Skip to main content

TrustAI | AI Platform for Enterprises & Government Agencies

Appendix: Third-Party Provider List

Version: 1.0 · Effective date: May 2026

Document nameTrustAI Third-Party Provider List Appendix
Version1.0
Effective dateMay 2026
ScopeApplies together with Terms of Service v1.0 and Privacy Policy v1.1
UpdatesTrust Soft updates on changes and notifies under Article 14 of the Terms of Service
Contactlegal@trustsoft.com.vn | dpo@trustsoft.com.vn

This Appendix forms an inseparable part of the TrustAI Terms of Service and Personal Data Protection & Privacy Policy.

Part 1. Introduction

This Appendix publishes the list of third-party providers used by Trust Soft to operate the TrustAI platform, including:

  • Cloud infrastructure providers and related services
  • Large Language Model (LLM) providers
  • Monitoring, security, and analytics service providers
  • Other technical partners that come into contact with data during service operations.

Note: This Appendix is published to fulfill the commitment to data processing transparency, meet the requirements of Decree 13/2023/ND-CP, and assist Organizations in assessing legal risk when using the service.

1.1. How to read this Appendix

Each provider is described with key information:

  • Name: trade name and legal entity (if different).
  • Service type: the provider's role in the TrustAI ecosystem.
  • Processing location: country/region where servers process data, key to assessing cross-border transfer risk.
  • Data categories shared: scope of data Trust Soft transfers to the provider.
  • Legal basis: Data Processing Agreement (DPA), Standard Contractual Clauses (SCC), or equivalent commitments.
  • Policy link: link to the provider's privacy policy.

1.2. Appendix updates

  • Trust Soft updates this Appendix on provider changes
  • Update notices are sent to Organization Administrators at least 30 days before changes take effect (per Article 14.2 of the Terms of Service)
  • The current version is always published at Trust Soft's official address.

Part 2. Large Language Model (LLM) providers

LLMs process prompt content and generate AI responses. They are the most direct content-processing components and require the highest transparency.

Note: Organizations may choose which AI models to use in their plan and may exclude specific providers as needed (especially when requiring Vietnam-based providers), per Article 14.3 of the Terms of Service.

2.1. FPT AI Factory (Vietnam)

Legal entityFPT Smart Cloud Company Limited (FPT AI Factory)
Service typeOpen-source LLMs hosted by FPT on infrastructure located in Vietnam
Models usedGPT OSS 120B, Qwen3.6-27B, GLM-5.1
Processing locationData centers in Vietnam (operated by FPT AI Factory)
Data sharedPrompt content and conversation context necessary to generate responses, no user identity data is sent
Security commitmentData does not leave Vietnam, customer content is not used to train models
Legal basisDPA between Trust Soft and FPT Smart Cloud, compliant with Decree 13/2023/ND-CP
Cross-border transferNo
Recommended forOrganizations with strong data sovereignty requirements, especially government agencies
Policy linkhttps://fptcloud.com/privacy-policy/

2.2. Microsoft Azure (United States)

Legal entityMicrosoft Corporation (delivered via Microsoft Azure)
Service typeLarge language models hosted on Azure
Models usedGPT-5.3 chat, GPT-5.4, GPT-5.4 mini, Kimi-K2.6
Processing locationUnited States
Data sharedPrompt content, conversation context, attached documents (if any), technical session identifiers (not including user identity data)
Provider commitmentMicrosoft commits not to use customer data to train foundation models
Legal basisData Processing Addendum under Microsoft's standard terms
Cross-border transferYes (processing in the United States), TIA performed and safeguards applied
Policy linkhttps://www.microsoft.com/privacy

2.3. DeepSeek API (China)

Legal entityDeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.)
Service typeDeepSeek language models via API
Models usedDeepseek v3.2, Deepseek v4 Flash, Deepseek v4 Pro
Processing locationChina
Data sharedPrompt content and conversation context necessary to generate responses, no user identity data is sent
Legal basisDeepSeek API terms
Cross-border transferYes, TIA performed
RecommendationOrganizations evaluate per business requirements, opt-out available under Article 14.3 of the Terms of Service
Policy linkhttps://www.deepseek.com/privacy

2.4. LLM provider comparison

ProviderModelsProcessing locationPublic-sector suitabilityNo-training commitment on customer data
FPT AI FactoryGPT OSS 120B, Qwen3.6-27B, GLM-5.1VietnamHigh, recommendedYes (hosted domestically, under DPA)
Microsoft AzureGPT-5.3 chat, GPT-5.4, GPT-5.4 mini, Kimi-K2.6United StatesMedium-highYes (Microsoft commitment)
DeepSeek APIDeepseek v3.2, v4 Flash, v4 ProChinaLow, requires reviewPer provider terms

Part 3. Cloud infrastructure providers

TrustAI prioritizes cloud infrastructure hosted in Vietnam to ensure data sovereignty and compliance with the Cybersecurity Law.

3.1. Primary infrastructure

Service typeVirtual machines (IaaS), object storage, internal networking, load balancing
Data center locationVietnam (Hanoi, Ho Chi Minh City)
Data storedAll Organization data (accounts, documents, chat history, logs)
CommitmentCompliance with the Cybersecurity Law and in-country data residency
Legal basisDPA signed between Trust Soft and the provider
Security standardsISO 27001 or equivalent, Vietnamese information security certifications as applicable

Note: the specific infrastructure provider name is disclosed to the Organization in the documentation attached to the Service Contract and may be subject to bilateral confidentiality.

3.2. Auxiliary services

Service typePurposeProcessing location
CDN (content delivery network)Speed up loading of UI assets (CSS, JS, images)Multi-region, no content data processed
Transactional emailAuthentication and system notificationsVietnam (preferred) or Southeast Asia
Vector databaseStore and query document embeddings in the knowledge baseVietnam (co-located with primary infrastructure)
ASR (speech-to-text)Power the voice-to-text featureVietnam (preferred) or Singapore

Part 4. Monitoring and security providers

These services help Trust Soft detect incidents, ensure performance, and protect the system. They DO NOT process user content, only technical logs and operational data.

Service typePurposeData processed
Application Performance Monitoring (APM)Error detection, response time measurement, system optimizationTechnical logs, error codes, performance metrics (no user content)
Centralized log managementAggregate and analyze logs from servicesAccess logs, system activity logs
Web Application Firewall (WAF)Block attacks targeting the web app (SQL injection, XSS…)HTTP requests, IP addresses, attack signatures
Intrusion Detection System (IDS)Detect and alert on anomalous network activityNetwork traffic, access logs
SSL/TLS certificate managementIssue and renew HTTPS certificatesDomain names (no content processed)
Backup and Disaster RecoveryRegular backups and recovery on incidentsEncrypted backups of all system data

Part 5. External channel integration partners

When Organizations enable integrations with external platforms, those platforms participate in data processing in their own roles.

5.1. Zalo Official Account (Zalo OA)

Legal entityVNG Corporation (Zalo)
Service typeOA messaging platform allowing Organizations to interact with end users
Legal roleIndependent Controller (for end-user Zalo data) or Joint Processor
Processing locationVietnam
Data involvedZalo user ID, messages exchanged through the OA channel
Organization responsibilityComply with Zalo OA terms, notify end users about AI processing (Articles 26 and 27 of the Terms of Service)
Policy linkhttps://zalo.me/policy

5.2. Meta Platforms (Facebook, Messenger)

Legal entityMeta Platforms, Inc.
Service typeSocial networking and messaging platform (Facebook, Messenger) allowing Organizations to connect their Page and interact with end users
Legal roleIndependent Controller (for end-user Facebook data) or Joint Processor
Processing locationGlobal (Meta infrastructure); data stored by Trust Soft is hosted on infrastructure located in Vietnam
Data involvedPSID (Page-scoped user ID issued by Meta), public Facebook display name, Messenger message content (including attached images), comments on the Page's posts and the commenter's ID
How it is connectedOrganizations connect their own Page via Facebook Login for Business on app.trustsoft.vn; Trust Soft is not added to the Organization's Business Manager. Page access tokens are stored encrypted and data is isolated per Organization
Organization responsibilityComply with Meta's Platform Terms, notify end users about AI processing (Articles 26 and 27 of the Terms of Service)
Policy linkhttps://www.facebook.com/privacy/policy

5.3. Web Component (embedded on the Organization's website)

  • The Web Component is embedded in the Organization's website per the Organization's configuration.
  • Trust Soft provides the technology. The Organization owns the website and is the Data Controller for end users visiting it.
  • Trust Soft processes messages sent through the Web Component as Data Processor.
  • The Organization is responsible for: displaying privacy notices, cookie consent (if applicable), and complying with the privacy policy of its website.

Part 6. Controls and Reviews

6.1. Provider selection criteria

Trust Soft applies the following criteria when selecting third-party providers:

  • Hold international security certifications (ISO 27001, SOC 2, or equivalent)
  • Commit to comply with Vietnamese law, particularly Decree 13/2023/ND-CP and the Cybersecurity Law
  • Have a signed DPA or equivalent commitment in writing
  • Commit not to use customer data to train AI models without consent
  • Have a clear security incident notification mechanism
  • Publish a complete privacy policy.

6.2. Periodic review

  • Trust Soft performs risk reviews of third-party providers at least every 12 months.
  • Ad-hoc reviews on material changes (provider policy, security incidents, legal changes).
  • Review results are retained and made available to Organizations on valid request.

6.3. Organization rights

  • Request detailed information about a specific provider (certifications, DPA, storage location).
  • Request exclusion of a provider from its data processing under Article 14.3.
  • Request periodic reports on the providers processing its data.
  • Participate in audits of Trust Soft's processing activities, per Service Contract terms.

6.4. Contact

Legallegal@trustsoft.com.vn
Data Protection Officer (DPO)dpo@trustsoft.com.vn
Security incident contact (24/7)security@trustsoft.com.vn
General supportsupport@trustsoft.com.vn

─── End of document ───

TrustAI

Online