Subprocessors
Effective September 24, 2026
Altyst uses the following third-party subprocessors to operate the Service. Each receives only the data necessary for its function. We will update this page and, where required, notify customers of material changes.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Railway (Railway Corp.) | Application hosting (API + worker), managed PostgreSQL, managed Redis | All application data at rest and in transit within the platform (accounts, deals, extracted data, job payloads) | US |
| Amazon Web Services (S3) | Object storage for uploaded documents and generated exports | Uploaded source documents and generated workbooks/PDFs | US (us-west-2) |
| Anthropic (Anthropic PBC) | AI extraction, document understanding, listing reads, location research, narrative generation | Document text and prompts derived from uploads, sent when a document is read; pasted listing links; a deal's property address and type, sent for location research when a deal that has an address is opened. Financial outputs are computed by the deterministic engine, not the model. | US |
| Stripe (Stripe, Inc.) | Payments + merchant of record + tax | Billing email, payment method (handled entirely by Stripe), transaction and subscription data | US |
| Vercel (Vercel Inc.) | Frontend hosting + CDN | Serves the web app; receives HTTP request metadata. No customer documents pass through Vercel. | Global edge |
| Resend (Resend, Inc.) or Postmark (ActiveCampaign, LLC), whichever is configured as the transactional email provider | Account, verification, and notification email | Recipient email address and message content | US |
| Google (Google LLC) | Ads conversion measurement on the public site and app (the Google tag) | Page URL and standard request metadata for pages you visit while the tag runs; a Google advertising cookie. No deal or document content. See the Cookie Notice and opt-out link there. | US |
| GitHub (Microsoft) | Source control + CI (not a runtime data processor) | Source code only; no customer data | — |
Sign-in runs through Google or Microsoft as your OpenID Connect identity provider. In that role the provider processes your sign-in under its own terms as an independent controller of your account with it — it is not our subprocessor — and we receive only your email, name, and a provider account identifier, as the Privacy Policy describes.
Data flows (summary)
- Documents: browser → Altyst API → AWS S3 (stored, content-addressed, org-scoped keys); text extracted server-side; extraction may call Anthropic.
- Location research: a deal's address and property type → Anthropic, when a deal that has an address is opened.
- Location facts: a U.S. deal address → the U.S. Census Bureau geocoder and data API and the FEMA flood-map service. These are public government lookups, not subprocessors; they receive the address only.
- Deterministic underwriting: computed in-process; no external processor.
- Payments: handled by Stripe as merchant of record; Altyst never sees card numbers.
- Backups: encrypted logical backups → AWS S3.
Questions: support@altyst.ai.
Altyst — commercial real-estate underwriting software. Effective September 24, 2026. Version 1.4. Questions about this document: support@altyst.ai.