We believe a compliance product should hold itself to the transparency it asks of its users. This page lists every third-party service (“sub-processor”) that ARGOS relies on to run, exactly what data each one handles, and where it is hosted — so your own compliance and procurement teams can assess us properly.
Scope — and who is responsible for what
This page covers the ARGOS application (argos.truoco.com). For data our customers put into ARGOS, the customer firm is the data controller and Prymera Consulting Private Limited acts as a data processor under a Data Processing Agreement. The providers below are our sub-processors, engaged to deliver the service.
This is separate from the public marketing website, whose only personal data is the demo-request form — that’s covered in our Privacy Policy.
Who operates ARGOS
ARGOS is operated by Prymera Consulting Private Limited, Unit No. 10, 16th Floor, Aurora Waterfront, GN-34/1, Sector V, Salt Lake City, Kolkata 700091, West Bengal, India — the same entity that acts as processor under customer DPAs. Contact: connect@remitso.com.
Current sub-processors
| Provider | What they do for ARGOS | Data they process | Hosting location |
|---|---|---|---|
| Railway Railway Corp. (USA) | Application hosting & compute — runs the ARGOS web app and the PEP/sanctions validator service | All application data in transit and in memory during processing | United States (underlying compute on Google Cloud Platform) |
| Supabase Supabase, Inc. (USA) | Primary database & authentication — stores tenant records and manages login | User accounts & hashed credentials, cases, screening records, watchlists, the audit trail | Amazon Web Services — Europe (London), eu-west-2 |
| Qdrant Cloud Qdrant Solutions GmbH (Germany) | Vector search over the regulatory corpus for grounded, cited retrieval | Embeddings of the official source corpus and of runtime queries | Managed cloud (AWS/GCP) — region to confirm |
| OpenAI OpenAI, L.L.C. (USA) | Large-language-model inference and text embeddings that power grounded answers | Compliance queries, retrieved source text and screening context, sent for a single response | United States |
| Anthropic Anthropic, PBC (USA) | Large-language-model inference — an automatic fallback provider if the primary model errors or is unavailable, so a single provider outage doesn’t stop the service | Compliance queries, retrieved source text and screening context, sent for a single response (only on fallback) | United States |
| Brave Search API Brave Software, Inc. (USA) | Adverse-media web screening (one of two independent providers) | The name / search terms of the subject being screened | United States |
| Tavily Tavily, Inc. (USA) | Adverse-media web screening (second independent provider) | The name / search terms of the subject being screened | United States |
Underlying infrastructure: Railway runs on Google Cloud Platform; Supabase and Qdrant Cloud run on major cloud providers (AWS/GCP). These upstream providers are themselves sub-processors in the chain.
How we treat data at these providers
- No training on your data. Compliance queries go direct to the model provider (OpenAI) under a data-processing agreement with zero or short retention — there is no aggregator or proxy in the data path, and your data is not used to train models.
- Screening providers see only what they need. The adverse-media lane sends only the subject’s name / search terms to Brave and Tavily — not your case records or account data.
- Tenant isolation. Every case, watchlist, audit row and session is scoped to your firm within the database.
- Encryption in transit across all provider connections, and a tamper-evident, hash-chained audit trail for every action.
International transfers
Our primary database — holding accounts, cases, screening records and the audit trail — is hosted in the UK/EU region (AWS Europe, London), so the bulk of personal data stays within the EEA/UK. Some other sub-processors are located in the United States, and Prymera Consulting Private Limited is established in India. Where the personal data of EU/UK individuals is transferred outside the EEA/UK, those transfers are made under appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum), or an applicable adequacy decision. We can share the relevant transfer mechanisms with customers on request.
Changes to this list
We may add or replace sub-processors as the product evolves. When we do, we’ll update this page. Customers with a Data Processing Agreement can request advance notice of material changes to sub-processors and may raise a reasonable objection, as set out in that agreement.
Requesting the detail
For our Data Processing Agreement, the full sub-processor chain, hosting regions, or the transfer safeguards, contact Prymera Consulting Private Limited at connect@remitso.com.