Sub-Processor Register

  • Organisation: Noviqent Ltd
  • Company number: 17232197, registered in England & Wales
  • ICO registration: ZC225920
  • Publication status: Public, customer-accessible
  • Last updated: 25 August 2026

Current hosting architecture

Application, database, and worker infrastructure are operated by Noviqent directly — not outsourced to a third-party cloud platform, so this is disclosed here as infrastructure, not as a sub-processor. Alert payloads, the context gathered in response to them, and the resulting analyses are stored on that infrastructure.

Current sub-processors

Which AI sub-processor applies to you depends on what your organisation configures. Incident Copilot's reasoning step is performed by an AI provider your organisation chooses and supplies its own API key for. Exactly one provider is active for your organisation at a time, and it receives the gathered context for each incident. There is no default and no shared Noviqent-held AI account: if you have not configured a provider, no context is sent anywhere and the reasoning step does not run.

What the active provider receives, whichever one it is: the alert payload, metric values and log lines retrieved from your Grafana, source files retrieved from your GitHub repository, and summaries of related Jira tickets. Any of that can incidentally contain personal data. No provider ever receives your account credentials or your connector credentials.

The provider you select becomes a sub-processor only by virtue of that selection:

  • Anthropic PBC — a sub-processor only if your organisation has configured the Claude provider. Receives the gathered context for each incident while it is the active provider.
  • OpenAI L.L.C. — a sub-processor only if your organisation has configured the GPT provider. Receives the gathered context for each incident while it is the active provider.
  • Google LLC — a sub-processor only if your organisation has configured the Gemini provider. Receives the gathered context for each incident while it is the active provider.
  • A private endpoint you host — if your organisation instead points Incident Copilot at your own OpenAI-compatible endpoint (in your network or your cloud account), then there is no AI-vendor sub-processor for the reasoning step at all. The context is sent to infrastructure your organisation controls, and no third party receives it. Whoever hosts that endpoint for you is your relationship, not ours.

Switching providers changes who receives your incident context from that point onwards. The change is recorded in your organisation's audit log, and the current provider is shown on the Connectors page. Apart from whichever AI provider you have selected, no other third party processes your data on our behalf.

Not sub-processors: your own connected tools

Grafana, GitHub, and Jira appear throughout this product, and it would be easy to assume they belong on the list above. They do not, and the distinction is a real one rather than a technicality.

  • Those systems are yours. You authorise Incident Copilot to connect to them; they are not parties we engage to process data on our behalf.
  • Data flows from them to us. A sub-processor is a third party that receives data from Noviqent; these are sources we read from.
  • The two exceptions are writes into your own tenant, at your instruction: we open a draft pull request in your GitHub repository, and we create a ticket in your Jira project. In both cases the data stays inside a system your organisation already controls and already has its own agreement with the vendor for.

Listing them as sub-processors would misdescribe who holds your data, so they are documented here as connected systems instead.

Not currently in use

No third-party email delivery, monitoring, logging, error-tracking, analytics, authentication, or CAPTCHA service is currently used to process your account or incident data.

Notice of changes

Noviqent will update this register before enabling a new production sub-processor, and will follow the customer authorisation/notification mechanism set out in your organisation's Data Processing Agreement before adding a material new one. If your organisation needs a signed Data Processing Agreement in place and doesn't already have one — for example, before routing production alerts — contact compliance@noviqent.co.uk. See the Privacy Notice for what personal data is processed at each stage and where.