Subprocessors · last updated September 2026
Subprocessors and every outbound call.
Latent runs inside your environment. In the default serving path it has no subprocessor. Nothing is sent to Latent. This page lists every outbound call the product can make and who controls it. It also lists the vendors the company uses for this website and for sales.
The product
With the default two containers running, no subprocessor handles your prompts, answers, activations or weights. These are the outbound calls any component can make. None of them goes to a Latent endpoint.
| Call | What it sends | Goes to | Who controls it |
|---|---|---|---|
| Model weights | A download request with your Hugging Face token. | Hugging Face | You. It runs on first start. After that you can block all egress from the host. |
| Usage reporting in vLLM and Hugging Face | vLLM's own usage statistics and the Hugging Face hub's telemetry headers. | The vLLM project and Hugging Face | You. Both are on in the base install. The hardening overlay, recommended for every new pilot, turns them off. |
| Labelling during calibration | The calibration sample's text: source, question and answer. | The provider you pick, with your key. latent calibrate uses Anthropic unless you choose otherwise. | You. Label with your own reviewers or a model you host, and nothing leaves. |
| Written explanations | The stored source, request and answer for one flagged request. | Anthropic, with your key | You. Off until you set LATENT_EXPLAIN_JUDGE=1. It then runs when a reviewer asks, or on each flagged answer if you turn on the gateway's judge response. |
| Alerts | Aggregates only. The body carries no content and no secrets. | Your webhook, Slack, PagerDuty or email | You. Only when a reviewer saves a destination. Private-network hosts are refused unless you allow them. |
| Stronger-model routing | A flagged request, re-issued. Your client's credential is never forwarded. | The endpoint you name | You. Gateway only, and off by default. |
| Dataset push | The labelled pairs you export, with their text. | Your Hugging Face dataset repo | You. Only when someone on your team presses Push on the Improve page, with a token they type. The token is never stored. |
| Telemetry to Latent | Nothing. | No one | There is no usage reporting, license check or phone-home, and no code that would send one. |
Your keys, your accounts. A call made with your key runs under your own account with that provider. If you turn one on, list that provider as a subprocessor of your own data.
What Latent receives
Nothing, unless you send it. Two cases come up in a pilot.
- A report at the end of a pilot, if you choose to share it with us.
- Activation statistics from your traffic, if you ask us to fit the calibration for you. The few-MB calibration file comes back to you. You can run the fit inside your environment instead.
Latent never receives, copies or transmits model weights.
The company
These vendors run the website and sales. None of them is part of the product. None of them sees your model's traffic.
| Vendor | Purpose | What it handles |
|---|---|---|
| Netlify | Hosts runlatent.ai | Standard server logs of requests to the site |
| Cal.com | Booking calls with us | The details you enter when you book |
Contact
Questions about this list go to founders@runlatent.ai. The full security detail is on the security page.