Hebbia Subprocessors List (October 2026): Changes and History
Hebbia names 16 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Hebbia subprocessors (October 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Amazon Web Services | Cloud provider | — |
| 2 | Google [Gemini + Workspace] | LLM + Email/Drive | — |
| 3 | OpenAI | LLM | — |
| 4 | Anthropic | LLM | — |
| 5 | Microsoft [365 + Azure OpenAI Services] | Data storage and processing | — |
| 6 | Elastic | Search index | — |
| 7 | Auth0 | Identity provider | — |
| 8 | Cerebras | LLM Infrastructure Hosting | — |
| 9 | BaseTen | LLM Infrastructure Hosting | — |
| 10 | Fireworks.ai | LLM Infrastructure Hosting | — |
| 11 | Groq | LLM Infrastructure Hosting | — |
| 12 | Modal | LLM Infrastructure Hosting | — |
| 13 | Reducto AI | Document parsing | — |
| 14 | Merge | Integration provider | — |
| 15 | Datadog | Platform logging and monitoring | — |
| 16 | MongoDB | Embedding and re-ranking services | — |
Get an email when Hebbia changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Hebbia
What Hebbia's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“Upon becoming aware of a Security Incident, Hebbia shall inform Customer without undue delay and provide all such timely information and cooperation as required by Applicable Data Protection Law”
DPA, www.hebbia.com ↗ - Notice of a new subprocessor
-
10 days ahead
“At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers”
DPA, www.hebbia.com ↗ - Transfers outside the EU
-
Standard contractual clauses
“in relation to Processor Data that is protected by the EU GDPR, the EU SCCs will apply completed as follows:”
DPA, www.hebbia.com ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“Upon termination or expiry of the Agreement, Hebbia shall (at Customer's election) destroy or return to Customer all Processor Data (including all copies of the Processor Data) in its possession or control without undue delay.”
DPA, www.hebbia.com ↗ - Audit rights
-
Once a year
“Customer will not exercise its audit rights more than once in any twelve (12) calendar month period, except (i) if and when required by instruction of a competent data protection authority; or (ii) Customer believes a further audit is necessary due to a Security Incident suffered by Hebbia.”
DPA, www.hebbia.com ↗
Certifications at Hebbia
What Hebbia's trust page lists, with the text each one comes from. SOC 2 Type I or Type II: what's the difference?
- SOC 2 Type II
-
Active
“SOC 2 Type 2”
Trust page, www.hebbia.com ↗ - ISO 27001
-
Active
“ISO 27001:2022”
Trust page, www.hebbia.com ↗ - ISO 42001
-
Active
“ISO/IEC 42001:2023”
Trust page, www.hebbia.com ↗
Documents we track for Hebbia
- DPA
- checked October 4, 2026 www.hebbia.com ↗
- Privacy policy
- checked October 4, 2026 www.hebbia.com ↗
- Subprocessor list
- checked October 5, 2026 trust.hebbia.ai ↗
- Terms of service
- checked October 4, 2026 www.hebbia.com ↗
- Trust page
- checked October 4, 2026 www.hebbia.com ↗
Change history
Tracking since October 5, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Hebbia subprocessors FAQ
- How many subprocessors does Hebbia use?
- Hebbia lists 16 subprocessors on its published list, including Amazon Web Services, Google [Gemini + Workspace], OpenAI, Anthropic, and Microsoft [365 + Azure OpenAI Services] and 11 more.
- How quickly does Hebbia report a personal data breach to customers?
- According to its DPA, Hebbia reports a personal data breach to customers without undue delay, with no set deadline: “Upon becoming aware of a Security Incident, Hebbia shall inform Customer without undue delay and provide all such timely information and cooperation as required by Applicable Data Protection Law”
- How much notice does Hebbia give before adding a subprocessor?
- Hebbia's DPA gives 10 days' notice of a new subprocessor, the time customers have to object: “At least ten (10) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Hebbia will add such third party to the List and notify subscribers”
- How does Hebbia transfer personal data outside the EU?
- Hebbia's DPA relies on standard contractual clauses: “in relation to Processor Data that is protected by the EU GDPR, the EU SCCs will apply completed as follows:”
- Does Hebbia have a SOC 2 Type II report?
- Yes. Hebbia's trust page lists a SOC 2 Type II report: “SOC 2 Type 2”
- Which security certifications does Hebbia list?
- Hebbia's trust page lists SOC 2 Type II, ISO 27001, and ISO 42001.
- When was Hebbia's subprocessor list last checked?
- ClauseTrail last checked Hebbia's subprocessor list on October 5, 2026. Lists are re-checked daily.
- How do I find out when Hebbia adds or removes a subprocessor?
- ClauseTrail monitors Hebbia's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.