Ishavi
Annex BRev. 2026-05
Sub-processor register

Every third party that touches customer data.

The register below is the full list of sub-processors Ishavi engages to deliver the platform. It is incorporated by reference into the customer Data Processing Agreement (Annex B). New sub-processors are notified to subscribers thirty days before they go live.

NameServiceData processedLocationStatus
WorkOSIdentity, SSO, SAML, directory syncRecruiter email, organisation name, SSO claimsUnited States (us-east-1)Active · DPA signed · SOC 2 Type II
SupabaseManaged Postgres + Auth backing storeAll structured customer data: tenants, jobs, interview metadata, scorecardsap-south-1 (Mumbai)Active · DPA signed · SOC 2 Type II
CloudflareR2 object storage + CDN + DNSInterview audio recordings, transcripts, model output artefacts; static assetsGlobal edge; R2 bucket region: WEUR / ENAM as tenant requiresActive · DPA signed · ISO 27001, SOC 2 Type II
ResendTransactional email deliveryRecipient email, message content (invite links, appeal updates, audit notifications)United States (us-east-1)Active · DPA signed · SOC 2 Type II
SentryError monitoring + performance tracesStack traces, request paths, user IDs (no payloads); PII scrubbing enabledUnited States (us-east-1)Active · DPA signed · SOC 2 Type II
OpenAIWhisper (speech-to-text), GPT (scoring fallback), TTS (interviewer voice)Interview audio frames, transcript chunks, system + user prompts, model outputsUnited StatesActive · Enterprise DPA signed · zero-retention API mode · SOC 2 Type II
AnthropicClaude family for conversation orchestration and follow-up generationConversation context, rubric grounding, system + user prompts, model outputsUnited StatesActive · Commercial DPA signed · zero-retention API mode · SOC 2 Type II
Google AI StudioGemini family for rubric-anchored scorecard compositionTranscript excerpts, rubric definitions, model outputsUnited StatesActive · Cloud DPA signed · SOC 2 Type II, ISO 27001
VercelFrontend application hosting + edge functionsRequest headers, IP addresses (truncated), routing metadataiad1 (us-east-1) primary; multi-region edgeActive · DPA signed · SOC 2 Type II
Oracle Cloud InfrastructureBackend API host (Mumbai region)All transit and processing of customer requests routed through this hostap-south-1 (Mumbai)Active · Master Services Agreement · ISO 27001, SOC 2 Type II
Notification policy

30-day notice before any change.

When Ishavi adds, removes, or substitutes a sub-processor, we publish the change here and notify the sub-processor mailing list at least 30 calendar days before the change takes effect. Customers may object to a new sub-processor in writing within that window; if we cannot resolve the objection through reasonable steps, the customer may terminate the affected portion of the service per the terminating provisions of the DPA.

Emergency replacements (security incident, vendor outage, regulatory order) are notified after the fact within five business days, with a written explanation of why prior notice was not possible.