Audit artefacts
Evidence an auditor accepts
Two exports built from the same cited evidence as the rest of Verax: a pre-fill of the DORA register templates we can actually support, and a hashed ISO/IEC 42001 evidence pack. Both are scoped to the AI vendors this workspace was observed using — a provider you do not use does not belong in your register.
DORA register of information
Download B_05.02 CSVRegulation (EU) 2022/2554 (DORA), Art. 28(3) · Commission Implementing Regulation (EU) 2024/2956
What the supply chain says, and what it does not
An empty supply chain means we hold no sub-processor evidence for that provider — not that it has none.
91 of 91 sub-processor relationships carry a source URL. Uncited relationships are our record of a vendor disclosure and should be confirmed against the vendor's own sub-processor list before you rely on them.
13 of 91 links are the provider's own group entities (matched on a shared brand name). They are genuine sub-processors but not third-party ICT providers — DORA registers intra-group arrangements separately. A group company trading under an unrelated name will not be caught, so treat this as a reviewer's hint, not a determination.
Published, but unreadable
3 provider(s) publish a sub-processor list only through a JavaScript trust portal we cannot read without executing scripts. The list exists — we simply cannot cite it, so it is reported as unread rather than as absent. Request it from the vendor directly.
Anthropic Claude · Fireflies.ai · Perplexity AI
Nothing held
No sub-processor source is known for these providers at all — distinct from the ones above, where the vendor does publish a list we cannot cite. Ask these for one.
Google Gemini · Slack AI
| Rank | Provider | Receives from | Role | Type | Evidence |
|---|---|---|---|---|---|
| 2 | Amazon Web Services Inc (AWS) | GitHub Copilot | Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services | third party | docs.github.com |
| 2 | Anthropic PBC | GitHub Copilot | AI Inference and AI Services | third party | docs.github.com |
| 2 | Cerebras Systems Inc. | GitHub Copilot | AI Inference and AI Services | third party | docs.github.com |
| 2 | Cloudflare | GitHub Copilot | Content delivery service | third party | docs.github.com |
| 2 | Elasticsearch, Inc. | GitHub Copilot | Cloud Hosted Infrastructure | third party | docs.github.com |
| 2 | Fastly | GitHub Copilot | Content delivery service | third party | docs.github.com |
| 2 | Fireworks AI | GitHub Copilot | AI Inference and AI Services | third party | docs.github.com |
| 2 | FullStory, Inc. | GitHub Copilot | Customer support ticketing analysis | third party | docs.github.com |
| 2 | Google Cloud Platform (GCP) | GitHub Copilot | Cloud Hosted Infrastructure, AI Inference and AI Services | third party | docs.github.com |
| 2 | Hewlett-Packard Limited | GitHub Copilot | Cloud Hosted Infrastructure | third party | docs.github.com |
| 2 | LambdaTest | GitHub Copilot | Cloud Hosted Infrastructure | third party | docs.github.com |
| 2 | Microsoft (Azure) | GitHub Copilot | Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services | third party | docs.github.com |
| 2 | Moveworks | GitHub Copilot | Customer support ticketing analysis | third party | docs.github.com |
| 2 | NexMo Inc (aka Vonage) | GitHub Copilot | SMS notification provider for 2 Factor Authentication | third party | docs.github.com |
| 2 | Obsidian Security | GitHub Copilot | Security management | third party | docs.github.com |
| 2 | OpenAI | GitHub Copilot | AI Inference and AI Services | third party | docs.github.com |
| 2 | Oracle America, Inc. | GitHub Copilot | Cloud Hosted Infrastructure | third party | docs.github.com |
| 2 | Pusher | GitHub Copilot | Building and managing real-time infrastructure for web and mobile applications | third party | docs.github.com |
| 2 | Tines Automation Inc. | GitHub Copilot | Security management | third party | docs.github.com |
| 2 | Twilio (SendGrid) | GitHub Copilot | SMS notification provider for 2 Factor Authentication | third party | docs.github.com |
| 2 | xAI | GitHub Copilot | AI Inference and AI Services | third party | docs.github.com |
| 2 | Zendesk | GitHub Copilot | Customer support ticketing system | third party | docs.github.com |
| 2 | GitHub Australia Pty Ltd | GitHub Copilot | GitHub Subsidiary | intra-group | docs.github.com |
| 2 | GitHub BV | GitHub Copilot | GitHub Subsidiary | intra-group | docs.github.com |
| 2 | GitHub Canada ULC | GitHub Copilot | GitHub Subsidiary | intra-group | docs.github.com |
| 2 | GitHub Germany GmbH | GitHub Copilot | GitHub Subsidiary | intra-group | docs.github.com |
| 2 | GitHub India Pty Ltd | GitHub Copilot | GitHub Subsidiary | intra-group | docs.github.com |
| 2 | npm Inc | GitHub Copilot | GitHub Subsidiary | intra-group | docs.github.com |
| 2 | Semmle Inc | GitHub Copilot | GitHub Subsidiary | intra-group | docs.github.com |
| 2 | Anthropic | Grammarly | Generative AI provider | third party | superhuman.com |
| 2 | AWS | Grammarly | Data hosting and product infrastructure | third party | superhuman.com |
| 2 | Azure | Grammarly | Generative AI provider | third party | superhuman.com |
| 2 | Baseten | Grammarly | Infrastructure provider | third party | superhuman.com |
| 2 | Databricks | Grammarly | Data analytics and infrastructure provider | third party | superhuman.com |
| 2 | Dyspatch (SendWithUs) | Grammarly | Platform provider for cloud communications | third party | superhuman.com |
| 2 | Fivetran | Grammarly | Security and maintenance for internal analytics and debugging | third party | superhuman.com |
| 2 | Grammarly | Infrastructure provider | third party | superhuman.com | |
| 2 | Iterable | Grammarly | Platform provider for cloud communications | third party | superhuman.com |
| 2 | Imgix | Grammarly | Platform provider for image and file caching and serving | third party | superhuman.com |
| 2 | OpenAI | Grammarly | Generative AI provider | third party | superhuman.com |
| 2 | Sumo Logic | Grammarly | Security and maintenance for service monitoring, security event management, and debugging | third party | superhuman.com |
| 2 | Turbopuffer | Grammarly | Infrastructure provider | third party | superhuman.com |
| 2 | Twilio | Grammarly | Platform provider for cloud communications | third party | superhuman.com |
| 2 | Zendesk | Grammarly | Customer support provider for ticketing management | third party | superhuman.com |
| 2 | Superhuman Platform Inc. | Grammarly | Provision of services in accordance with the Data Privacy Addendum | third party | superhuman.com |
| 2 | Grammarly Germany GmbH | Grammarly | Provision of services in accordance with the Data Privacy Addendum | intra-group | superhuman.com |
| 2 | Limited Liability Company “Grammarly Ukraine” | Grammarly | Provision of services in accordance with the Data Privacy Addendum | intra-group | superhuman.com |
| 2 | Grammarly Canada LLC | Grammarly | Provision of services in accordance with the Data Privacy Addendum | intra-group | superhuman.com |
| 2 | Coda Project, LLC | Grammarly | Provision of services in accordance with the Data Privacy Addendum | third party | superhuman.com |
| 2 | Superhuman Labs LLC | Grammarly | Provision of services in accordance with the Data Privacy Addendum | third party | superhuman.com |
| 2 | Anthropic | Microsoft Copilot | LLM provider / AI model provider | third party | learn.microsoft.com |
| 2 | OpenAI | Microsoft Copilot | LLM provider / AI model provider | third party | learn.microsoft.com |
| 2 | Cloudflare, Ltd. | OpenAI ChatGPT | Content delivery network provider, Web Hosting | third party | openai.com |
| 2 | Microsoft Corporation | OpenAI ChatGPT | Cloud infrastructure | third party | openai.com |
| 2 | CoreWeave, Inc. | OpenAI ChatGPT | Cloud infrastructure | third party | openai.com |
| 2 | Oracle Cloud Infrastructure | OpenAI ChatGPT | Cloud infrastructure | third party | openai.com |
| 2 | Google Cloud Platform | OpenAI ChatGPT | Cloud infrastructure | third party | openai.com |
| 2 | Amazon Web Services, Inc. | OpenAI ChatGPT | Cloud infrastructure | third party | openai.com |
| 2 | Cerebras | OpenAI ChatGPT | Cloud infrastructure | third party | openai.com |
| 2 | Snowflake, Inc. | OpenAI ChatGPT | Data warehousing | third party | openai.com |
| 2 | TaskUs, LLC | OpenAI ChatGPT | Customer support, Moderation of content, Moderation of GPTs | third party | openai.com |
| 2 | Intercom, Inc. | OpenAI ChatGPT | Customer support | third party | openai.com |
| 2 | Salesforce | OpenAI ChatGPT | Customer support | third party | openai.com |
| 2 | Pylon Labs | OpenAI ChatGPT | Customer support | third party | openai.com |
| 2 | Accenture International Limited | OpenAI ChatGPT | Customer support, Moderation of content | third party | openai.com |
| 2 | Fivetran, Inc. | OpenAI ChatGPT | ETL provider | third party | openai.com |
| 2 | Confluent | OpenAI ChatGPT | Infrastructure management | third party | openai.com |
| 2 | Cinder Technologies, Inc. | OpenAI ChatGPT | Platform for content moderation, Platform for moderation of GPTs | third party | openai.com |
| 2 | WorkOS, Inc. | OpenAI ChatGPT | Cross-domain identity management | third party | openai.com |
| 2 | Okta, Inc. | OpenAI ChatGPT | User authentication services (via Auth0) | third party | openai.com |
| 2 | Merge API, Inc. | OpenAI ChatGPT | Infrastructure management | third party | openai.com |
| 2 | OpenAI Ireland Ltd. | OpenAI ChatGPT | Technical and operational support for the Services | intra-group | openai.com |
| 2 | OpenAI UK Ltd. | OpenAI ChatGPT | Technical and operational support for the Services | intra-group | openai.com |
| 2 | OpenAI Japan Ltd. | OpenAI ChatGPT | Technical and operational support for the Services | intra-group | openai.com |
| 2 | Amazon Web Services, Inc. | Otter.ai | Cloud service provider and customer data storage platform | third party | otter.ai |
| 2 | Zendesk | Otter.ai | Cloud-based customer support services | third party | otter.ai |
| 2 | OneSignal | Otter.ai | Customer engagement and push notifications | third party | otter.ai |
| 2 | Stripe | Otter.ai | Cloud-based Payment Processing | third party | otter.ai |
| 2 | Zuora | Otter.ai | Subscription Management & Billing | third party | otter.ai |
| 2 | Slack | Otter.ai | Internal messaging platform for communications | third party | otter.ai |
| 2 | Anthropic | Otter.ai | Provider for backend support of AI-enabled functionality | third party | otter.ai |
| 2 | OpenAI | Otter.ai | Provider for evaluating the effectiveness of our Large Language Models (LLM) | third party | otter.ai |
| 2 | Intercom | Otter.ai | Support services | third party | otter.ai |
| 2 | Research Transcriptions | Otter.ai | Provider for annotating training and evaluation data for our product features | third party | otter.ai |
| 2 | Workato | Otter.ai | Provider for building automations and integrations | third party | otter.ai |
| 2 | Google Cloud Platform | Otter.ai | Cloud service provider | third party | otter.ai |
| 2 | Crusoe | Otter.ai | Cloud service provider | third party | otter.ai |
| 2 | Crescendo | Otter.ai | Customer-initiated support cases processing | third party | otter.ai |
| 2 | WorkOS | Otter.ai | Directory sync for enterprise login workflow | third party | otter.ai |
| 2 | PlanHat | Otter.ai | Customer Success platform for post-sales lifecycle | third party | otter.ai |
| 2 | On24 | Otter.ai | Webinar and virtual event hosting platform | third party | otter.ai |
Templates this export does not cover
- — B_01.01–B_01.03 — the entity maintaining the register, entities in scope, and branches. Yours, not the vendor's.
- — B_02.01–B_02.03 — contractual arrangements, terms, dates and value. These live in your contract management system.
- — B_03.01–B_03.03 — signing entities and providers per contract.
- — B_04.01 — entities making use of the ICT service.
- — B_06.01 — identification of functions, and B_07.01 — assessment of ICT services supporting critical or important functions. Criticality is a judgement about YOUR business processes; we have no basis to assert it.
A pre-fill of two register templates from published vendor evidence — not a submission-ready register and not legal advice. Cells we hold no evidence for are left empty and listed in `to_complete`; they must be completed from your contracts and your own criticality assessment before anything is filed with a competent authority.
ISO/IEC 42001 evidence pack
Download JSONRead the dates, not just the scores
7 of 10 records carry no last-verified date. Completeness scores field coverage, not recency — an undated record may be fully populated and still out of date. Treat those rows as unconfirmed.
Undated: Anthropic Claude, GitHub Copilot, Grammarly, Microsoft Copilot, OpenAI ChatGPT, Otter.ai, Perplexity AI
Content hash
7e07d37c1083d8daa4ae937606be3cc91cfc1afa6e8ddddc151a95086bd5f2c5
The body object only, excluding generated_at, so unchanged evidence hashes identically across dates. Re-export at any time and compare: an identical hash shows the underlying evidence has not moved, and a pack edited after the fact will not reproduce it.
Anthropic Claude
field coverage 1.00 · no verification dateA.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II, ISO 27001 No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: www.anthropic.com, privacy.anthropic.com
Fireflies.ai
field coverage 1.00 · verified 2026-06-27A.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II, GDPR, HIPAA No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: fireflies.ai, fireflies.ai, guide.fireflies.ai, guide.fireflies.ai
GitHub Copilot
field coverage 0.85 · no verification dateA.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: docs.github.com
Google Gemini
field coverage 0.85 · verified 2026-07-18A.10.3 Suppliers of AI systems and services — applies
Basis: certifications: ISO 27001, SOC 2 Type II No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: support.google.com, cloud.google.com
Grammarly
field coverage 0.85 · no verification dateA.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II, ISO 27001 No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: www.grammarly.com
Microsoft Copilot
field coverage 1.00 · no verification dateA.10.3 Suppliers of AI systems and services — applies
Basis: certifications: ISO 27001, SOC 2 Type II No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: learn.microsoft.com, learn.microsoft.com
OpenAI ChatGPT
field coverage 1.00 · no verification dateA.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: openai.com
Otter.ai
field coverage 0.85 · no verification dateA.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: otter.ai
Perplexity AI
field coverage 0.80 · no verification dateA.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: www.perplexity.ai
Slack AI
field coverage 0.93 · verified 2026-06-27A.10.3 Suppliers of AI systems and services — applies
Basis: certifications: SOC 2 Type II, ISO 27001 No AI-management certification identified; assurance must come from your own supplier assessment.
Sources: slack.com, slack.com, slack.engineering
Supplier-facing evidence assembled from published vendor documentation on the dates shown. It is not a certification, not an audit opinion, and not a compliance determination. It covers third-party AI services this workspace was observed using; it does not assess your organisation's own AI systems, which carry separate obligations.
Both artefacts are also available over the API — see integrations for how to authenticate with your workspace key.