Skip to main content
Trust center

Trust center

Subprocessors

Every third party that may process customer data. We notify customers at least 30 days before engaging a new subprocessor for any covered data category.

SubprocessorPurposeData categoriesLocationBAA
SupabasePrimary application database and file storage.Customer content (incl. PHI), audit log, account dataUSSigned
Amazon Web ServicesAI inference on de-identified prompts.De-identified prompts only (Safe Harbor)US (HIPAA-eligible region)Signed
Amazon Web Services (S3)Encrypted off-site backup of production data.Customer content (encrypted at rest)USSigned
Adobe Sign (Acrobat Sign)Electronic signature on recommendation bundles and state board filings.Signer identity, signed PDF artifacts (may contain PHI)USSigned
Intuit QuickBooks OnlineInvoice drafting from time entries and bundle outcomes.Facility-level billing metadata. No PHI on invoice line items.USN/A — no PHI
Google Cloud (Calendar API)Two-way calendar sync via OAuth.Calendar event titles/times. No PHI in event body.USOn request
Microsoft (Outlook/Graph API)Two-way calendar sync via OAuth.Calendar event titles/times. No PHI in event body.USOn request
ResendTransactional and opt-in marketing email.Recipient email, subject line, sanitized body.USSigned
TwilioSMS reminders (opt-in only).Recipient phone, sanitized SMS body.USSigned
RenderApplication hosting.Application logs (no PHI). HTTP request metadata.USSigned
CloudflareDNS, edge caching, DDoS protection.HTTP request metadata only. No PHI.Global CDNN/A — no PHI

Last updated 2026-05-30. Subscribe to subprocessor changes by emailing [email protected].