Every third party that touches your data, named.
ArthurAI™ uses a deliberate, minimal set of subprocessors. Each is engaged under a contract that includes appropriate technical and organizational measures. Material changes to this list are disclosed under change-control with a notice period before the change takes effect for an institutional deployment.
Last updated May 17, 2026. To request the executable Data Processing Agreement or to object to a subprocessor change, talk to our team.
Microsoft Azure is the entire substrate. Every service below runs inside Azure under the same Microsoft Online Services Data Protection Addendum.
Microsoft Azure — Compute
East US (production), West US 2 (ULE)
Role. Static Web Apps, Container Apps, Azure Functions (queue + timer triggers)
Agreement. Microsoft Online Services DPA + Azure customer agreement (public reference: aka.ms/dpa)
Microsoft Azure — Storage
East US, West US 2; EU/Africa on request
Role. Blob Storage (tenant-scoped containers), Cosmos DB (Mongo API), Azure Database for PostgreSQL
Agreement. Microsoft Online Services DPA
Microsoft Azure — Security
East US (production)
Role. Key Vault (RBAC + soft delete + private endpoint), Bastion (admin access), NAT Gateway (egress), Front Door Premium + WAF
Agreement. Microsoft Online Services DPA
Microsoft Azure — Monitoring
East US, West US 2
Role. Application Insights (server + client telemetry), Log Analytics (operational logs)
Agreement. Microsoft Online Services DPA
Microsoft Azure — Messaging
East US
Role. Service Bus (async job queues for course generation, LCP summary, learning profile, email send)
Agreement. Microsoft Online Services DPA
Microsoft Azure — Networking
East US (production)
Role. Virtual Network with private endpoints for Key Vault, Cosmos, Functions; Private DNS zones
Agreement. Microsoft Online Services DPA
Microsoft Azure — Identity
Global Microsoft Entra
Role. Microsoft Entra ID for institutional federation, SSO, conditional-access integration
Agreement. Microsoft Online Services DPA
Microsoft Azure — Cognitive Services (Speech)
East US, West US 2
Role. Text-to-Speech with Azure Neural Voices for accessibility
Agreement. Microsoft Online Services DPA
The Eve-Education™ F5/reasoner architecture composes a small classifier, a fine-tuned Small Reasoning Model, and three frontier reasoning models behind Azure-hosted endpoints — with data residency aligned to the deployment region and no use of inputs or outputs for model training. This section names the entity that processes the data, not the model SKU: a subprocessor obligation attaches to the processor, and SKUs are revised without changing who processes what, where, or under which agreement. Model-level detail — including the frontier reasoning-model providers — is disclosed to each institution under its signed data processing agreement; where an institution or jurisdiction prohibits a specific provider, it is swapped without rebuilding the agent.
Microsoft Corporation — Azure AI Foundry (classification and small-reasoning tier)
Aligned to deployment region; no training on inputs or outputs
Role. Hosts and executes the compact classifier and the fine-tuned Small Reasoning Model (LoRA fine-tuned by MindHYVE.ai on Eve-Genesis, Education Edition) that perform request routing, classification, and the bulk of educational reasoning. Inference runs on Microsoft-operated Azure infrastructure inside the institution’s deployment region, so Microsoft is the processing entity for every call on this tier.
Agreement. Microsoft Online Services DPA + Azure AI Foundry service terms (public reference: aka.ms/dpa)
Microsoft Corporation — Azure AI Foundry (hosted general-purpose tier)
Aligned to deployment region (East US production)
Role. Hosts and executes the general-purpose generation, vision, multilingual generation, complex-reasoning, and text-embedding components composed in F5. Microsoft is the processing entity: third-party model licenses are honored under Azure hosting, so these components execute inside the Azure boundary rather than on a model publisher’s own infrastructure.
Agreement. Microsoft Online Services DPA + Microsoft Azure AI Foundry service terms (model licenses honored under Azure hosting) (public reference: aka.ms/dpa)
Frontier reasoning models (provider names withheld)
U.S. infrastructure (API tier — no training on inputs or outputs)
Role. Three frontier reasoning, generation, and vision models composed per request for high-stakes reasoning paths; provider identities are disclosed to institutions under the DPA
Agreement. Enterprise agreements with data-not-used-for-training terms; provider names disclosed under the customer DPA
Transactional email and notification delivery.
Microsoft Communication Services
East US
Role. Transactional email (account notifications, password reset, certificate delivery, parental consent emails where applicable)
Agreement. Microsoft Online Services DPA
These subprocessors operate only on arthurgrid.ai. They never see institutional product data. Microsoft Clarity is opt-in via the CCPA-aligned consent banner.
Microsoft Clarity
Microsoft Clarity infrastructure
Role. Consent-gated visitor analytics on the marketing site only — aggregate session behavior, no audio, no keystroke logging, no cross-site tracking
Agreement. Microsoft Online Services DPA + consent gate enforced at runtime
Where applicable, institutional billing flows through one of two payment providers. ArthurAI™ stores billing metadata and subscription status; card data remains with the payment provider (PCI scope-minimized).
Stripe, Inc.
Stripe U.S. infrastructure
Role. Payment processing for institutional subscriptions; Stripe webhook ingestion for subscription state
Agreement. Stripe Services Agreement + Stripe DPA
Block, Inc. (Square)
Block U.S. infrastructure
Role. Alternative payment processor for institutional subscriptions where Stripe is not preferred
Agreement. Square Payment Processing Terms + Square DPA
Change control
Material changes to this list (adding a new subprocessor with access to institutional data, or replacing an existing one) trigger a written notice to institutional Data Protection Officers with a 30-day notice period. The institution may object during the notice period; objection paths are documented in the executed Data Processing Agreement.
See also: Data Processing Agreement · data handling · security FAQ.