. engages to deliver the Service. Each sub-processor has a written DPA in place with us that imposes obligations equivalent to those in our customer DPA. We publish changes here at least 30 days before they take effect; material changes are also emailed to workspace admins and posted on /changelog.
2. Sub-processor registry
| Sub-processor | Purpose | Region | Transfers | DPA |
|---|---|---|---|---|
| Amazon Web Services | Compute, storage, KMS, network | US, EU, AP (per workspace pin) | SCCs in place | Yes |
| Stripe | Billing, payouts (Stripe Connect) | US (Stripe-hosted) | SCCs in place | Yes |
| Resend | Transactional email | US | SCCs in place | Yes |
| Sentry | Application error tracking | US (EU available) | SCCs in place | Yes |
| PostHog | Product analytics (cookie-less, IP-truncated) | EU | Intra-EEA | Yes |
| Integration gateway | OAuth + API token brokerage for 800+ third-party tools | US, EU (per workspace pin) | SCCs in place | Yes |
| Cloudflare | DNS, WAF, DDoS mitigation, asset CDN | Global edge | SCCs in place | Yes |
| LLM providers | Model inference (selectable per agent; zero-retention contracts where supported) | US, EU (provider-dependent) | SCCs in place | Yes |
3. About the integration gateway
The integration gateway is a white-labeled vendor that brokers OAuth and API tokens for the 800+ third-party tools available in the Service catalog. By policy, we don't surface the vendor's brand to end customers. It's part of the AgentLoka experience. The vendor is treated as a sub-processor with the standard DPA; customers under NDA can request the vendor name from legal@agentloka.com.
4. Get notified of changes
Subscribe to the change notification list at legal@agentloka.com or watch /changelog.
Questions, redlines, or just curious? Email legal@agentloka.com. For the security posture that backs these terms, see /security.