Last Updated: February 2026
This page lists all third-party subprocessors that Gradient AO, LLC (doing business as Gradient CIO) engages to process personal data on behalf of our customers. We maintain this list in accordance with our Privacy Policy and Data Processing Addendum.
Notice of Changes: We will provide at least thirty (30) days' advance notice of any additions or replacements to this list. Customers may object to new subprocessors as described in our Data Processing Addendum.
Clerk provides secure authentication services including login, registration, session management, and multi-factor authentication for our Platform. Clerk maintains SOC 2 Type II compliance aligned with Trust Services Criteria and implements comprehensive security controls including multi-factor authentication, role-based access control, and encryption in transit and at rest.
Compliance Documentation: Clerk Trust Center
Stripe processes payment transactions, manages subscriptions, and handles billing for our Platform. Stripe is PCI DSS Level 1 certified (the highest level of payment card security certification), SOC 1 Type II and SOC 2 Type II compliant, and ISO 27001 certified. Stripe maintains one of the most rigorous security and compliance programs in the payment processing industry.
Compliance Documentation: Stripe Security & Compliance
Railway provides cloud infrastructure, hosting services, and operational monitoring for the Platform. This includes PostgreSQL database hosting (enterprise-grade relational database for portfolio data storage), Redis cache hosting (high-performance in-memory store for session management and performance optimization), application servers, load balancing, and automated deployment systems. Railway is SOC 2 Type II certified and SOC 3 certified, demonstrating independent verification of security, availability, processing integrity, confidentiality, and privacy controls across their infrastructure. PostgreSQL provides ACID-compliant transactional consistency and data integrity guarantees essential for financial applications. Railway implements automated database backups, point-in-time recovery, encryption at rest and in transit, and geographic redundancy to ensure data availability and business continuity.
Compliance Documentation: Railway Trust Center
Resend delivers transactional emails including account notifications, password resets, billing confirmations, and security alerts. Resend provides reliable email infrastructure with SPF, DKIM, and DMARC authentication to ensure email deliverability and prevent spoofing.
Compliance Documentation: Resend Security & Compliance
Cloudflare provides network security including DDoS protection, web application firewall (WAF), content delivery network (CDN), and global traffic management for the Platform. Cloudflare is SOC 2 Type II certified, ISO 27001 certified, and PCI DSS compliant. Cloudflare's global network spans over 300 cities worldwide, providing low-latency access and protection against cyber threats.
Compliance Documentation: Cloudflare Trust Hub
Sentry provides application performance monitoring, error tracking, and real-time alerting for the Platform. Sentry monitors application health, tracks software errors, captures performance issues, and provides diagnostic context to enable rapid identification and resolution of technical issues. Sentry is SOC 2 Type II certified, ISO 27001 certified, GDPR compliant, and HIPAA compliant. Sentry processes technical telemetry data including error logs, stack traces, performance metrics, and application events to support platform reliability and operational monitoring.
Compliance Documentation: Sentry Security & Compliance
The Platform uses artificial intelligence and machine learning technologies to provide analytics, capital market assumptions, and intelligent assistance features. These AI subprocessors process platform usage data and portfolio metadata as necessary to provide AI-powered features. Customer portfolio data is not used to train AI models without explicit customer consent.
m-qubit.ai provides machine learning algorithms and intellectual property for generating AI-recommended capital market expectations including expected returns, volatilities, and correlations used in portfolio analytics. The ML models are trained on 30+ years of historical market data, economic indicators, and institutional forecasts to provide forward-looking capital market assumptions that adjust for current market conditions.
Anthropic provides large language model APIs (Claude models) for intelligent assistant features including natural language query processing, portfolio analysis interpretation, and interactive guidance within the Platform. Anthropic is SOC 2 Type II certified and maintains enterprise-grade security practices including data encryption, access controls, and comprehensive monitoring.
Compliance Documentation: Anthropic Trust Center
Note on AI Providers: The Platform may use additional AI model providers including but not limited to OpenAI and other leading AI research organizations. The specific AI models deployed may vary by feature and are subject to change as technology evolves. All AI providers are contractually required to implement appropriate data protection measures and not use customer portfolio data for model training without explicit consent.
All subprocessors are contractually required to implement appropriate technical and organizational measures to protect personal data and comply with applicable data protection laws, including GDPR and CCPA.
Personal data may be transferred to and processed by subprocessors in the United States. Where required, we use Standard Contractual Clauses (SCCs) or other appropriate safeguards to ensure adequate protection of personal data transferred outside the European Economic Area, United Kingdom, or Switzerland.
For questions about our subprocessors or data processing practices, please contact us at [email protected].
← Back to Home