Trust

Subprocessor register template

Publish a dated, contract-aligned list before launch. The codebase can integrate the providers below; inclusion in source does not prove that a provider is active in a particular deployment.

Provider/categoryPurposeData involvedRegion/locationActive in deployment?
Hosting/CDN providerApplication delivery and computeRequest metadata and application traffic[region][yes/no]
PostgreSQL providerPrivate application recordsCustomer content and account data[region][yes/no]
Object-storage providerContracts and uploaded filesCustomer documents[region][yes/no]
Identity providerAuthentication/session managementIdentity, email, session identifiers[region][yes/no]
Resend or replacementInvitation emailName, email, workspace, invite URL[region][yes/no]
Anthropic or replacementOptional drafting assistanceMinimum deal facts sent by approved workflows[region][yes/no]
Monitoring/error providerReliability and security telemetryRedacted diagnostics and request metadata[region][yes/no]

Record legal entity, service URL, processing location, transfer mechanism, security terms, deletion behavior, and customer-notice procedure for every active provider. AI is tenant-disabled by default; never mark its provider active merely because the dependency is installed.

Next: deployment