Subprocessors
Subprocessors
Effective September 24, 2026. Evriq, Inc. uses the subprocessors below to provide the Evriq service. A subprocessor is a third party that may process Customer Data or customer personal data on Evriq's behalf. Evriq will update this page at least 30 days before a new subprocessor begins processing Customer Data, and will tell workspace administrators by email.
Infrastructure and service providers
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | Network edge and TLS proxy in front of app.evriq.ai; DNS; encrypted off-site backups (R2 object storage); uptime monitoring; inbound email routing for evriq.ai; hosting of the evriq.ai website and demo | All traffic in transit; encrypted backup archives (Cloudflare holds ciphertext only) | United States; global edge network |
| Microsoft Corporation (Microsoft Azure) | Hosts the virtual machine that runs the Evriq application and every customer Workspace | All Customer Data at rest and in processing: Workspace databases, repositories, files, session transcripts, the encrypted vault and provider credentials, audit logs | United States (North Central US region) |
| PeakQuorum | Web origin that forwards app traffic from the Cloudflare edge to the application host; holds the Azure subscription the application host runs in; hosts Evriq's own source code and runs its continuous-integration builds | All traffic in transit between the edge and the host; Evriq's source code (no Customer Data in the source or builds) | United States |
| Auth Yourself | Identity provider: sign-in, multi-factor authentication, password reset and email verification, one isolated organization per customer | Name, email address, credentials and second factors, sign-in events | United States |
| Resend, Inc. | Delivery of account email (sign-in links, password reset, verification) on behalf of the identity provider; operational alert email to Evriq staff | Recipient email address and message content; alert email carries workspace names and status only | United States |
| Apple Inc. (Apple Push Notification service) | Push notifications to the Evriq iOS app, when a user enables them | Device token; notification text | United States |
| Browser push services (Google, Mozilla, Apple, depending on the user's browser) | Web push notifications, when a user enables them | Push endpoint; encrypted notification payload | United States; global |
| Amazon Web Services, Inc. (Amazon SNS) | SMS alerts, only when a workspace administrator configures an SMS destination | Phone number; alert text | United States |
When Evriq enables card billing, its payment processor will be added here before it processes any billing data.
AI model providers selected by the customer
Agent turns run on credentials the customer supplies, under the customer's own agreement with each provider. Evriq forwards prompts and the context an agent needs to the provider the customer configured, and does not pool credentials or accounts across customers. These providers are listed for transparency; the customer's contract with the provider governs their processing.
| Provider | Used for |
|---|---|
| Anthropic | Claude agent turns, on the customer's Anthropic key |
| OpenAI | Codex and chat turns, on the customer's OpenAI key |
| Gemini, on the customer's Google key | |
| DeepSeek | Chat participants and review-round seats on the customer's DeepSeek key. Prompts and the session transcript are sent to DeepSeek's API; it runs no tools and receives no files beyond that text |
| xAI | Grok chat participants on the customer's xAI key. Prompts and the session transcript are sent to xAI's API |
| Mistral AI, Ollama Cloud, OpenRouter, Together AI, Groq, Fireworks AI, and any OpenAI-compatible endpoint the customer supplies | Chat seats over the customer's own credential for that provider. Prompts and the session transcript are sent to the endpoint the customer chose |
| Microsoft (Azure OpenAI and Azure AI Foundry), Amazon Web Services (AWS Bedrock), Google (Vertex AI) | The same models reached through the customer's own cloud account and credentials; the cloud provider's terms with the customer govern |
Git hosts and other services chosen by the customer
When a customer connects a repository host, Evriq sends git traffic and, where a host API is used to create a repository or open a merge request, API calls to that host with the token the customer supplied. Supported hosts: GitHub (including GitHub Enterprise), GitLab (including self-hosted), Bitbucket, Gitea, Forgejo and Codeberg, PeakQuorum, and any other git server by URL. The customer's agreement with the host governs what it does with that content. Evriq holds a customer's tokens only as encrypted, write-only Workspace or project secrets.
Hosting
The Evriq application and every customer Workspace run on a Microsoft Azure virtual machine in the North Central US region, in an Azure subscription held by PeakQuorum. Requests reach it through Cloudflare's edge and PeakQuorum's web origin; no Workspace has its own hostname. Customer repositories live in the customer's Workspace on that machine. Encrypted off-site backups are stored in Cloudflare R2.