Subprocessor register template
Publish a dated, contract-aligned list before launch. The codebase can integrate the providers below; inclusion in source does not prove that a provider is active in a particular deployment.
| Provider/category | Purpose | Data involved | Region/location | Active in deployment? |
|---|---|---|---|---|
| Hosting/CDN provider | Application delivery and compute | Request metadata and application traffic | [region] | [yes/no] |
| PostgreSQL provider | Private application records | Customer content and account data | [region] | [yes/no] |
| Object-storage provider | Contracts and uploaded files | Customer documents | [region] | [yes/no] |
| Identity provider | Authentication/session management | Identity, email, session identifiers | [region] | [yes/no] |
| Resend or replacement | Invitation email | Name, email, workspace, invite URL | [region] | [yes/no] |
| Anthropic or replacement | Optional drafting assistance | Minimum deal facts sent by approved workflows | [region] | [yes/no] |
| Monitoring/error provider | Reliability and security telemetry | Redacted diagnostics and request metadata | [region] | [yes/no] |
Record legal entity, service URL, processing location, transfer mechanism, security terms, deletion behavior, and customer-notice procedure for every active provider. AI is tenant-disabled by default; never mark its provider active merely because the dependency is installed.
Next: deployment