Skip to main content
Iron Gorilla

Top use cases

Show all solutions
  • GovernmentZero-trust autonomy with cryptographic chain-of-custody.
  • Banking & FinanceEnforce compliance on trading, lending, and transaction flows.
  • HealthcareHIPAA-aligned AI agents with PHI protection and audit trails.
  • InsuranceAutomated claims triage with PII redaction and policy control.

More industries

  • Construction
  • Energy
  • Aerospace
  • Transportation

By team

  • Enterprise IT
  • Teams & SMBs

Resources

  • Platform overviewSee how Iron Gorilla builds, manages, and deploys AI employees.
  • Help CenterGet straightforward answers and product guidance.
  • Trust CenterReview security, privacy, and compliance information.
  • Developer docsFind implementation guidance and technical references.

Learn

  • Insights
  • Compare

About

  • Company
  • Partners
LoginGet started for free

Legal

Policies & Agreements

Legal documents covering your use of the Iron Gorilla platform, how we handle data, and related notices and policies.

Documents

Terms of ServicePrivacy PolicyData Processing AddendumAcceptable Use PolicyEU AI Act Transparency AddendumCookie NoticeSubprocessor ListCopyright and DMCA PolicyAI Transparency NoticeConsumer Health Data Privacy NoticeBiometric Information Privacy PolicyNCII Notice and Removal PolicyCA GenAI Training Data Disclosure

Team Clarity, Inc. DBA Iron Gorilla Public Subprocessor and Service Provider List

Last updated: July 29, 2026

This list identifies providers and provider categories that may process personal data in connection with Iron Gorilla. Not every provider processes every customer's data. Customer-authorized integrations are not Team Clarity subprocessors unless Team Clarity separately engages them to provide the Services. The applicable Order Form, DPA, data region, plan, configuration, and Regulatory Addendum determine which providers may be used.

Provider/categoryPurposePossible dataLocation frameworkRegulated-data status
Amazon Web ServicesHosting, compute, storage, networking, backups, logging, and cloud infrastructure.Account, Customer Data, logs, metadata, security and operational data, depending on configuration.Provider and selected region; support and operational access may occur elsewhere as disclosed.PHI or other regulated data only when the provider, services, region, and upstream contract are expressly approved in the applicable activation schedule.
CloudflareDNS, CDN, traffic management, web application firewall, DDoS protection, bot mitigation, security, and performance.IP addresses, request metadata, security events, traffic and limited content depending on configuration.Global network with regional and product-specific processing.Regulated data only for specifically approved products/configurations and signed upstream terms; otherwise excluded.
SentryError monitoring, debugging, reliability, and performance analysis.Error events, stack traces, identifiers, metadata, and content inadvertently included by configuration.Provider locations and project settings.Not authorized for PHI or other specially regulated data unless specifically approved and configured to exclude or protect that data.
StripePayment processing, billing, invoices, subscriptions, tax and payment-related fraud prevention.Billing, transaction, payment-method metadata, business contact and account information.Provider locations and financial network participants.Not an approved PHI processing path. Customers must not place PHI or sensitive Customer Data in billing descriptions or payment metadata.
Microsoft 365Business email, documents, internal communications, support, and operations.Business contact, support, account, document, and communication data.Tenant and provider locations.PHI only through an expressly approved tenant, service, configuration, and BAA schedule. Standard support email is not automatically HIPAA Eligible.
Google AnalyticsWebsite and usage analytics, subject to consent and settings.Cookie identifiers, device/browser data, page interactions, IP-derived location and referral data.Provider network.Not authorized for PHI, consumer health data, biometric identifiers, student data, or nonpublic financial information.
TwilioSMS, verification, notifications, communications, and related messaging.Telephone numbers, message metadata, verification and communication content depending on feature.Provider and carrier network locations.Regulated data only for expressly approved products, regions, configurations, and upstream contractual terms.
OpenAISupported AI model API processing, model calls, prompts, outputs, moderation, and related AI services where enabled.Prompts, outputs, files, metadata, model and tool-call data as configured.Provider locations and selected enterprise/API settings.Default: not authorized for PHI or specially regulated data. Permitted only if named in the applicable activation schedule and all upstream contractual, retention, training, security, and regional requirements are satisfied.
AnthropicSupported AI model API processing, model calls, prompts, outputs, and related AI services where enabled.Prompts, outputs, files, metadata, model and tool-call data as configured.Provider locations and selected enterprise/API settings.Default: not authorized for PHI or specially regulated data. Permitted only if named in the applicable activation schedule and all upstream requirements are satisfied.
Other supported model providersModel routing and AI services selected or enabled for a customer.As described for the specific provider and feature.Provider-specific.Not approved for regulated data unless expressly identified in a signed activation schedule.
Customer-authorized integrationsCRM, ERP, HRIS, repositories, productivity, ticketing, communications, cloud, data, model, and other systems connected by Customer.Data selected, transmitted, or accessed by Customer's configuration.Determined by Customer and the connected provider.Customer-authorized recipient, not a Team Clarity subprocessor unless separately engaged. Customer is responsible for legality and regulated-data eligibility.

Change Notice and Objections

Team Clarity may add or replace subprocessors as described in the DPA. Enterprise customers with contractual notice or objection rights should use the contact and period stated in their DPA or Order Form. An objection must identify reasonable data-protection grounds relating to the new subprocessor. This public list should be maintained with version history and a subscription or notice mechanism before relying on it as the contractual change-notice channel.

Regulated Data

Presence on this list does not authorize a provider to receive protected health information, consumer health data, biometric information, student data, nonpublic financial information, controlled information, or other specially regulated data. Authorization requires a signed Regulatory Addendum and activation schedule naming the approved service path.

Contact

Questions and objections: legal@teamclarity.ai.

Iron Gorilla

The platform for building and governing AI employees, with policy-backed controls and clear human oversight.

  • SBA Certified Small Business

Product

  • Trust Profiles
  • Agent Builder
  • Command Center
  • Policy Builder
  • Reporting
  • Compliance Hub

Solutions

  • Government
  • Banking
  • Insurance
  • Healthcare
  • Energy
  • Aerospace

Resources

  • Trust Center
  • Help Center
  • Developer Docs
  • Insights
  • Compare
  • Pricing

Company

  • Company
  • Partners
  • Press Kit
  • Accessibility
  • Legal

© 2026 Team Clarity, Inc. DBA Iron Gorilla. All rights reserved.

Capabilities Statement