How we protect customer data, our compliance posture, and the third parties that help us operate the platform.
tenant-route helper.See our privacy notice for the full record of data we collect, retention windows, and user rights.
Our DPA is available on request — email legal@neww.ai.
| Vendor | Purpose | Region |
|---|---|---|
| Google Cloud Platform | Compute, Cloud SQL, GCS, Cloud Tasks | US |
| Anthropic | LLM inference (Claude) | US |
| Groq | Fast LLM inference (Llama) | US |
| OpenAI | Backup LLM + embeddings | US |
| Stripe | Billing and payments | US / EU |
| PostHog | Product analytics | US |
| Upstash | Distributed cache and rate limits | US / EU |
| Drata | Compliance evidence collection (SOC 2) | US |
| Data class | Region | Notes |
|---|---|---|
| User profiles, workspaces | us-central1 (Cloud SQL) | Replicated within region. |
| Generated artifacts | us-central1 (GCS) | Encrypted at rest with Google-managed keys. |
| Chat ephemeral | us-central1 (Firestore) | TTL-bounded; not used as source of truth. |
| Cache + locks | Upstash global edge | Non-PII keys only. |
Live platform health is published at /status. Customer-impacting incidents are recorded there with a timestamped update log; security incidents that affect customer data are also notified per contract terms.