Every third party that touches your data,
named on the record.
A subprocessor is any third-party service that may process customer data on SpecSense’s behalf. Below is the complete list — what they do, where they run, and their security attestations. We update this page when subprocessors are added or removed.
Subprocessor change notifications.
Enterprise customers receive 30 days’ written notice before any material subprocessor change, with an objection window as defined in the DPA. Pilot and Team customers can subscribe to notifications at security@specsense.ai.
Hosting, compute & storage
The core platforms that run SpecSense — the marketing site, pilot portal, database, and document storage.
| Vendor | Purpose | Region | Attestations | DPA |
|---|---|---|---|---|
Vercel Vercel Inc. | Marketing site hosting, edge CDN, DNS resolution. | Global edge · EU regions available for functions | SOC 2 Type II · ISO 27001 · GDPR-compliant | Link ↗ |
Railway Railway Corp. | Pilot portal compute + document storage volume (current pilot stack). Migrating to Supabase + Fly.io for enterprise. | US-East (current) · EU pinning on roadmap | SOC 2 Type II | Link ↗ |
Supabase Supabase Inc. | Enterprise Postgres database + object storage (on the Q4 2026 roadmap). Not yet in production for customer data. | Frankfurt (eu-central-1) — enterprise target | SOC 2 Type II · HIPAA-ready | Link ↗ |
Fly.io Fly.io Inc. | Enterprise compute platform (on the Q1 2027 roadmap). Not yet in production for customer workloads. | Frankfurt (fra) + London (lhr) — enterprise target | SOC 2 in progress · GDPR-compliant | Link ↗ |
Cloudflare Cloudflare Inc. | DNS management (specsense.ai) and TLS certificate issuance. | Global | SOC 2 Type II · ISO 27001 · PCI DSS | Link ↗ |
AI inference
AI providers that generate candidate findings. All are contractually bound not to train on customer data.
| Vendor | Purpose | Region | Attestations | DPA |
|---|---|---|---|---|
Anthropic Anthropic PBC | Primary AI provider — Claude models generate candidate findings. Contractual zero-training on customer inputs. | US (default) · EU-region routing via AWS Bedrock on roadmap | SOC 2 Type II · zero training on API inputs (contractual) | Link ↗ |
Payments, email & scheduling
Vendors that handle customer identifiers (name, email, payment) but not engineering documents.
| Vendor | Purpose | Region | Attestations | DPA |
|---|---|---|---|---|
Stripe Stripe Payments Europe Ltd. (EU customers) | Payment processing for marketplace and pilot invoicing. No engineering documents pass through Stripe. | Ireland (EU customers) · US (global fallback) | PCI DSS Level 1 · SOC 2 Type II · ISO 27001 | Link ↗ |
Resend Resend Inc. | Transactional email delivery — pilot notifications, magic-link authentication, DPA delivery. No document content in email bodies. | US · EU region available | SOC 2 Type II | Link ↗ |
Cal.com Cal.com Inc. | Pilot introduction scheduling. Handles name + email only; no document access. | EU-hosted instance (cal.eu) for SpecSense bookings | SOC 2 Type II · GDPR-compliant | Link ↗ |
Analytics & error monitoring
Internal-facing tools that receive aggregate, non-document telemetry.
| Vendor | Purpose | Region | Attestations | DPA |
|---|---|---|---|---|
Vercel Analytics Vercel Inc. | Aggregate site analytics (page views, referrers). No cookies, no PII. Cookieless by design. | Global edge | SOC 2 Type II · GDPR-compliant | Link ↗ |
Need a signed DPA?
Data Processing Addendum available on request. Named security contact assigned for enterprise conversations.
