A subprocessor is a third party we engage to help provide the Enjamb platform, and that may process customer data in the course of doing so. This page lists them, what each is used for, and where it operates.
Each subprocessor is bound by written terms that limit it to processing on our instructions, and none of them is permitted to train models on customer data. We remain responsible for their performance under our agreement with you. Our commitments on all of this are set out in the Privacy Policy and the Platform Agreement.
We give notice before adding a subprocessor, on the terms in your data processing addendum, so that you have the opportunity to object before it begins processing.
1. Platform Subprocessors
These are engaged for every customer, because they run the platform itself.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure underlying the platform | United States |
| Railway Corp. | Application hosting and container orchestration | United States |
| Supabase, Inc. | Database, object storage, and realtime services | United States |
| WorkOS, Inc. | Authentication, single sign-on, and directory synchronization | United States |
| Anthropic PBC | Model provider for Claude models | United States |
| OpenAI, LLC | Model provider for GPT models | United States |
| Resend, Inc. | Transactional email, including invitations and notifications | United States |
2. Feature-Specific Subprocessors
These are engaged only where a customer uses the capability they support. If the capability is not enabled in your workspace, the subprocessor does not process your data.
| Subprocessor | Purpose | Used when |
|---|---|---|
| Modal Labs, Inc. | GPU compute for model execution, including structure prediction | An agent runs a workload that requires GPU compute |
| Blaxel, Inc. | Sandboxed compute for agent code execution | An agent executes code or runs an analysis environment |
| Stripe, Inc. | Payment processing for billing contact and payment details | An account is billed by card rather than by invoice |
| PostHog, Inc. | Product analytics on marketing and in-product usage events | Analytics are enabled for the workspace |
3. What Is Not on This List
Systems you connect. When you authorize Enjamb to reach an electronic lab notebook, a document vault, a clinical data platform, an object store, or a messaging tool, that system is not our subprocessor. You choose it, you hold the agreement with its provider, and you direct what flows to it. Our role is to carry your users' instructions to it under their own permissions.
Public research sources. Where an agent searches published literature or public registries, it sends a query and receives public results. No customer data is transferred to those sources, so they are not subprocessors.
Self-hosted components. Some parts of the platform use open source software that we operate inside our own infrastructure rather than consuming as a hosted service, including the document editing engine. Because no data leaves our environment, the software's publisher does not process customer data and is not a subprocessor.
4. Changes and Notice
We update this page when a subprocessor is added or removed, and the date at the top reflects the current version. Customers with a data processing addendum receive notice in advance of an addition, together with the objection process that addendum provides.
To receive notice by email when this list changes, or to ask about a particular subprocessor, write to privacy@enjamb.ai.


