DPA summary & sub-processors
Honest summary for self-hosted ReboundPad. A counsel-drafted DPA / MSA is still required for enterprise contracts. Last updated 2026-09-30.
Self-hosted (primary)
For a customer-operated deployment, ReboundPad is typically not a processor of customer prompts, credentials, or flow data, because that data never leaves the customer environment. There are no ReboundPad sub-processors for that data path.
Details: product pack compliance/SUBPROCESSORS.md and compliance/SHARED_RESPONSIBILITY.md.
What customers usually process themselves
- Model providers (Azure OpenAI, Bedrock, Vertex, Ollama, gateways)
- Cloud / on-prem infrastructure
- Connector targets (Jira, Slack, databases, …)
- Optional observability backends
Those relationships are between the customer and those vendors.
Self-hosted cloud ops vs hosted SaaS
Self-hosted cloud ops (tenants/regions/provisioning + Helm/TF on your infrastructure) is GA. ReboundPad-hosted multi-cloud SaaS with billing/SLA is not offered. If/when a hosted control plane processes customer data, a formal sub-processor list and DPA will be published before that offering is sold. Do not treat this page as authorization to process regulated data in a ReboundPad-hosted environment today.
Marketing site
Demo-request email content is handled as ordinary sales correspondence. See Privacy.
Next step for procurement
Request the security pack (compliance/) and a counsel-reviewed DPA/MSA via [email protected].
