CoreShieldCoreShield AI

Last updated:

The Arabic version of this document is the authoritative legal text. This English translation is provided for convenience; in case of any discrepancy, the Arabic version prevails.

Sub-processors

Effective: 16 July 2026

This page lists the third-party sub-processors MainCore Technologies engages to process personal data through CoreShield AI. It mirrors Annex A of our Data Processing Agreement and was verified against the deployed pilot configuration on 2026-08-08 — only sub-processors genuinely in use are listed.

Current sub-processors

Sub-processorPurposeData category receivedHosting region
Microsoft AzureCloud hosting: compute, storage, managed PostgreSQL, and Key Vault (encryption-key custody). All platform infrastructure runs here.All platform data. Original personal-data values are AES-256-GCM encrypted at rest in the vault; only cloaked derivatives are processed outside the vault.UAE North — current pilot. [OWNER DECISION: production/sovereign hosting region — the pilot runs in Azure UAE North; real customer data will be hosted inside the Kingdom of Saudi Arabia, provider under evaluation]
OpenAIExternal LLM inference (model gpt-4o-mini) for the Send verb.Cloaked text only — tokenized placeholders; never original values.[OWNER DECISION: OpenAI API data-processing region + signed OpenAI DPA]

Not currently engaged

The following are not in use in the deployed pilot as of 2026-08-08 and must not be treated as active sub-processors until enabled: Anthropic, Google (Gemini), and Azure OpenAI (alternative LLM providers — not configured); AWS and STC Cloud (STC Cloud is a candidate in-Kingdom host under evaluation, not yet deployed); and any analytics or error-tracking service (none is deployed).

Changes

We will give 30 days' notice of any new sub-processor via the mechanism in the Data Processing Agreement, during which a customer may object.


This document requires a Saudi lawyer's sign-off before publication.