Update to Vapi’s Subprocessor Model
Vapi Logo

Trust Center

Start your security review
View & download sensitive information
ControlK

Welcome to Vapi's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.
  • Spring Venture Group
  • New York Life
  • Versa
  • Mindtickle
  • Independent Bank

Documents

Featured Documents

COMPLIANCESOC 2

Subprocessors

Trust Center Updates

Update to Vapi’s Subprocessor Model

Subprocessors

As part of our continuing work to give customers more transparency and control over how their data flows through the Vapi platform, Vapi will begin using a two-tier model for the third-party providers that may process Customer Personal Data.

Vapi Subprocessors are providers that Vapi engages directly to deliver the core Voice AI platform, such as hosting, infrastructure, core model inference, observability, and similar providers. Vapi enters into data processing agreements with each Vapi Subprocessor, flows down applicable data protection obligations, and remains responsible for their acts and omissions as set out in Vapi’s DPA. The current Vapi Subprocessor List is available on our Customer Trust Portal at https://security.vapi.ai/item/subprocessors .

Optional Providers are customer-selected third-party services that customers may choose to enable through the Vapi platform. Optional Providers are disabled by default and are enabled only by affirmative customer action. When a customer enables an Optional Provider, the customer instructs Vapi to route selected Customer Data to and from that provider. Because customers select Optional Providers and instruct Vapi to route data to and from them, Optional Providers are not Vapi subprocessors and are not on Vapi's Subprocessor List, and Vapi's flowed-down subprocessor commitments under the DPA do not apply to them. Customers are responsible for determining whether they require separate provider-specific terms, including data processing terms or cross-border transfer mechanisms, and for obtaining those terms where available. The current Optional Providers list is available on our Customer Trust Portal at https://security.vapi.ai/item/vapi-optional-providers for informational purposes.

What’s moving and what’s not: Effective September 14, 2026, certain processors will move from Vapi’s previous Subprocessor List to the Optional Providers list. For existing customers currently routing data to those providers, their status will remain unchanged on your account until either your next renewal or your affirmative acceptance of the change in writing. New enablements after September 14, 2026 will use the Optional Provider framework from the start.

What changes for you: For most customers, nothing changes today. All providers currently on your account remain governed by your existing DPA. The new structure simply lets you opt into a wider set of providers without waiting for Vapi to sign DPAs with each one.

Questions: infosec@vapi.ai or privacy@vapi.ai.

Notice of Subprocessor Update

Subprocessors

This notice supplements the update to our Subprocessor List at security.vapi.ai, made in accordance with Section 3.2 of the Vapi Data Processing Addendum (the “DPA”).

What is changing
WorkOS, Inc. (“WorkOS”) currently supports single sign-on (SSO) for the Vapi platform. Effective July 31, 2026, WorkOS’s role will expand to provide authentication services more broadly. As part of this change, end-user authentication data that was previously stored within your region (via Supabase) will be processed by WorkOS on infrastructure located in the United States.

Subprocessor details
Subprocessor: WorkOS, Inc.
Service: Authentication (previously SSO only)
Processing location: United States
Categories of data: Authentication identifiers and account information (e.g., name, email address, user/account identifiers) and system metadata (e.g., timestamps, device identity, IP address). Does not include call recordings, transcripts, call logs, or conversation content.
Data subjects: Your employees and end users who authenticate to your Vapi-powered application.

For customers in the EEA, UK, and Switzerland
This change involves a transfer of personal data to the United States. Such transfers continue to be made under the Standard Contractual Clauses incorporated into your DPA with Vapi (Section 5), including the UK Addendum and Swiss adaptations where applicable. Vapi’s onward transfer of authentication data to WorkOS is itself governed by Standard Contractual Clauses (with UK and Swiss supplements) under Vapi’s data processing agreement with WorkOS.

For customers in Australia
Vapi handles personal information consistent with Australian Privacy Principle 8. WorkOS is contractually bound, under Vapi’s agreement with WorkOS, to protect personal information through security, confidentiality, and onward-transfer obligations.

If you have any questions regarding this update, please contact us at security.vapi.ai or via privacy@vapi.ai.

New Subprocessor Notifications

Subprocessors

We've updated our subprocessor list with the addition of Databricks, which will be used as our primary data platform to support the delivery and operation of our services. Databricks may process customer data to support the provision of our services, provide analytics capabilities and improve our products and services.
Databricks is hosted in the United States and is subject to appropriate contractual, security, and privacy safeguards consistent with our third-party risk management program.
The complete and updated list of subprocessors is available in Vapi Trust Center dashboard under the "Subprocessors" tab. Should you have any questions, please contact your account representative.

We’ve updated our subprocessor list with the addition of Soniox, a transcription service provider that customers may optionally select within the Vapi dashboard. When selected by a customer, Soniox may process audio and related data for the purpose of providing transcription services as part of our services. Soniox is available for customers using our US and EU deployments and may also be used by customers who have enabled the HIPAA mode.

The complete and updated list of subprocessors is available in Vapi Trust Center dashboard under the "Subprocessors" tab. Should you have any questions, please contact your account representative.

2025 Penetration Test Executive Summary Now Available!

Compliance

Check out the executive summary for our most recent independent third-party penetration test for 2025! Now available in Documents in our Trust Center.

If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo