Back to home

Sub-processors

Last updated: August 6, 2026

Yomigo AI uses the third-party services below to operate the platform. Each sub-processor is contractually bound to handle data only as required to deliver their service.

HIPAA status — stated plainly. Our Business Associate Agreement coverage is not yet complete across the voice stack. Google Cloud — which covers Firestore, Cloud Storage, Cloud Run, Vertex AI and Google Cloud Text-to-Speech — has an executed BAA. Twilio, LiveKit, Deepgram and Sentry do not. Those four sit in the path that carries call audio, so until this table shows them executed, Yomigo is not in a position to support Protected Health Information and you should not route PHI through the platform. We would rather tell you this than let a badge imply otherwise.

We notify workspace owners by email at least 14 days before adding or replacing any sub-processor that processes customer data. Questions: privacy@yomigo.ai.

VendorServiceData categoriesRegionHIPAA
Google Cloud / Firebase Hosting, Firestore, Cloud Functions, Cloud Storage, IdentityAccount data, workspace data, call metadata + transcripts, recordingsUnited States
BAA in place
Twilio PSTN voice, SMS, SIP trunking, number provisioning, 10DLCCaller phone numbers, call audio (transit), SMS bodiesUnited States
BAA not in place

BAA not yet executed. Requires Twilio Security or Enterprise Edition. Carries call audio and SMS bodies, so this is a required agreement before any PHI use.

LiveKit Cloud Real-time media infrastructure, SIP terminationCall audio (transit only — not persisted)United States
BAA not in place

HIPAA-eligible subscription tier is active; the BAA itself is not yet executed.

Deepgram Speech-to-text (caller speech → transcript)Call audio (transit), unredacted transcripts (briefly, in-memory only)United States
BAA not in place

BAA request in progress. Receives raw caller audio on every call, so this is a required agreement before any PHI use.

Cartesia Text-to-speech (agent voice synthesis)Agent-generated text (no caller PHI flows here)United States
BAA verifying

BAA signed by Yomigo; awaiting confirmation of the countersigned copy. Care/behavioral-health calls do not route here — they are pinned to Google Cloud Text-to-Speech.

Google AI (Gemini) Large language model — conversational reasoningConversation context (redacted for HIPAA workspaces)United States
BAA in place

Vertex AI tier with BAA; consumer Gemini API is not BAA-covered

Anthropic Claude (served via Google Vertex AI) Safety-only crisis classifier on behavioral-health calls — never the conversational modelSingle caller utterance, on ambiguous turns only; returns a category label, no free textUnited States
BAA n/a

Runs inside Google Vertex AI Model Garden under our executed Google Cloud BAA — the data does not leave Google, so no separate Anthropic agreement applies. A deliberately different model family from our primary model, so the two do not share blind spots.

Google Calendar (customer-initiated) Appointment booking on a calendar the customer connectsFree/busy availability (read) and appointment events Yomigo creates on the connected calendar; OAuth refresh token (encrypted)United States
BAA n/a

Google Calendar is a Google Workspace service and is not covered by our Google Cloud BAA — coverage for your calendar comes from your own Workspace agreement with Google. Access is limited to events Yomigo books plus free/busy — never your other calendar events.

Sentry Error monitoring and observabilityError events, stack traces (PHI fields scrubbed before send)United States
BAA not in place

BAA not yet executed. Yomigo scrubs PHI before events leave the worker (stack-frame locals disabled, fail-closed redaction), so no PHI is expected to reach Sentry.

Stripe Payment processing and subscription billingBilling contact, payment method (PCI-scoped to Stripe — Yomigo does not see card data)United States
BAA n/a

No PHI processed through billing pipeline

Resend Transactional email (welcome, invites, billing receipts)Email addresses, transactional message bodiesUnited States
BAA n/a

Transactional email only — Yomigo does not send PHI by email. Identifiers in operational alerts are masked for HIPAA workspaces.

A note on BAA scope

A BAA between Yomigo and a sub-processor does not, by itself, make a customer's use of Yomigo HIPAA-compliant. HIPAA compliance is a posture relative to a specific workflow. Customers who transmit PHI through Yomigo must (a) execute a BAA with Yomigo (Custom plan), (b) enable HIPAA workspace mode, and (c) design their agent's behavior so it doesn't ask for information that isn't necessary. See our Privacy Policy and Terms of Service for full obligations.