Trust & Transparency

Every third party that touches your data,
named on the record.

A subprocessor is any third-party service that may process customer data on SpecSense’s behalf. Below is the complete list — what they do, where they run, and their security attestations. We update this page when subprocessors are added or removed.

Last updated: 13 August 2026← Back to Security

Subprocessor change notifications.

Enterprise customers receive 30 days’ written notice before any material subprocessor change, with an objection window as defined in the DPA. Pilot and Team customers can subscribe to notifications at security@specsense.ai.

Infrastructure

Hosting, compute & storage

The core platforms that run SpecSense — the marketing site, pilot portal, database, and document storage.

VendorPurposeRegionAttestationsDPA

Vercel

Vercel Inc.

Marketing site hosting, edge CDN, DNS resolution.Global edge · EU regions available for functionsSOC 2 Type II · ISO 27001 · GDPR-compliantLink ↗

Railway

Railway Corp.

Pilot portal compute + document storage volume (current pilot stack). Migrating to Supabase + Fly.io for enterprise.US-East (current) · EU pinning on roadmapSOC 2 Type IILink ↗

Supabase

Supabase Inc.

Enterprise Postgres database + object storage (on the Q4 2026 roadmap). Not yet in production for customer data.Frankfurt (eu-central-1) — enterprise targetSOC 2 Type II · HIPAA-readyLink ↗

Fly.io

Fly.io Inc.

Enterprise compute platform (on the Q1 2027 roadmap). Not yet in production for customer workloads.Frankfurt (fra) + London (lhr) — enterprise targetSOC 2 in progress · GDPR-compliantLink ↗

Cloudflare

Cloudflare Inc.

DNS management (specsense.ai) and TLS certificate issuance.GlobalSOC 2 Type II · ISO 27001 · PCI DSSLink ↗
AI providers

AI inference

AI providers that generate candidate findings. All are contractually bound not to train on customer data.

VendorPurposeRegionAttestationsDPA

Anthropic

Anthropic PBC

Primary AI provider — Claude models generate candidate findings. Contractual zero-training on customer inputs.US (default) · EU-region routing via AWS Bedrock on roadmapSOC 2 Type II · zero training on API inputs (contractual)Link ↗
Business operations

Payments, email & scheduling

Vendors that handle customer identifiers (name, email, payment) but not engineering documents.

VendorPurposeRegionAttestationsDPA

Stripe

Stripe Payments Europe Ltd. (EU customers)

Payment processing for marketplace and pilot invoicing. No engineering documents pass through Stripe.Ireland (EU customers) · US (global fallback)PCI DSS Level 1 · SOC 2 Type II · ISO 27001Link ↗

Resend

Resend Inc.

Transactional email delivery — pilot notifications, magic-link authentication, DPA delivery. No document content in email bodies.US · EU region availableSOC 2 Type IILink ↗

Cal.com

Cal.com Inc.

Pilot introduction scheduling. Handles name + email only; no document access.EU-hosted instance (cal.eu) for SpecSense bookingsSOC 2 Type II · GDPR-compliantLink ↗
Operational

Analytics & error monitoring

Internal-facing tools that receive aggregate, non-document telemetry.

VendorPurposeRegionAttestationsDPA

Vercel Analytics

Vercel Inc.

Aggregate site analytics (page views, referrers). No cookies, no PII. Cookieless by design.Global edgeSOC 2 Type II · GDPR-compliantLink ↗

Need a signed DPA?

Data Processing Addendum available on request. Named security contact assigned for enterprise conversations.