Last updated: June 12, 2026

Subprocessors

Duct uses the following categories of third-party providers to deliver the service. We require appropriate data protection terms with each provider that processes customer data on our behalf.

ProviderPurposeLocation
Cloud infrastructure providerHosts Duct services, databases, and networkingUnited States
PostgreSQL (managed or self-hosted)Persistent storage for accounts, manifests, sessions, and audit eventsSame region as deployment
RedisCaching, rate limiting, and short-lived session stateSame region as deployment
LLM providers (e.g. Anthropic, OpenAI, Google, Groq)Intent classification, tool routing, and response synthesis when platform or customer-supplied API keys are usedVaries by provider

When you invoke an action, Duct also sends requests to your configured API — that endpoint is controlled by you, not Duct.

When shell-to-shell is enabled, limited metadata is exchanged with another customer's shell to complete a delegated call. Both sides record an audit entry.

We will update this page when we add or replace subprocessors that process customer data. For privacy questions, see the Privacy Policy.