Legal
Sub-processors
Not yet published here. The register exists and we send it on request; what we will not do is put a partial list on a public page that a vendor risk team could mistake for a complete one.
01Status
This document is in counsel review and is not yet published
Seldon Compute, Inc. publishes a legal document only once counsel has reviewed it against the system as actually built. That review is not finished for this one, so no version of it is published here. Nothing on this page is operative, and nothing on this page should be relied on when assessing whether to send us data.
We would rather say that plainly than publish borrowed boilerplate. A privacy notice describes what a company actually does with data, and terms of service are a contract. Both are only worth reading if they are true, and neither is true until the words have been checked against the operational practice behind them.
The finished document will be published here with its effective date recorded at the top. If you need the terms that apply to you before then, ask: customers under agreement contract on written terms today, and we will send what governs your account rather than point you at a page.
Contact
Security, privacy, data handling, and vendor due diligence. Also the address for responsible disclosure.
Contracting, commercial terms, and anything a procurement team needs in writing.
Published today
The fleet page explains the capacity sourcing model, which is the shape of the register. For the register itself, naming each entity with its region and transfer mechanism, write to the security team and it will be sent to you.
How we source capacity02Intended scope
What the document will cover
A list of topics, not a summary of terms. Each item below describes something the finished document will address, and nothing below is operative until that document is published.
- 01Each sub-processor by legal entity name, not by brand, since those differ often enough to matter in a diligence review.
- 02The processing purpose for each, described narrowly rather than as a general category.
- 03Processing locations by country or region, which for a cross-market GPU fleet is the entry most likely to change.
- 04The transfer mechanism relied on for each flow that leaves the customer's chosen region.
- 05Whether a sub-processor can access request content, or only metadata, or neither. This distinction does most of the work in an actual security review.
- 06The notice period before a new sub-processor is added, and the objection process for customers who cannot accept one.
- 07A change log with dates, so a customer can prove what the list said on the day they signed.
- 08How the list is scoped by product, since dedicated and customer-VPC deployments have a materially different vendor footprint from the shared endpoint.
If you need something in writing before this is published
Security reviews and procurement processes do not wait for a publication schedule. Write to security@seldon.ai and describe what your process requires. Where an accurate answer exists we will put it in writing, and where one does not we will say so rather than send a document that reads well and means nothing.
The trust center lists the controls that are implemented today and the certifications that are not, with the distinction between the two made explicit.