Loading...
Last updated: August 25, 2026
IngestX uses third-party providers selectively to operate and support its services.
The exact provider set can vary by product scope, deployment model, region, support arrangement, and customer-specific implementation.
Inclusion below confirms only that an integration is visible in the repository. It does not establish that a provider is enabled in production, acts as a Sub-Processor for every customer, or applies to every deployment.
Before relying on this register for procurement or contracting, the open TODOs must be reconciled against the approved production configuration and applicable customer agreement.
The following named services are visible in the repository and may process the listed data when the relevant feature is enabled. Processing regions are intentionally left as TODOs where the repository does not establish a deployment-applicable fact.
| Provider | Service / purpose | Data processed | Processing region |
|---|---|---|---|
| Cloudflare | Optional bot protection and human verification | IP address, device, request, and challenge data | TODO: Confirm the services enabled and their applicable processing regions. |
| Google Analytics | Optional public-website analytics | Cookie identifiers, device, and usage data | TODO: Confirm production enablement and applicable processing regions. |
| Google Workspace APIs | Optional customer-authorized OAuth, Gmail, or Drive integrations | Account identifiers, OAuth tokens, email or file metadata, and customer-selected content | TODO: Confirm the enabled APIs, tenant configuration, and applicable processing regions. |
| Microsoft Graph / Entra | Optional customer-authorized OneDrive, SharePoint, Outlook, or identity integrations | Account identifiers, OAuth tokens, file or email metadata, and customer-selected content | TODO: Confirm the enabled APIs, tenant configuration, and applicable processing regions. |
| Groq | Optional external AI and OCR inference | Submitted prompts and Customer Content, which may include document images, text, or structured fields | TODO: Confirm production enablement, approved data classes, retention configuration, and applicable processing regions. |
| Replicate | Optional external AI and OCR inference | Submitted prompts and Customer Content, which may include complete document images | TODO: Confirm production enablement, approved model version, retention configuration, and applicable processing regions. |
| Resend | Optional transactional email delivery | Recipient, routing, and message data | TODO: Confirm production enablement and applicable processing regions. |
| Xendit | Optional checkout, payment, and webhook processing | Billing contact, order, and transaction data | TODO: Confirm production enablement, legal role, and applicable processing regions. |
| DOKU | Optional payment and billing processing | Billing contact, order, and transaction data | TODO: Confirm production enablement, legal role, and applicable processing regions. |
| Fast2SMS | Optional SMS and OTP delivery | Phone number and OTP-routing metadata | TODO: Confirm production enablement, legal role, and applicable processing regions. |
A provider’s presence in the codebase does not mean it is enabled for every customer. The order form or Data Processing Addendum controls where a customer-specific commitment is required.
Customers and prospective customers may request the current applicable vendor and subprocessor information during formal legal, procurement, or security review. A current list can be provided under NDA where appropriate, including:
For legal or procurement review, contact [email protected].
For security-focused diligence questions, contact [email protected].
Any commitment about prior approval, advance notice, region restrictions, or Indonesia-only processing should be confirmed in the applicable customer agreement, order form, or implementation scope.