Key facts
- Of nineteen AI vendors serving wealth management whose public documents we reviewed on 17 August 2026, eight publish a subprocessor list we were able to read.
- Six of the eight readable lists name a model provider, and two name a transcription provider.
- We found no vector store or embedding service named in the public documents of any of the nineteen vendors.
- Anthropic's own subprocessor list, read on 23 September 2026, carries twenty entries and added TurboPuffer, a vector and full-text search database, on 6 May 2026 under the category web search.
- Three of the nineteen vendors (Orion with Redtail CRM, Black Diamond, and Zocks) appear on the twelve-entry connector list of Claude for Financial Advisors, released 14 September 2026.
- Regulation S-P requires a covered firm's policies to be reasonably designed to require oversight of service providers "including through due diligence and monitoring" (17 CFR 248.30).
Your AI vendor has vendors.
Regulation S-P requires your firm's incident response program to include written policies and procedures reasonably designed to require oversight of service providers, and it says how: "including through due diligence and monitoring." That is an active duty and it sits with you.
Here is the practical problem. You cannot perform due diligence on a company you have never been told about. For most advisory firms, the vendor's published subprocessor list is the only place that company's name could appear.
So we went looking for those lists. We read the public documents of nineteen AI vendors selling into wealth management, the same nineteen we reviewed for breach-notification deadlines in August, and looked for one thing: who else is holding the data.
Eight of nineteen vendors publish a subprocessor list we could read, and none of them names a vector store
Eight of the nineteen publish a subprocessor list we were able to read. One more names its processors inside the privacy policy without publishing a titled list. One publishes a subprocessors section that returned no entries. One publishes a trust center gated behind an access request, which we did not submit. For the remaining eight we could not find a subprocessor disclosure in the documents we read.
Six of those eight name a model provider. Several name the model company by full legal entity. Two name the cloud platform that provides the model service rather than the model company itself.
Two of the eight name a transcription provider, both in products that record and transcribe client meetings.
In none of the documents we read did we find a named vector store or embedding service. Not on any of the eight readable lists, and not in the documents of the other eleven vendors.
That last finding is the one worth sitting with, and the first three are what give it force. Naming an AI-layer processor is demonstrably achievable, and most vendors who publish a list do it. What we could not find is concentrated in one specific layer.
An AI feature runs on several companies, and the vector store is the one least often named
When an advisory platform adds an AI capability, the work is rarely done by one company. A typical arrangement involves some subset of:
| Layer | What sits here |
|---|---|
| Application vendor | the company on your contract |
| Cloud host | the infrastructure the application runs on |
| Model provider | reached directly, or through a cloud platform's model service |
| Orchestration or inference layer | sometimes a separate platform |
| Vector store | where embeddings of your documents persist |
| Transcription | for anything that touches recorded meetings |
| Implementation partner | anyone with production access during a build |
| Observability and logging | tooling that can capture prompt and response content |
Of the eight lists we read, the AI-specific layers named were the model provider, in six cases, and transcription, in two.
The vector store deserves a plain explanation, because it is the layer we did not find named and the one an advisor is least likely to have heard of. To let an AI system answer questions about your client documents, those documents are usually converted into numerical representations called embeddings, and those embeddings are held in a separate index, often a separate database. The embedding is not the document, but it is derived from it, it persists, and it sits in a second system. If that system is never named, it is unlikely to appear in your vendor inventory or to be identifiable in your incident response program, and your diligence has nothing specific to attach to.
What happens to that second copy when a client leaves is a larger question, and we will take it up in a separate article. The point here is narrower: across nineteen vendors, we could not find it named.
We did find one named, though not on any of the nineteen. Anthropic publishes a subprocessor list of twenty entries in its trust center, and an update dated 6 May 2026 added TurboPuffer, described there as providing web search for all Anthropic products except Claude for Government. TurboPuffer describes itself as a vector and full-text search database. That is the only vector database we found named by any company in this review, and it belongs to the model provider, filed under a category most readers would not open looking for one. Whether that store ever holds anything derived from a firm's own documents is not something the list says. It is the kind of question the list exists to prompt.
The gap looks like paperwork lagging architecture, not concealment
Subprocessor lists and data processing agreements were designed for a world of hosting, email and CRM. The obligations they encode assume a fairly stable set of vendors doing fairly legible things.
The AI stack added several new categories of processor in roughly twenty-four months. Paperwork lagged architecture. That fits what we found better than any account involving intent, particularly given that six of the eight readable lists do name model providers and two name transcription vendors.
Several of the disclosures we read name AI-layer processors by entity, which is the clearest evidence that the disclosure is achievable. Egnyte names Anthropic PBC, OpenAI OpCo LLC and Google LLC with their service categories. Hadrius names OpenAI under the category "SOTA LLM Inference." Lira AI names OpenAI. Strata AI names Microsoft Azure OpenAI for language processing and Recall.ai and Deepgram for meeting transcription, in a section titled "Sub-Processors and Third-Party Services." Hazel, the assistant distributed through Altruist, names seven entities including two model providers and two transcription services. Orion names Amazon Web Services in an AI-model-provider category. WealthFluent, which publishes no titled list, names its model provider and hosting arrangement in the body of its privacy policy. One vendor's trust center is gated, so this is not a complete comparison across the sample.
When the model provider is the company on your contract, the chain runs the other way
Claude for Financial Advisors, released by Anthropic on 14 September 2026, has started to turn the chain around for some firms. The plugin's connector list names twelve advisor systems. Three of them are vendors in this review: Orion, including Redtail CRM, Black Diamond, and Zocks. We wrote about what the plugin is and is not in The Plugin Is a First Draft.
With a connector, the model provider is the company on your contract and the portfolio or CRM vendor becomes a source the model reads from, at your direction. The subprocessor list that matters most is then the model provider's, and the question for the source-system vendor is narrower: what does the connector read, what can it write, and where is that recorded. The plugin's own repository advises preferring connectors that expose read-only tools, and at least one connector description on the list includes writes, made with the advisor's approval.
The framing of the launch, in the trade press and on LinkedIn, is that client data stays where it is. Schwab described its planned connector to Financial Planning on 21 September 2026 in those terms: activated at the firm level, with the firm choosing which users may use it, account numbers, Social Security numbers and dates of birth masked, and a contract clause prohibiting training on client data. Those are the right controls, and they are controls a subprocessor list cannot show you. What the framing leaves out is the path. Whatever the model reads in session passes through the model provider and its own subprocessors, twenty of them on Anthropic's list, and the session is retained on whatever terms the firm's plan carries. LPL has said its own advisor agent uses many of the same integrations, so the same reading applies one layer up. "Stays on the custodian's servers" describes the source. It does not describe the path.
None of that changes the duty. It changes which list you ask for first.
Six of the nineteen publish pages that only render in a browser
Six of the nineteen publish pages that are assembled in the browser rather than served as text. An automated review sees only page metadata for those, and would report them as absences.
Opened in a browser, four of the six turned out to publish readable lists or disclosures, and one of them is among the most detailed in the sample. One returned an empty subprocessors section. One presented an access-request form.
Anthropic's list is built the same way. Fetched as text, the page returns a welcome banner and nothing else; the twenty entries appear only in a browser. Two things follow for a firm doing diligence. First, open the page yourself rather than trusting a scan or a summary, because the difference here was four vendors out of nineteen, and the model provider's list would have read as empty too. Second, some trust centers require you to request access, so a list may exist without being public, and asking may be the only way to see it.
The oversight duty sits with the firm under Regulation S-P
The oversight duty under Regulation S-P is the firm's. Regulation S-P is explicit that notwithstanding a firm's use of a service provider, "the obligation to ensure that affected individuals are notified ... rests with the covered institution."
Your written policies and procedures must be reasonably designed to require oversight of service providers "including through due diligence and monitoring," and to ensure those providers take appropriate measures to provide notification "as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider."
Regulation S-P defines a service provider as any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information "through its provision of services directly to a covered institution."
How far down the chain that definition reaches is a question for your counsel, and we are not going to resolve it in an article. No regulator has ruled on it. What we can say is what the record shows: the SEC's 2024 adopting release does not address subcontractors, sub-service providers or downstream vendors anywhere in its text, and does not address derived or processed data as a category. One commenter asked the Commission to clarify the scope of the service provider definition. The response section does not take up the question.
The operational consequence does not depend on how that is eventually resolved. Whatever the legal perimeter turns out to be, your diligence can only cover parties you know about, and for the layer we looked at hardest, the naming is absent.
The dates are in force. The 2024 amendments to Regulation S-P took effect on 2 August 2024, with an eighteen-month compliance period for larger entities and twenty-four months for smaller ones, running from the 3 June 2024 publication date. That computes to 3 December 2025 and 3 June 2026. One wrinkle worth knowing: the larger-entity test appears only in the adopting release and was never written into the rule itself, so a firm reading the regulation alone cannot tell which date applied to it. For registered investment advisers the threshold is $1.5 billion or more in assets under management. If your firm is state-registered, the FTC Safeguards Rule is the more likely fit, and it also requires you to select, contract with and monitor service providers on safeguards.
Eight questions to send when the subprocessor list arrives, or does not
The fourth question in our nine-question vendor checklist asked vendors to name every subprocessor and model provider that touches your data. These eight are what to ask when the answer arrives, or does not.
- Which model provider processes our data, and is it named on your subprocessor list?
- Where are embeddings of our data held, which company operates that store, and is it named on your list?
- When we terminate, are embeddings deleted, or only the source records?
- Does your subprocessor notice obligation cover model providers and inference platforms, and how many days of notice do we get?
- If one of your subprocessors is breached, what is their notice obligation to you, and yours to us?
- Does any implementation or development partner have production access to our data?
- Does your logging or observability tooling capture prompt and response content, and who operates it?
- When did you last update this list, and what has changed in your architecture since then?
If you reach a system through a connector rather than through the vendor's own AI feature, send the same eight questions to the model provider, and ask the source-system vendor questions 6 and 7 about the connector itself.
Question 8 does the most work, so put it last and read the answer carefully. A subprocessor list is a statement about a system as it stood on the day the list was written. Two of the documents in this review predate their own vendor's publicly announced AI launch by more than a year, and one subprocessor list carries a date six years old.
Question 4 is the one most likely to expose a soft commitment. Of the eight readable lists, one publishes an advance-notice period for new subprocessors with an actual number of days attached, and even there the agreement carries two provisions that are not obviously reconciled. Two more commit to notice without stating how far in advance, one attaching a thirty-day objection window after the fact and the other stating no number at all. A notice obligation with no clock is difficult to monitor against.
What we read: nineteen vendors, reviewed 17 August 2026
Nineteen vendors, reviewed 17 August 2026. Each row records what we found in public documents, not an assessment of the vendor.
| Vendor | Public subprocessor list | What the documents name | Where we looked |
|---|---|---|---|
| Orion | Yes | 36 entities per the annex, including a cloud AI-model service. Our fetch of the web page truncated after three rows | Subprocessor page and data processing agreement |
| Egnyte | Yes | 25 entities, three of them in an artificial-intelligence services category | Subcontractor page and data processing agreement |
| Hadrius | Yes | 14 entities, including a model provider | Trust center, subprocessors tab |
| Strata AI | Yes, within the privacy policy | A sub-processors section naming a model provider and two transcription services | Privacy policy, sub-processors section |
| Hazel | Yes | 7 entities, including two model providers and two transcription services | Trust center, terms of use, Altruist subscription agreement |
| Lira AI | Yes | 7 entities, including a model provider | Trust center, subprocessors tab |
| SideDrawer | Yes | 7 entities, none of them in an AI role | Sub-processor page and data processing agreement |
| Zocks | Yes | 1 entity, a cloud host | Security page, privacy policy, terms of service |
| WealthFluent | Named inline, no titled list | 3 processors named in the privacy policy, including a model provider | Privacy and security policy, terms of use |
| Jump | Section published, no entries | The subprocessors tab returned no results. Recipient categories are named in the privacy policy | Trust center, privacy policy, security FAQ |
| Verlo | Gated behind an access request | Not verified. We did not submit the request form | Trust center, privacy statement, terms |
| FastTrackr AI | We could not find one | Categories only, including a third-party AI service and speech-to-text | Privacy policy, terms of service, business site |
| SS&C Black Diamond | We could not find one | Generic reference to suppliers and sub-contractors | Group privacy statement, Black Diamond privacy notice, security addendum |
| eMoney Advisor | We could not find one | Advertising and analytics vendors only | Privacy policy, security page |
| Masttro | We could not find one | We could not find a third party named in an AI role | Privacy policy, data security page |
| VastAdvisor | We could not find one | An observability tool named in the AI safety statement | Privacy policy, terms, AI safety statement |
| Verapath | We could not find one | We could not find a named vendor schedule | Privacy policy, terms and conditions |
| Hamachi.ai | We could not find one | The categories "AI model providers" and "cloud infrastructure providers" | Privacy policy, terms |
| WealthAi | We could not find one | A hosting platform named on the website | Privacy notice, website |
Method. We reviewed the public documents of nineteen AI vendors serving wealth management and its advisors, the same sample as our August breach-notification review, drawn from twenty-seven companies of which nineteen published enough to assess. For each we looked for a published subprocessor or subcontractor list, then read the privacy policy, terms of service, data processing agreement where one exists, and any trust or security page. Six vendors publish pages that are assembled in the browser, and those were opened in a browser rather than fetched, which changed four of the nineteen results. We recorded the source URL and capture date for every finding, and they are available on request. Reviewed 17 August 2026. The eight readable lists were revalidated in a browser on 22 August 2026 with no changes found. Anthropic's subprocessor list and the Claude for Financial Advisors repository were read on 23 September 2026, and Egnyte's subcontractor page was spot-checked the same day and found unchanged (last updated June 2026). Scheduled for full revalidation by 15 November 2026.
These findings describe what vendors publish, not their security or their practices. Subprocessor lists and data processing agreements are commonly distributed under non-disclosure or through a gated portal, so a vendor may maintain a complete list that is not public. "We could not find" is a statement about our search. It is not a statement about the vendor.
Ask for the list before you sign, and read it as a description of an architecture
Ask for the list before you sign, and read it as a description of an architecture rather than a formality. Then ask when it was last updated and what has changed since.
If your vendor uses AI to answer questions about client documents, the embeddings of those documents are somewhere. That somewhere has an operator, a jurisdiction and a name. Across nineteen vendors, including eight that publish a list and six that name their model provider, we could not find that name in public. It is a reasonable thing to ask for, and worth asking before the question becomes urgent.
Questions
Does Regulation S-P require my AI vendor to disclose its subprocessors?
Not in those words. Regulation S-P requires the firm's policies to be reasonably designed to require oversight of service providers through due diligence and monitoring, and the 2024 adopting release does not address subcontractors or downstream vendors. The disclosure is something the firm asks for because its own diligence cannot reach a party it has not been told about.
What is a vector store, and why does it matter for client data?
To let an AI system answer questions about client documents, those documents are usually converted into embeddings, numerical representations that persist in a separate index or database. The embedding is derived from the document, it outlives the query, and it sits in a second system with its own operator. If that system is never named, the firm's vendor inventory and incident response program have nothing to attach to.
If I use Claude for Financial Advisors through a connector, whose subprocessor list do I need?
The model provider's, first. With a connector, the model provider is the company on your contract and the portfolio or CRM vendor becomes a source the model reads from at your direction. Ask the source-system vendor what the connector reads, what it can write, and where that is recorded; the plugin's repository advises preferring connectors that expose read-only tools.
Does "we could not find" mean the vendor has no subprocessor list?
No. It means we could not find one in the public documents we read on the dates stated. Subprocessor lists and data processing agreements are often provided under non-disclosure or through a gated trust center, so a vendor may keep a complete list that is not public. Asking for it may be the only way to see it.
Advisor Insights provides general professional information, not individualized investment, legal, cybersecurity, or compliance advice. Your obligations depend on your registrations, your systems, and your contracts, and should be confirmed with counsel. Regulatory descriptions are U.S. federal and current as of August 2026. Vendor findings reflect public documents reviewed on 17 August 2026, and the model-provider and connector facts reflect documents read on 23 September 2026; any of them may have changed since.
Primary sources
General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.