Last updated August 31, 2026
LATO engages the subprocessors below to operate the service. Each is engaged under written data-protection terms, is reviewed by our security owner before it touches customer data, and is re-verified at least annually against its own published attestations. We update this page at least 30 days before adding or replacing a subprocessor.
Not on this list: services you connect with your own credentials under your own contract (Harmonic, Affinity, Granola, and the Google Workspace and Microsoft 365 integrations). There LATO acts on your instruction against an account LATO does not hold.
| Provider | Purpose | Data shared | Location | Retention by provider | Attestations | Trust center |
|---|---|---|---|---|---|---|
| Anthropic | AI inference (Claude) | Conversation content and the context an agent needs for a task | US (Standard Contractual Clauses) | Up to 30 days for safety and abuse prevention, then deleted. Not used for model training | SOC 2 Type II, ISO 27001, ISO/IEC 42001 | trust.anthropic.com |
| Supabase | Database, authentication, file storage | Account data, conversation history, uploaded files | EU | Customer-controlled; deleted when you delete it | SOC 2 Type II, ISO 27001 | trust.supabase.io |
| WorkOS | Enterprise single sign-on (SAML/OIDC) and directory provisioning (SCIM), where your organization uses SSO | Work email, name, SSO identifiers and directory attributes of users in SSO-enabled organizations | US (SCCs) | While your organization’s SSO connection is active | SOC 2 Type II | trust.workos.com |
| Railway | Backend hosting | API requests and session data in transit | EU | Not stored independently by Railway | SOC 2 Type II | trust.railway.com |
| Daytona | Sandboxed agent workspaces | Files and data your agent processes during a task | EU | Workspace auto-stops when idle; archived after inactivity; deleted with your agent | SOC 2 Type 1, ISO 27001 | trust.daytona.io |
| E2B | Sandboxed code execution | Code and data passed to Python execution | Ephemeral | Sandbox destroyed after use (max 24 hours) | SOC 2 Type II (per vendor) | trust.e2b.dev |
| Exa | Web search for agents | Search queries issued by your agent. No account or conversation data | US (SCCs) | Per Exa’s retention policy | SOC 2 Type II | trust.exa.ai |
| Firecrawl | Fetching web pages for research | Web addresses to retrieve. No account or conversation data | US | Per Firecrawl’s retention policy | SOC 2 Type II (per vendor) | trust.firecrawl.dev |
| ElevenLabs | AI voice interviews (speech recognition and synthesis) | Interview audio and the study context the interviewer needs. Not supplied with participant names or contact details | US (SCCs); EU residency available on enterprise terms | Per ElevenLabs’ retention policy. Not used to train their models under our business terms | SOC 2 Type II (per vendor) | compliance.elevenlabs.io |
| Clay | Contact and company enrichment when sourcing interview participants | Business contact and company details used to identify potential participants | US (SCCs) | Per Clay’s retention policy | SOC 2 Type II (per vendor) | trust.clay.com |
| PostHog | Product analytics and session replay, only if you accept analytics in the cookie banner | Page views, feature usage, session replays | EU (Frankfurt) | Per PostHog’s retention policy | SOC 2 Type II (report published) | trust.posthog.com |
| Pydantic Logfire | Application monitoring | Error logs and performance traces, scrubbed of secrets | EU | 30 days | SOC 2 Type II | trust.oneleet.com/pydantic |
| Vercel | Website and add-in hosting, add-in analytics | Page views, feature usage | Global edge | Per Vercel’s retention policy | SOC 2 Type II, ISO 27001 | security.vercel.com |
| Google Workspace | Outbound email from your agent (agent@latolabs.io) | Email content sent to you and your invitees | Global (SCCs) | Per mailbox retention | ISO 27001, SOC 2 and SOC 3 | cloud.google.com/security/compliance |
Attestations are as published by each provider on the date of our last review (2026-08-26). “Per vendor” marks a claim we have not yet verified against a certificate or audit report. Ask security@latolabs.io if you need a specific provider’s report; most are obtainable only under the provider’s own NDA.