Subprocessors
These providers help Secured Roots deliver the service. We limit each integration to the information needed for its function.
Last updated August 6, 2026| Provider | Purpose | Information involved | Provider notice |
|---|---|---|---|
| Supabase | Database, authentication, and evidence-file storage | Account, organization, program, roster, incident, billing-status, and evidence data | Privacy information |
| Vercel | Web application hosting, request routing, and deployment | Application requests, IP and device metadata, and server-rendered application data | Privacy information |
| Stripe | Checkout, subscriptions, invoices, tax calculation, and customer portal | Billing contacts, organization and address data, subscription state, invoices, and payment data entered directly into Stripe | Privacy information |
| Resend | Transactional email delivery and delivery-status webhooks | Recipient email, message content, and delivery metadata | Privacy information |
| OpenAI | Assisted drafting of policy documents | Organization profile, selected framework, assessment answers and notes, and state-pack requirements submitted for generation | Privacy information |
Changes
This page is the current list. Material additions that meaningfully change how customer data is processed will be posted here before or when the provider begins processing, except where urgent security or availability needs make advance notice impractical.
Questions or objections
Contact gabe.holcomb@securedroots.com. We will explain the provider’s role and available options; some core providers are necessary to operate the service.