Trust center
Trust center
Subprocessors
Every third party that may process customer data. We notify customers at least 30 days before engaging a new subprocessor for any covered data category.
| Subprocessor | Purpose | Data categories | Location | BAA |
|---|---|---|---|---|
| Supabase | Primary application database and file storage. | Customer content (incl. PHI), audit log, account data | US | Signed |
| Amazon Web Services | AI inference on de-identified prompts. | De-identified prompts only (Safe Harbor) | US (HIPAA-eligible region) | Signed |
| Amazon Web Services (S3) | Encrypted off-site backup of production data. | Customer content (encrypted at rest) | US | Signed |
| Adobe Sign (Acrobat Sign) | Electronic signature on recommendation bundles and state board filings. | Signer identity, signed PDF artifacts (may contain PHI) | US | Signed |
| Intuit QuickBooks Online | Invoice drafting from time entries and bundle outcomes. | Facility-level billing metadata. No PHI on invoice line items. | US | N/A — no PHI |
| Google Cloud (Calendar API) | Two-way calendar sync via OAuth. | Calendar event titles/times. No PHI in event body. | US | On request |
| Microsoft (Outlook/Graph API) | Two-way calendar sync via OAuth. | Calendar event titles/times. No PHI in event body. | US | On request |
| Resend | Transactional and opt-in marketing email. | Recipient email, subject line, sanitized body. | US | Signed |
| Twilio | SMS reminders (opt-in only). | Recipient phone, sanitized SMS body. | US | Signed |
| Render | Application hosting. | Application logs (no PHI). HTTP request metadata. | US | Signed |
| Cloudflare | DNS, edge caching, DDoS protection. | HTTP request metadata only. No PHI. | Global CDN | N/A — no PHI |
Last updated 2026-05-30. Subscribe to subprocessor changes by emailing [email protected].