Subprocessors
The third parties that process data on Vajra's behalf, what each one handles, and where that data is stored. Vajra's own SOC 2 Type I audit is planned. Questions: hello@vajraops.ai
| Provider | Purpose | Data location | Data handled | Attestations |
|---|---|---|---|---|
| Lovable (Lovable Labs AB, Stockholm, Sweden) | Platform provider: application hosting, database, authentication, file storage, backups, transactional and inbound email, and the AI gateway used for break analysis | United States (primary hosting region for application data and file storage) | All client reconciliation data and user accounts. | Attestations and Lovable's own infrastructure providers are published at trust.lovable.dev trust.lovable.dev |
| Google (Google LLC) | Underlying model provider for AI break analysis, reached only through the Lovable AI gateway. Google is engaged as a subprocessor of Lovable, not of Vajra directly; Lovable's subprocessor registry and vendor risk management govern that connection | United States (per Lovable) | Pseudonymized text: fund, manager, account, broker and security names and codes, and document file names, are replaced with per-request surrogate codes, and every amount, balance and position size is rescaled by one random whole-number factor per request, so no real holding, balance or quantity is disclosed. Dates, currencies, and instrument and event types are not masked, since the analysis depends on them. Figures in the published analysis are restored from Vajra's own record of the client's file, not recomputed from the model's answer. Vajra holds the lookup table in memory for the length of a single request, so this is pseudonymization, not irreversible anonymization. Vajra has opted out of model training on its platform account, so prompts are not used to train models. The provider may keep short-lived operational logs under standard terms; those logs contain the pseudonymized request, not the underlying names or amounts. AI analysis can be switched off per client, in which case no request is sent. | Attestations for this connection are covered under Lovable's vendor programme at trust.lovable.dev trust.lovable.dev |
Pricing and market data
Security prices used to value reconciliation differences come from the client's own pricing file, loaded into Vajra by the client or delivered over the client's SFTP. Vajra makes no outbound market data request for a client's securities in production, so no pricing provider receives the client's holdings or traded symbols. A public exchange price service is used only to seed test data in demonstration environments, not as a production price source, and client pricing takes precedence over it.
Reference services receive no fund, position or client data. Benchmark interest rates (SOFR, EFFR, OBFR, BGCR, TGCR, CORRA, SONIA, €STR, SARON, TONA and AONIA) are read from the Federal Reserve Bank of New York, the Bank of Canada, the Bank of England, the European Central Bank, the Swiss National Bank data portal, the Bank of Japan and the Reserve Bank of Australia; these are published economy-wide rates and carry no security or client identifier. Public company filings are read from SEC EDGAR. Security identifier lookups (ISIN or CUSIP to ticker) use Bloomberg's public OpenFIGI mapping service and send the identifier only, with no fund, position, size or client reference. Bloomberg does see which identifiers are looked up.
File transfer and other infrastructure
Feed and document collection over SFTP connects directly from Vajra to the client's or prime broker's own SFTP endpoint using credentials held in an encrypted server-side vault. No third-party file transfer service sits in between. Transactional email (alerts, daily summaries, sign-in mail) and inbound document email are handled within the Lovable platform listed above. The database behind the platform is part of that service and covered by its attestations, not a separate subprocessor. Application source code is not held with a third-party code host for this deployment.
If a client connects its own locked archive storage (for example Amazon S3 with Object Lock) for the daily sealed record copy, that storage is the client's own and will be listed here once connected.
Last updated September 2026.