Subprocessors

Last updated August 31, 2026

Contents

LATO engages the subprocessors below to operate the service. Each is engaged under written data-protection terms, is reviewed by our security owner before it touches customer data, and is re-verified at least annually against its own published attestations. We update this page at least 30 days before adding or replacing a subprocessor.

Not on this list: services you connect with your own credentials under your own contract (Harmonic, Affinity, Granola, and the Google Workspace and Microsoft 365 integrations). There LATO acts on your instruction against an account LATO does not hold.

Current subprocessors

Provider Purpose Data shared Location Retention by provider Attestations Trust center
Anthropic AI inference (Claude) Conversation content and the context an agent needs for a task US (Standard Contractual Clauses) Up to 30 days for safety and abuse prevention, then deleted. Not used for model training SOC 2 Type II, ISO 27001, ISO/IEC 42001 trust.anthropic.com
Supabase Database, authentication, file storage Account data, conversation history, uploaded files EU Customer-controlled; deleted when you delete it SOC 2 Type II, ISO 27001 trust.supabase.io
WorkOS Enterprise single sign-on (SAML/OIDC) and directory provisioning (SCIM), where your organization uses SSO Work email, name, SSO identifiers and directory attributes of users in SSO-enabled organizations US (SCCs) While your organization’s SSO connection is active SOC 2 Type II trust.workos.com
Railway Backend hosting API requests and session data in transit EU Not stored independently by Railway SOC 2 Type II trust.railway.com
Daytona Sandboxed agent workspaces Files and data your agent processes during a task EU Workspace auto-stops when idle; archived after inactivity; deleted with your agent SOC 2 Type 1, ISO 27001 trust.daytona.io
E2B Sandboxed code execution Code and data passed to Python execution Ephemeral Sandbox destroyed after use (max 24 hours) SOC 2 Type II (per vendor) trust.e2b.dev
Exa Web search for agents Search queries issued by your agent. No account or conversation data US (SCCs) Per Exa’s retention policy SOC 2 Type II trust.exa.ai
Firecrawl Fetching web pages for research Web addresses to retrieve. No account or conversation data US Per Firecrawl’s retention policy SOC 2 Type II (per vendor) trust.firecrawl.dev
ElevenLabs AI voice interviews (speech recognition and synthesis) Interview audio and the study context the interviewer needs. Not supplied with participant names or contact details US (SCCs); EU residency available on enterprise terms Per ElevenLabs’ retention policy. Not used to train their models under our business terms SOC 2 Type II (per vendor) compliance.elevenlabs.io
Clay Contact and company enrichment when sourcing interview participants Business contact and company details used to identify potential participants US (SCCs) Per Clay’s retention policy SOC 2 Type II (per vendor) trust.clay.com
PostHog Product analytics and session replay, only if you accept analytics in the cookie banner Page views, feature usage, session replays EU (Frankfurt) Per PostHog’s retention policy SOC 2 Type II (report published) trust.posthog.com
Pydantic Logfire Application monitoring Error logs and performance traces, scrubbed of secrets EU 30 days SOC 2 Type II trust.oneleet.com/pydantic
Vercel Website and add-in hosting, add-in analytics Page views, feature usage Global edge Per Vercel’s retention policy SOC 2 Type II, ISO 27001 security.vercel.com
Google Workspace Outbound email from your agent (agent@latolabs.io) Email content sent to you and your invitees Global (SCCs) Per mailbox retention ISO 27001, SOC 2 and SOC 3 cloud.google.com/security/compliance

Attestations are as published by each provider on the date of our last review (2026-08-26). “Per vendor” marks a claim we have not yet verified against a certificate or audit report. Ask security@latolabs.io if you need a specific provider’s report; most are obtainable only under the provider’s own NDA.