Vendor transparency

Subprocessors

These providers help Secured Roots deliver the service. We limit each integration to the information needed for its function.

Last updated August 6, 2026
ProviderPurposeInformation involvedProvider notice
SupabaseDatabase, authentication, and evidence-file storageAccount, organization, program, roster, incident, billing-status, and evidence dataPrivacy information
VercelWeb application hosting, request routing, and deploymentApplication requests, IP and device metadata, and server-rendered application dataPrivacy information
StripeCheckout, subscriptions, invoices, tax calculation, and customer portalBilling contacts, organization and address data, subscription state, invoices, and payment data entered directly into StripePrivacy information
ResendTransactional email delivery and delivery-status webhooksRecipient email, message content, and delivery metadataPrivacy information
OpenAIAssisted drafting of policy documentsOrganization profile, selected framework, assessment answers and notes, and state-pack requirements submitted for generationPrivacy information

Changes

This page is the current list. Material additions that meaningfully change how customer data is processed will be posted here before or when the provider begins processing, except where urgent security or availability needs make advance notice impractical.

Questions or objections

Contact gabe.holcomb@securedroots.com. We will explain the provider’s role and available options; some core providers are necessary to operate the service.