Subprocessors

The third parties that process data on our behalf.

Every third party that processes personal information on Verinode’s behalf is listed here. Required by GDPR Article 28(2) and CCPA service-provider disclosure rules. Each name links to that company’s own privacy policy, so you can check what we say about them against what they say about themselves. We update this page whenever the list changes; the date below records the most recent revision.

Last updated: July 2026

Active subprocessors

Infrastructure

Vercel

PurposeApplication hosting and compute.

DataOperator and user data processed by the application.

LocationUnited States, with global edge.

SafeguardsEU-Commission Standard Contractual Clauses (SCCs 2021/914), SOC 2 Type 2, ISO 27001.

Supabase

PurposeManaged database, file storage, and authentication.

DataOperator and user personal information.

LocationCanada and the United States; regional deployment, including the EU, available on request.

SafeguardsEU-Commission SCCs (2021/914), SOC 2 Type 2, HIPAA-eligible plans.

Cloudflare

PurposeNetwork, DNS, and email routing.

DataInbound email content, in transit.

LocationGlobal edge.

SafeguardsEU-Commission SCCs, SOC 2 Type 2, ISO 27001.

Backblaze B2

PurposeEncrypted off-site backup storage.

DataEncrypted backups only. Backblaze cannot read them.

LocationCanada. Operator data is primarily stored in the United States, so the backup copy is a transfer to Canada, and it carries ciphertext only.

SafeguardsPrivate storage under credentials held separately from every other vendor we use. Backups are encrypted before upload; Backblaze never holds the decryption key. Retention is 90 days, then automatic deletion, which is what keeps the erasure window in the Data Use Policy true. SOC 2 Type 2. Data Processing Addendum executed, including EU-Commission SCCs.

Language model providers

We use language models for document extraction, analysis, and IQ's reasoning. Any provider listed here may handle any of that work: we route between them for availability, cost, and quality, and one provider standing in for another is normal operation. Each is held to the same terms, so the routing does not change how your data is treated.

Anthropic

PurposeLanguage model processing.

DataDocument and message content, which may contain personal information. Direct identifiers are replaced with placeholders on the text paths (forwarded email bodies, pasted text, voice transcripts); PDFs are sent as rendered pages without masking. Also operator account metadata, and the prompts and responses themselves.

LocationUnited States.

SafeguardsNo training on our data under paid API terms, contractually guaranteed. Prompts and responses are held for up to 30 days for abuse monitoring, then deleted; that window is the provider's standard trust-and-safety retention and is not training, not human review in the ordinary course, and not available to anyone else. Direct identifiers are stripped from forwarded email bodies, pasted text, and voice transcripts before they are sent. PDFs are a deliberate exemption and go to the vision model as rendered pages: masking a scan before it is read destroys extraction on invoices and estimates, so that content is sent unmasked. We name the exemption rather than implying blanket masking. Zero-retention terms are a planned upgrade, not a control we claim today. Data Processing Addendum executed. SOC 2 Type 2.

OpenAI

PurposeLanguage model processing, embeddings, and speech synthesis.

DataDocument and message content, which may contain personal information. Direct identifiers are replaced with placeholders on the text paths (forwarded email bodies, pasted text, voice transcripts); PDFs are sent as rendered pages without masking. Also operator account metadata, and the prompts and responses themselves. No operator voice recordings are sent to OpenAI.

LocationUnited States.

SafeguardsNo training on our data under paid API terms, contractually guaranteed. Prompts and responses are held for up to 30 days for abuse monitoring, then deleted; that window is the provider's standard trust-and-safety retention and is not training, not human review in the ordinary course, and not available to anyone else. Direct identifiers are stripped from forwarded email bodies, pasted text, and voice transcripts before they are sent. PDFs are a deliberate exemption and go to the vision model as rendered pages: masking a scan before it is read destroys extraction on invoices and estimates, so that content is sent unmasked. We name the exemption rather than implying blanket masking. Zero-retention terms are a planned upgrade, not a control we claim today. Data Processing Addendum executed. SOC 2 Type 2.

Google (Gemini)

PurposeLanguage model processing.

DataDocument and message content, which may contain personal information. Direct identifiers are replaced with placeholders on the text paths (forwarded email bodies, pasted text, voice transcripts); PDFs are sent as rendered pages without masking. Also operator account metadata, and the prompts and responses themselves.

LocationUnited States.

SafeguardsNo training on our data under paid API terms. Data Processing Addendum and EU-Commission SCCs pending execution. SOC 2 Type 2, ISO 27001.

Document processing

LlamaIndex (LlamaParse)

PurposeConverts uploaded documents into machine-readable text so they can be analyzed.

DataContent of documents operators upload or forward, which may contain personal information.

LocationUnited States.

SafeguardsNo training on customer content under LlamaIndex's standard terms. SOC 2 Type 2. Data Processing Addendum pending execution.

Voice

Deepgram

PurposeSpeech-to-text for voice mode and for audio and video that operators send in.

DataOperator voice recordings. Audio is transcribed and discarded; only the transcript is retained.

LocationUnited States.

SafeguardsZero-retention mode enabled on every request: Deepgram stores neither the audio nor the transcript. No training on customer audio. SOC 2 Type 2. HIPAA-eligible plan with BAA available on request. Data Processing Addendum executed.

Recall.ai

PurposeSends the Verinode Notetaker into a video meeting when an operator asks it to, and returns that meeting's transcript.

DataAudio and video of the meetings an operator sends it to, which include the voice of everyone on the call, and the transcript produced from them.

LocationUnited States.

SafeguardsThe bot joins under a name every participant can see, so a room always knows it is there; the operator chooses which meetings it joins and owns the recording-consent decision. Recordings are set to be deleted after 24 hours, and Verinode keeps the transcript rather than the recording. Security certifications and the Data Processing Addendum are under review and not yet in place.

Identity and access

WorkOS

PurposeEnterprise single sign-on and directory provisioning.

DataUser name, email address, role assignments, and directory metadata. No operator business data.

LocationUnited States.

SafeguardsEU-Commission SCCs, SOC 2 Type 2, signed DPA.

Operations

Resend

PurposeTransactional and notification email.

DataRecipient name and email address, message subject and body.

LocationUnited States.

SafeguardsEU-Commission SCCs, SOC 2 Type 2.

Twilio

PurposeText-message notifications.

DataRecipient phone number, message body.

LocationUnited States.

SafeguardsEU-Commission SCCs, SOC 2 Type 2, HIPAA BAA available on request.

Stripe

PurposeSubscription billing and payment processing.

DataOperator name, billing email, billing address, payment method (card stored at Stripe, not at Verinode).

LocationUnited States and global processing nodes.

SafeguardsPCI-DSS Level 1, SOC 2 Type 2, EU-Commission SCCs.

Intuit (QuickBooks Online)

PurposeOur own bookkeeping and accounting.

DataCustomer records for billing: business name, contact name and email, billing address, and invoice amounts. This is Verinode's own ledger. When an operator connects their QuickBooks to Verinode, that runs the other way: we read from their books at their direction and send them nothing.

LocationUnited States.

SafeguardsSOC 2 Type 2. Data Processing Addendum pending execution.

Google Workspace

PurposeOur own email, calendar, and document storage.

DataCorrespondence with operators and anything personal it contains, together with internal documents and meeting records.

LocationUnited States, with global infrastructure.

SafeguardsData Processing Addendum executed, including EU-Commission SCCs. Workspace content is not used for advertising or to train models, under Google's Cloud terms. SOC 2 Type 2, ISO 27001.

Attio

PurposeCustomer relationship management: our own record of the operators and prospective operators we talk to.

DataBusiness contact details and our correspondence with them. No data from the platform itself: Attio is not connected to Verinode's systems, so nothing flows to it automatically.

LocationUnited Kingdom.

SafeguardsSOC 2 Type 2. UK GDPR and EU-Commission SCCs under Attio's standard Data Processing Addendum; execution pending.

Better Stack

PurposeIndependent retention of security audit logs.

DataAudit metadata only. No operator business data.

LocationUnited States.

SafeguardsSCCs where applicable, SOC 2 Type 2 (Better Stack Telemetry product).

Apify

PurposeCollection of public web content for vendor, regulatory, and market research.

DataNone: public sources only.

LocationUnited States and EU.

SafeguardsSCCs where applicable (no operator personal information processed).

Analytics and observability

Vercel Analytics and Logs

PurposePerformance monitoring and error tracking.

DataRequest paths, response times, error traces. No operator personal information.

LocationUnited States.

SafeguardsSame as Vercel hosting.

Google Analytics

PurposeAggregate traffic measurement on the public marketing site.

DataWebsite usage data: pages viewed, referring site, approximate region, and a browser identifier. Not present in the signed-in application, so operator activity inside Verinode never reaches Google.

LocationUnited States.

SafeguardsGoogle Analytics 4, which does not store IP addresses. Advertising and remarketing features are not enabled. Google's Data Processing Terms and EU-Commission SCCs apply.

What subprocessors we do not use

For clarity (questions come up):

  • ·Carrier-aligned analytics providers (Verisk, Cotality, and similar): never used as a sub-processor and never given operator data. This is a binding commitment in the Data Use Policy.
  • ·Advertising networks and data brokers: none, ever. The marketing site measures its own traffic in aggregate, with advertising and remarketing features turned off, and that measurement is absent from the signed-in application entirely.
  • ·Operator-data sale or licensing arrangements: none, ever.

How we evaluate subprocessors

Before adding a sub-processor, we verify:

  1. 1.They have a published security posture (SOC 2 Type 2 or ISO 27001 ideally; demonstrably substantive security otherwise).
  2. 2.They will sign a Data Processing Agreement (DPA) consistent with our obligations to operators.
  3. 3.For non-US operators: they offer EU-Commission Standard Contractual Clauses or equivalent transfer mechanism.
  4. 4.For LLM providers: a no-training-on-our-data clause is contractually guaranteed. Zero-retention is preferred where a provider offers it, and we hold it with Deepgram but not with Anthropic or OpenAI.
  5. 5.We can audit their processing on request (right-to-audit clause in DPA).

Notification of changes

We keep this page current and email operators when the subprocessor list changes. If a change affects how your data is processed and you object, you can exercise your erasure right at any time under our normal data-subject-request procedure.

Contact

Questions, objections, or DPA requests: [email protected].

This is a living document. Subprocessor changes take effect on the revision date above.