Full Trust Center copy follows this language.
Current subprocessors
| Vendor | Role | Typical region | Data categories | Agreement |
|---|---|---|---|---|
| Clerk | Authentication & sessions | US (configurable) | Identity, sessions, org membership | Clerk DPA |
| Supabase | Postgres workspace data | US (project region) | Workspace Postgres — commitments, audit, prefs | Supabase DPA |
| Vercel | Application hosting / edge | Global edge + US origin | Request logs, static assets, serverless runtime | Vercel DPA |
| OpenAI / xAI | Model inference (Capture, Cleo) | Provider regions | Prompts/context only when AI features are enabled | Provider terms · enterprise opt-out available |
| Stripe | Billing | Global | Billing identity — CHD stays with Stripe (PCI out of scope) | Stripe DPA |
| Composio | Optional toolkit OAuth (when configured) | US | Optional toolkit OAuth tokens when Connect is used | Composio terms |
| Upstash | Distributed rate limits (when configured) | US/EU (config) | Rate-limit counters only (no customer content) | Upstash DPA |
Material changes are posted here and reflected in /api/r5e/assurance. For residency questions, see Architecture.
Need a signed DPA?
Draft is public. Countersignature is sales-led for enterprise deals — never a fake seal.