Sub-Processors
Nexture AI LLC
Effective Date: September 28, 2026
This document was last reviewed and updated on the effective date above. The change log in Section 6 records what changed.
Brand notice. This service is offered publicly under the name MiaSure. "MiaSure" is a trade name of Nexture AI LLC, the Wyoming limited liability company that operates the Service and is your contracting party under this document. Any reference herein to "Nexture AI," "Nexture AI LLC," "the Company," "we," "us," or "our" means Nexture AI LLC operating as MiaSure.
A sub-processor is a third-party service that processes data on Nexture AI's behalf to deliver the Service. This page is the list of our sub-processors that our Privacy Policy refers to. We review it whenever we add, remove, or change the role of a provider, and we give 30 days' advance notice before adding a sub-processor that will receive customer data (Section 5).
Each entry below identifies the provider's role, the class of data it processes, the geographic region of processing, the terms we use it under, and what those terms say about training on and retaining the data we send. Where an entry says "per the provider's terms," we are describing the provider's published commitments, not an additional commitment of our own. We do not authorize any provider to use customer data to train or improve its own general-purpose models.
Data classes used on this page:
- Tenant data — uploaded documents, extracted policy data, conversations with Mia, and content derived from them.
- Metadata — system-generated information about tenant data (e.g., timestamps, identifiers, processing state).
- User identity — authentication credentials, profile, and session information.
- Operational telemetry — application logs, error traces, and performance metrics. We remove credentials, email addresses, and other recognizable personal data before transmission, but this is pattern-based and cannot guarantee that no name appears in free text.
- Billing — payment and invoicing information; no policy or insured personal information.
1. Active Sub-Processors
These providers are engaged for every customer of the Service.
1.1. Infrastructure
Render
- Role: Platform-as-a-Service hosting. The MiaSure application stack runs on Render, including web servers, background workers, and runtime memory. Render personnel have technical access to container environment variables, logs, and runtime memory in the course of providing the service.
- Data class: Tenant data (in transit and in process memory), metadata, user identity, operational telemetry.
- Region: United States (us-east).
- Contractual basis: Render Terms of Service and Render Privacy Policy.
- Training and retention: Hosting only; application logs are retained per Render's terms.
MongoDB Atlas
- Role: Primary application database. Stores documents, extracted data (encrypted by our application before storage), user records, and platform metadata. Where configured, also stores our semantic-search index.
- Data class: Tenant data, metadata, user identity.
- Region: AWS us-east-1 (N. Virginia).
- Contractual basis: MongoDB Data Processing Addendum.
- Training and retention: Database hosting only; backups retained per our configuration (Privacy Policy § 7).
Redis Cloud (Redis Labs)
- Role: Job queue and transient cache supporting the document-processing pipeline.
- Data class: Metadata; transient tenant data passed through the queue during job execution.
- Region: AWS us-east-1.
- Contractual basis: Redis Enterprise Cloud DPA.
- Training and retention: Transient queue and cache data only.
Cloudflare
- Role: DNS, TLS termination, web application firewall, rate limiting, bot protection (including the Turnstile challenge on sign-in and sign-up), and the geographic access restriction in front of the Service. Every request and response passes through Cloudflare's network in transit.
- Data class: Tenant data in transit; user identity and operational telemetry (IP address, user agent, request metadata, challenge tokens).
- Region: Cloudflare's global network (traffic is handled nearest the requester).
- Contractual basis: Cloudflare Data Processing Addendum.
- Training and retention: Per Cloudflare's terms.
1.2. Amazon Web Services
All AWS services below are governed by the AWS Service Terms and the AWS Data Processing Addendum.
AWS S3
- Role: Object storage for uploaded PDFs, text transcripts of documents, and generated deliverables. Files are encrypted by our application (AES-256-GCM, per-account keys) before storage, and the bucket additionally applies S3 server-side encryption by default (SSE-S3, AES-256). Deleted files become noncurrent versions that a bucket lifecycle rule removes within 90 days.
- Data class: Tenant data.
- Region: us-east-1.
- Contractual basis: AWS DPA.
AWS KMS
- Role: Key management. Holds the key that protects the per-account encryption keys used for data at rest.
- Data class: Cryptographic material only; no tenant content.
- Region: us-east-1.
- Contractual basis: AWS DPA.
AWS SES
- Role: Outbound email (share notifications, review requests, messages you send through the Service, and system messages).
- Data class: User identity (sender and recipient addresses), metadata, and any tenant content in the message body or links.
- Region: us-east-1.
- Contractual basis: AWS DPA.
AWS Cognito
- Role: User authentication, password hashing, token issuance, and multi-factor authentication.
- Data class: User identity.
- Region: us-east-1.
- Contractual basis: AWS DPA.
AWS Secrets Manager
- Role: Storage of certain platform secrets and integration credentials.
- Data class: Credential material; no tenant content.
- Region: us-east-1.
- Contractual basis: AWS DPA.
1.3. AI Language-Model Providers
OpenAI
- Role: Language models for extraction and for Mia's answers; embeddings for semantic search; web search for insured and business research during data enrichment (Section 2.3); and, where selected, a real-time voice model for Talk to Mia (Section 1.4).
- Data class: Tenant data (document text, your questions, and derived prompts).
- Region: United States.
- Contractual basis: OpenAI API business terms (OpenAI Enterprise Privacy).
- Training and retention: Per OpenAI's API terms, data sent through the API is not used to train OpenAI's models by default. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring. Where our semantic-search index is kept in OpenAI's vector storage rather than in our own database, the indexed text is retained by OpenAI until we delete it, which we do when you permanently delete the document.
Anthropic
- Role: Language models for Mia's answers and for extraction and validation.
- Data class: Tenant data (document text, your questions, and derived prompts).
- Region: United States.
- Contractual basis: Anthropic Commercial Terms of Service.
- Training and retention: Per Anthropic's commercial terms, data sent through the API is not used to train Anthropic's models. Inputs and outputs may be retained for a limited period under those terms, including for trust-and-safety review.
Google (Gemini API and Google Maps Platform)
- Role: Gemini language models for the structural pass over documents and other extraction and analysis steps; the Google Geocoding API for address normalization (Section 2.3); and Google Maps static map images in some exported deliverables.
- Data class: Tenant data (document text for Gemini; property addresses or coordinates for Geocoding and maps).
- Region: United States.
- Contractual basis: Google's paid-service API terms and the Google Cloud Data Processing Addendum.
- Training and retention: Per Google's paid-service terms, data submitted through the paid Gemini API is not used to train Google's models; Google may retain it for a limited period for abuse monitoring.
Mistral AI
- Role: Language models used for some extraction steps, and Mistral OCR for converting documents to text (Section 1.5).
- Data class: Tenant data (document images and text).
- Region: Mistral AI is based in France and may process data in the European Union.
- Contractual basis: Mistral AI Terms.
- Training and retention: Per Mistral's terms for paid API use, data is not used to train Mistral's models; retention per those terms.
1.4. Voice: Talk to Mia
When you talk to Mia by voice, your voice is streamed in real time to the providers below, and the transcript is saved to your account. We do not store the audio.
Voice and meeting service (software licensed from AI Meetings LLC)
- Role: Runs real-time voice sessions for Talk to Mia and, when launched, the meeting assistant. It relays audio to the voice and speech providers listed here and returns the transcript to the Service. This provider keeps its own copy of Talk to Mia transcripts. When you close your account we delete the transcripts we hold and ask this provider to delete your meeting and interview records, but we cannot confirm what its deletion removes and it may retain a copy.
- Data class: Tenant data (audio in transit, transcripts, and, for meetings, participant names and email addresses).
- Region: United States.
- Contractual basis: Software license and service agreement with AI Meetings LLC.
- Training and retention: Transcripts are kept for the period stated in our Privacy Policy § 7. We have not authorized training on customer data.
xAI (Grok voice)
- Role: The default real-time voice model for Talk to Mia: it hears what you say and produces Mia's spoken reply.
- Data class: Tenant data (your voice and the conversation, which may refer to your policies).
- Region: United States.
- Contractual basis: xAI API terms of service.
- Training and retention: Per xAI's API terms. We have not authorized xAI to train on customer data.
OpenAI (real-time voice) — an alternative voice model for Talk to Mia, used when selected in place of xAI. See the OpenAI entry in Section 1.3.
Deepgram
- Role: Speech-to-text for voice and meeting features.
- Data class: Tenant data (audio and transcript text).
- Region: United States.
- Contractual basis: Deepgram terms of service.
- Training and retention: Per Deepgram's terms. We have not authorized Deepgram to train on customer data.
1.5. Document Text Recognition (OCR)
We use two OCR providers to convert uploaded documents to text. Depending on the processing step and configuration, either may be used first, with the other as a fallback when the first is unavailable or returns insufficient text. Some image-only content is also read with open-source OCR software that runs on our own servers and sends nothing to a third party.
Mistral AI — OCR — see the Mistral AI entry in Section 1.3, including its European Union processing region.
LLMWhisperer (Unstract, Inc.) — OCR
- Role: OCR and PDF-to-text conversion.
- Data class: Tenant data (document bytes and extracted text).
- Region: United States.
- Contractual basis: Unstract Privacy Policy; data handling documented in the Unstract Data Privacy FAQ.
- Training and retention: Per Unstract's documentation for its paid plan, which we use, documents are processed as a pass-through and are not stored or used to train Unstract's models.
1.6. Billing
Stripe
- Role: Payment processing for Credit purchases.
- Data class: Billing only. Stripe receives the purchaser's billing details and does not receive policy data or insured personal information.
- Region: United States and Stripe's global processing footprint.
- Contractual basis: Stripe Data Processing Agreement.
1.7. Operational Telemetry
Sentry
- Role: Error tracking and performance monitoring. No session recording or replay.
- Data class: Operational telemetry, scrubbed as described above before transmission.
- Region: United States.
- Contractual basis: Sentry Data Processing Addendum.
- Training and retention: Retained per Sentry's terms (typically up to 90 days).
1.8. Web Analytics
Plausible Analytics
- Role: Cookieless, aggregate page-view measurement across the site, except on excluded areas where it neither loads nor reports (shared-document pages, password-reset and set-password pages, the client-portal embed, and administrative, print, OAuth and developer pages). Page addresses are recorded without their query strings, and identifier-like path segments are replaced with a placeholder.
- Data class: Operational telemetry (aggregate page-view counts and referrers). No cookies are set and no tenant data is transmitted.
- Region: European Union.
- Contractual basis: Plausible Data Policy.
1.9. Web Fonts
Google Fonts
- Role: Delivers typefaces from Google's font servers (fonts.googleapis.com and fonts.gstatic.com) on some pages, for example our public brand page, and for a client portal whose broker has chosen a custom font. Your browser requests the fonts directly from Google when those pages load.
- Data class: Your IP address and standard request headers (such as user agent and referrer), sent by your browser to Google. No tenant data and no account data.
- Region: Global (Google edge network).
- Contractual basis: Google Fonts terms and Google's privacy policy.
2. Conditional Sub-Processors
These providers are engaged only for customers who have the corresponding feature switched on. Most are opt-in (a cloud connector is engaged only after the user grants OAuth consent). Data Enrichment (section 2.3) is the exception: it is on by default and can be switched off — for the whole account, or for an individual policy — at any time. Section 2.3 sets out exactly what that means and who receives what.
2.1. Cloud and Email Connectors (activated by OAuth consent in account settings)
Microsoft (Microsoft Graph)
- Role: Outlook calendar and email, OneDrive, and SharePoint connectors. Used only when a user grants OAuth consent.
- Permissions requested: When you connect Microsoft 365 we request
User.Read,Calendars.ReadWrite,OnlineMeetings.ReadWrite,OnlineMeetingTranscript.Read.All, andoffline_access; for email drafting,Mail.ReadWriteandContacts.Read; for sending from your mailbox,Mail.Send; for OneDrive,Files.Read; and for SharePoint,Sites.Read.All. Microsoft shows you the permissions requested before you consent. - Data class: Tenant data (the Microsoft 365 content the connector reads or writes at your direction), user identity (OAuth tokens, stored encrypted).
- Region: Microsoft's global footprint as configured for the customer's tenant.
- Contractual basis: Microsoft Graph data handling.
- Feature flag: Per-user OAuth consent.
Box
- Role: Cloud-folder ingest from Box. Used only when a user grants OAuth consent.
- Data class: Tenant data (the specific Box content the user authorizes).
- Region: Box's global footprint as configured for the customer's account.
- Contractual basis: Box Customer Agreement.
- Feature flag: Per-user OAuth consent.
2.2. Web Research (activated when ENABLE_WEB_RESEARCH=true for the deployment)
Tavily
- Role: Web search for market intelligence, including carrier rate notes and regulatory filings.
- Data class: Query terms only (e.g., carrier names, public topics). A query that mentions a person or an insured is never sent to Tavily. No tenant document content is transmitted.
- Region: United States.
- Contractual basis: Tavily terms.
- Training and retention: Per the provider's stated terms.
- Feature flag:
ENABLE_WEB_RESEARCH.
Jina Reader
- Role: URL-to-markdown extractor (
r.jina.ai) used as a fallback inside the web-research pipeline. - Data class: Public URLs only. No tenant document content is transmitted.
- Region: Provider's global footprint.
- Contractual basis: Jina AI legal.
- Training and retention: Per the provider's stated terms.
- Feature flag:
ENABLE_WEB_RESEARCH.
Firecrawl
- Role: AI-assisted web scraping for anti-bot or JavaScript-heavy sites. Third-tier fallback inside the web-research pipeline.
- Data class: Public URLs only. No tenant document content is transmitted.
- Region: United States.
- Contractual basis: Firecrawl terms.
- Training and retention: Per the provider's stated terms.
- Feature flag:
ENABLE_WEB_RESEARCHand a configuredFIRECRAWL_API_KEY.
2.3. Data Enrichment (on by default; per-account and per-policy opt-out)
When a policy finishes processing, we look up public and licensed reference data about the insured and the insured property — flood zone, seismic exposure, industry classification, carrier background — and attach it to the policy. This requires sending certain details to the providers listed below. Your policy documents themselves are never sent to any of them.
How to turn it off. Enrichment is on by default and is governed by three controls, all of which must permit a call before anything is sent:
- Per deployment: the
ENABLE_ENRICHMENTfeature flag. - Per account: Settings → Extraction → Data Enrichment. Switching it off stops all enrichment for your account immediately.
- Per policy: an individual policy can be excluded while enrichment stays on for the rest of your book. This is available on request today; a self-service control on the policy page is in progress.
These controls are enforced in code at every point where enrichment can start, and they fail closed — if the owning account cannot be resolved, no outbound call is made. The roster below is checked against the same machine-readable manifest the product uses to render the in-app disclosure.
Google Geocoding
- Role: Address normalization and geocoding for the insured location.
- Data class: Tenant data (the insured property address).
- Region: United States.
- Contractual basis: Google Cloud Data Processing Addendum.
- Training and retention: Per Google's paid-service terms.
- Feature flag:
ENABLE_ENRICHMENTplus the account and policy controls above.
FEMA (OpenFEMA / National Flood Hazard Layer)
- Role: Flood zone lookup for the insured location.
- Data class: Coordinates derived from the insured property address. No name, no policy number, no document content.
- Region: United States (US federal government service).
- Contractual basis: Public US government API; no account or key required.
- Training commitment: Not applicable — a public data lookup.
- Feature flag:
ENABLE_ENRICHMENTplus the account and policy controls above.
USGS
- Role: Seismic design (ASCE 7) data for the insured location.
- Data class: Coordinates derived from the insured property address. No name, no policy number, no document content.
- Region: United States (US federal government service).
- Contractual basis: Public US government API; no account or key required.
- Training commitment: Not applicable — a public data lookup.
- Feature flag:
ENABLE_ENRICHMENTplus the account and policy controls above.
NAICS.com
- Role: Descriptions for industry classification codes.
- Data class: A NAICS industry code (a number). No tenant data.
- Region: United States.
- Contractual basis: Provider's published API terms.
- Training commitment: Per the provider's stated terms.
- Feature flag:
ENABLE_ENRICHMENTplus the account and policy controls above.
Parse.bot
- Role: Structured extraction from known carrier web pages, used as a fast path before generic scraping in the web-research pipeline.
- Data class: A public target URL and a carrier name. No insured data and no tenant document content is transmitted.
- Region: United States.
- Contractual basis: Parse.bot terms.
- Training commitment: Per the provider's stated terms.
- Feature flag:
ENABLE_ENRICHMENTand a configuredPARSE_BOT_API_KEY.
Also engaged by enrichment: OpenAI (section 1.3) performs the business-classification step and any web search that could carry the insured's name or address — personal-data queries are routed to OpenAI, on the terms described in section 1.3, specifically so they never reach Tavily. Tavily, Jina Reader and Firecrawl (section 2.2) may be engaged for the non-personal web-research portion, on the terms described there.
2.4. Meeting Assistant (coming soon — not used in the production Service today)
The meeting assistant, in which Mia joins a Microsoft Teams meeting as an AI notetaker, and AI voice interviews are not yet available in the production Service. When they launch, they will use the voice and meeting service, Deepgram, and the language-model providers listed in Section 1, and the provider below. We will give the notice described in Section 5 before any customer data is sent to it.
Recall.ai
- Role: Meeting bot that joins a meeting and captures its audio for transcription.
- Data class: Tenant data (meeting audio and participant names).
- Region: United States.
- Contractual basis: Recall.ai terms of service and data processing agreement.
- Training and retention: Per Recall.ai's terms; retention to be configured to the minimum the feature requires before launch.
- Status: Not used in production until the meeting assistant launches.
3. Dormant — Listed for Transparency
The following providers have an API key slot reserved in our configuration for a planned future integration. There is no code in the product that calls any of them, so no customer data has ever been sent to them. They are disclosed here for full transparency. Each will be moved to the Active list above with 30 days' advance notice before any customer data is sent.
- AM Best — carrier financial ratings. Carrier ratings today come from the web-research pipeline, not from an AM Best API.
- Dun & Bradstreet (D&B) — business firmographics.
- Middesk — entity verification.
- OpenCorporates — corporate registry lookup.
- OFAC — sanctions screening.
- NCCI — workers' compensation class codes. Class-code descriptions today are served from a table built into the product; no NCCI API call is made.
- Realie — property data.
Listed for transparency. Not currently transmitting data. Will be moved to Active with 30 days' advance notice before any customer data is sent.
4. Not Sub-Processors
For completeness: MaxMind licenses us the GeoLite2 database we use to determine the country of a request; the lookup runs on our own servers and no request data is sent to MaxMind. Third-party AI assistants you connect to your account (for example, Claude or ChatGPT) receive information at your direction and under your own agreement with their provider; they are not our sub-processors (Privacy Policy § 5.6).
5. Notice of Changes
Before engaging any new sub-processor that will receive customer data, we will:
- Update this page to reflect the new entry, including its role, data class, region, and contractual basis, and record the change in the change log below.
- Provide at least 30 days' advance notice to customers by email to account holders and by a notice in the Service.
- Update the "Effective Date" at the top of this page.
Customers who object to a proposed new sub-processor should contact us at [email protected] during the notice period to discuss available options, which may include not using the feature that depends on it.
6. Change Log
- October 1, 2026. Listed Google Fonts (visitors' IP addresses are sent to Google when a page loads fonts from its servers). Corrected Plausible's scope: it runs across the site except the excluded areas, not on public pages only. Stated that the voice service provider keeps its own copy of Talk to Mia transcripts. Clarified that S3 applies server-side encryption by default in addition to our application-layer encryption.
- September 28, 2026. Added the providers that support Talk to Mia, which were in use but not listed: the voice and meeting service (software licensed from AI Meetings LLC), xAI (default voice model), and Deepgram (speech-to-text); and noted OpenAI's alternative real-time voice model. Listed Recall.ai as a provider for the meeting assistant, which is not yet in production. Added Cloudflare's full role (network, firewall, and geographic access restriction) and Google Maps static images. Corrected the Microsoft Graph permissions to the full set we request. Corrected the OCR description: both Mistral AI (which may process data in the European Union) and LLMWhisperer are used, either of which may run first. Replaced blanket "zero-retention / enterprise tier" statements with each provider's own training and retention terms. Limited Plausible to public pages. Removed the Meetings AI (aimeetings.net) entry, which is replaced by the voice and meeting service entry. We are sending notice of this update to account holders by email and in the Service; because these providers were already in use when this page was updated, this notice is given after the fact rather than 30 days in advance.
- August 19, 2026. Data enrichment roster regenerated from the product's vendor manifest; Parse.bot moved from Dormant to Active; seven reserved vendors listed as Dormant.
7. Contact Information
For questions about this Sub-Processors page or our vendor management program, please contact us at: