Sub-processors
Last updated: August 6, 2026
Yomigo AI uses the third-party services below to operate the platform. Each sub-processor is contractually bound to handle data only as required to deliver their service.
HIPAA status — stated plainly. Our Business Associate Agreement coverage is not yet complete across the voice stack. Google Cloud — which covers Firestore, Cloud Storage, Cloud Run, Vertex AI and Google Cloud Text-to-Speech — has an executed BAA. Twilio, LiveKit, Deepgram and Sentry do not. Those four sit in the path that carries call audio, so until this table shows them executed, Yomigo is not in a position to support Protected Health Information and you should not route PHI through the platform. We would rather tell you this than let a badge imply otherwise.
We notify workspace owners by email at least 14 days before adding or replacing any sub-processor that processes customer data. Questions: privacy@yomigo.ai.
| Vendor | Service | Data categories | Region | HIPAA |
|---|---|---|---|---|
| Google Cloud / Firebase | Hosting, Firestore, Cloud Functions, Cloud Storage, Identity | Account data, workspace data, call metadata + transcripts, recordings | United States | BAA in place |
| Twilio | PSTN voice, SMS, SIP trunking, number provisioning, 10DLC | Caller phone numbers, call audio (transit), SMS bodies | United States | BAA not in place BAA not yet executed. Requires Twilio Security or Enterprise Edition. Carries call audio and SMS bodies, so this is a required agreement before any PHI use. |
| LiveKit Cloud | Real-time media infrastructure, SIP termination | Call audio (transit only — not persisted) | United States | BAA not in place HIPAA-eligible subscription tier is active; the BAA itself is not yet executed. |
| Deepgram | Speech-to-text (caller speech → transcript) | Call audio (transit), unredacted transcripts (briefly, in-memory only) | United States | BAA not in place BAA request in progress. Receives raw caller audio on every call, so this is a required agreement before any PHI use. |
| Cartesia | Text-to-speech (agent voice synthesis) | Agent-generated text (no caller PHI flows here) | United States | BAA verifying BAA signed by Yomigo; awaiting confirmation of the countersigned copy. Care/behavioral-health calls do not route here — they are pinned to Google Cloud Text-to-Speech. |
| Google AI (Gemini) | Large language model — conversational reasoning | Conversation context (redacted for HIPAA workspaces) | United States | BAA in place Vertex AI tier with BAA; consumer Gemini API is not BAA-covered |
| Anthropic Claude (served via Google Vertex AI) | Safety-only crisis classifier on behavioral-health calls — never the conversational model | Single caller utterance, on ambiguous turns only; returns a category label, no free text | United States | BAA n/a Runs inside Google Vertex AI Model Garden under our executed Google Cloud BAA — the data does not leave Google, so no separate Anthropic agreement applies. A deliberately different model family from our primary model, so the two do not share blind spots. |
| Google Calendar (customer-initiated) | Appointment booking on a calendar the customer connects | Free/busy availability (read) and appointment events Yomigo creates on the connected calendar; OAuth refresh token (encrypted) | United States | BAA n/a Google Calendar is a Google Workspace service and is not covered by our Google Cloud BAA — coverage for your calendar comes from your own Workspace agreement with Google. Access is limited to events Yomigo books plus free/busy — never your other calendar events. |
| Sentry | Error monitoring and observability | Error events, stack traces (PHI fields scrubbed before send) | United States | BAA not in place BAA not yet executed. Yomigo scrubs PHI before events leave the worker (stack-frame locals disabled, fail-closed redaction), so no PHI is expected to reach Sentry. |
| Stripe | Payment processing and subscription billing | Billing contact, payment method (PCI-scoped to Stripe — Yomigo does not see card data) | United States | BAA n/a No PHI processed through billing pipeline |
| Resend | Transactional email (welcome, invites, billing receipts) | Email addresses, transactional message bodies | United States | BAA n/a Transactional email only — Yomigo does not send PHI by email. Identifiers in operational alerts are masked for HIPAA workspaces. |
A note on BAA scope
A BAA between Yomigo and a sub-processor does not, by itself, make a customer's use of Yomigo HIPAA-compliant. HIPAA compliance is a posture relative to a specific workflow. Customers who transmit PHI through Yomigo must (a) execute a BAA with Yomigo (Custom plan), (b) enable HIPAA workspace mode, and (c) design their agent's behavior so it doesn't ask for information that isn't necessary. See our Privacy Policy and Terms of Service for full obligations.