1. Purpose of this disclosure
Customers and regulators need transparency about who processes personal data and AI payloads. Categories below describe current production roles. Specific vendors may change; material changes are posted here and, for DPA customers, objection rights apply as stated in the DPA.
2. AI inference providers
Forge features may send prompts, code context, design context, or evaluation payloads to AI model providers for inference only. Customer payloads are not used to train shared third-party models when the provider offers a no-training / zero-retention enterprise configuration; we enable those controls where available (see IP Ownership §5).
- xAI / Grok API — generative assistance for software and design workflows (US-based provider).
- OpenAI API — optional model routing for coding and evaluation tasks when configured for a Tenant or environment.
- Anthropic API — optional model routing for coding and evaluation tasks when configured.
- Self-hosted / private-cloud models— models run on Echo-controlled infrastructure (e.g., FORGE/ANVIL cluster) for latency, isolation, or cost; data stays within Echo's operational perimeter subject to our security controls.
Exact model selection can vary by product stage, failover, and enterprise configuration. Enterprise customers may contract for pinned models or private endpoints.
3. Infrastructure & platform subprocessors
- Cloudflare — DNS, CDN, tunnel/edge ingress, DDoS protection for echosforge.com and related hostnames.
- Echo Private Cloud compute (FORGE/HAMMER/ANVIL) — primary application and service hosting operated by Echo Prime Tech LLC.
- Object / volume storage on Echo infrastructure — artifact and database persistence for Tenants.
4. Authentication, email, and billing
- Google OAuth — optional social sign-in (identity tokens only as authorized by you).
- Payment processors (e.g., Stripe or equivalent when enabled) — card processing and invoices; cardholder data handled by the processor under PCI scope.
- Transactional email providers — account and support email delivery when configured.
5. Observability and security
- Logging and metrics stack on Echo infrastructure — operational telemetry, health checks, and incident response.
- Error / APM tools — may be enabled for application diagnostics; configured to minimize sensitive payload capture.
6. What subprocessors receive
AI providers receive only the context needed for a job (prompts, file excerpts, evaluation inputs). Infrastructure hosts full application state for your Tenant. Payment processors receive billing identity, not CAD or source repositories. We do not sell Customer Content to data brokers.
7. Updates and contact
Check this page for the current list. Questions or DPA objections: [email protected].