Skip to content

Route5

Trust · Subprocessors

Who touches your data — and why.

Living subprocessors list for procurement and RoPA. AI vendors only receive prompts when AI is enabled; enterprise workspaces can disable AI entirely.

Full Trust Center copy follows this language.
7 vendorsUpdated with each material changePrivacy policy

Current subprocessors

VendorRoleTypical regionData categoriesAgreement
ClerkAuthentication & sessionsUS (configurable)Identity, sessions, org membershipClerk DPA
SupabasePostgres workspace dataUS (project region)Workspace Postgres — commitments, audit, prefsSupabase DPA
VercelApplication hosting / edgeGlobal edge + US originRequest logs, static assets, serverless runtimeVercel DPA
OpenAI / xAIModel inference (Capture, Cleo)Provider regionsPrompts/context only when AI features are enabledProvider terms · enterprise opt-out available
StripeBillingGlobalBilling identity — CHD stays with Stripe (PCI out of scope)Stripe DPA
ComposioOptional toolkit OAuth (when configured)USOptional toolkit OAuth tokens when Connect is usedComposio terms
UpstashDistributed rate limits (when configured)US/EU (config)Rate-limit counters only (no customer content)Upstash DPA

Material changes are posted here and reflected in /api/r5e/assurance. For residency questions, see Architecture.

Need a signed DPA?

Draft is public. Countersignature is sales-led for enterprise deals — never a fake seal.