<aside>
💡
Information on this trust center is generally about ISMS Copilot v1, the ancestor of current ISMS Copilot built, on another technology. If you’re using the latest ISMS Copilot 2.0, access the dedicated trust page, where we detailed how we’re taking security even further. In case you have any specific question or doubt, you can always reach out.
➡️ Find everything you need to know about ISMS Copilot 2.0
</aside>
Here's a list of subprocessors handling user data for ISMS Copilot:
AWS (Amazon Web Services):
- Role: Hosting provider for EU users.
- Location: Amsterdam, Netherlands.
- Data Handled: Conversation data for ISMS Copilot Chatbots (EU option).
Chatbase:
- Role: Chatbot platform provider.
- Location: United States.
- Data Handled: Conversation data for ISMS Copilot Chatbots (US default option).
- Compliance: SOC 2 Type 2 attested, ensuring rigorous controls for security, availability, and confidentiality of customer data.
Moustache:
- Role: Chatbot platform provider for EU users.
- Location: European Union.
- Data Handled: Conversation data for ISMS Copilot Chatbots (EU default option).
ChatLab:
- Role: Chatbot platform provider for EU users.
- Location: European Union.
- Data Handled: Conversation data for ISMS Copilot Chatbots (Temporay chats).
Mistral:
- Role: AI processing provider for EU users.
- Location: Sweden.
- Data Handled: Conversation data for ISMS Copilot Chatbots (EU option).
Azure OpenAI:
- Role: AI processing provider for EU users.
- Location: France.
- Data Handled: Conversation data for ISMS Copilot Chatbots (EU option).
OpenAI:
- Role: AI processing provider.
- Location: United States.
- Data Handled: Conversation data for ISMS Copilot Chatbots (US default option) and policy text generation for ISMS Policy Generator.
Anthropic:
- Role: AI processing provider.
- Location: United States.
- Data Handled: Conversation data for ISMS Copilot Chatbots (US option).
Our chatbots can alternatively rely on OpenAI or Anthropic models (or Mistral, for the EU version).
Bubble.io:
- Role: Application development platform.
- Location: United States.
- Data Handled: User inputs for ISMS Policy Generator.
Sendgrid:
- Role: Sending platforms emails (password reset, 2FA codes, legal updates).
- Location: United States.
- Data Handled: User email.
Zapier:
- Role: Automation tool for policy generation and email delivery.
- Location: United States.
- Data Handled: User inputs and generated policy data for ISMS Policy Generator.
Google Docs:
- Role: Document conversion and storage.
- Location: United States.
- Data Handled: Policy text for ISMS Policy Generator.
Stripe:
- Role: Payment processing.
- Location: United States.
- Data Handled: Payment information for subscription upgrades.