Skip to main content
Trust center

Trust center

Subprocessors

Every third party that may process customer data. We notify customers at least 30 days before engaging a new subprocessor for any covered data category.

Electronic signature is not on this list. Signing happens inside the platform. A signature is recorded with a timestamped attestation and a hash of the document that was signed, and for recommendations carrying PHI the signing record is written in our own environment. No third party receives the signed document or the signer’s identity.

AI inference never receives PHI. Prompts are de-identified to the HIPAA Safe Harbor standard before they leave our environment, and the de-identification is verified at the egress boundary — a prompt containing residual identifiers is blocked rather than sent. Our primary inference provider operates under a signed BAA. Anthropic is used only as failover when that provider is throttled or unavailable, and is listed here because it may receive de-identified prompts, not because it receives PHI.

SubprocessorPurposeData categoriesLocationBAA
SupabasePrimary application database and file storage — de-identified data only.Safe Harbor tokens (residents, facilities, prescribers), audit log (counts and IDs, PHI-free), staff account data. No direct identifiers.USNot required — de-identified
Amazon Web Services (Lambda + DynamoDB)De-identification on ingest and re-identification at render — the compute inside the PHI boundary.PHI: the re-identification map linking Safe Harbor tokens to real resident identities, and charts in flight through de-identification. Encrypted with a customer-managed KMS key.US (us-east-2)Signed
AnthropicAI inference for recommendation drafting and assistive summaries — the primary and sole inference provider.De-identified prompts only (Safe Harbor), verified at egressUSNot required — de-identified
Amazon Web Services (S3)Raw chart ingest and rendered letter artifacts — the storage layer inside the PHI boundary.PHI: charts as uploaded (pre-de-identification) and rendered letters carrying resident identifiers. Encrypted with a customer-managed KMS key; every object access logged to CloudTrail.US (us-east-2)Signed
Amazon Web Services (S3 — off-site backup)Daily backup of the application database and stored files, held outside the primary provider.Complete copy of the Supabase database (Safe Harbor tokens, staff account records) and Storage objects. Customer-managed KMS key, versioned, Object-Locked, seven-year retention.US (us-east-2)Signed
Intuit QuickBooks OnlineInvoice drafting from time entries and bundle outcomes.Facility-level billing metadata. No PHI on invoice line items.USN/A — no PHI
Google Cloud (Calendar API)Two-way calendar sync via OAuth.Calendar event titles/times. No PHI in event body.USOn request
Microsoft (Outlook/Graph API)Two-way calendar sync via OAuth.Calendar event titles/times. No PHI in event body.USOn request
ResendTransactional and opt-in marketing email.Recipient email, subject line, sanitized body. No PHI.USN/A — no PHI
TwilioSMS and RCS reminders (opt-in only).Recipient phone, sanitized message body and media (facility/count only — no PHI, enforced by template whitelist).USN/A — no PHI
RenderApplication hosting — de-identified compute only.Application logs (no PHI). HTTP request metadata.USN/A — no PHI
CloudflareDNS, edge caching, DDoS protection.HTTP request metadata only. No PHI.Global CDNN/A — no PHI

Last updated 2026-05-30. Subscribe to subprocessor changes by emailing [email protected].