SECURITY DOCUMENT
SUBPROCESSOR LIST
Production data recipients are documented before use. Provider-specific contractual and regional facts are verified for the deployed environment.
SUPABASE
PLATFORM SERVICESUsed for RUNSHIFT authentication, PostgreSQL, storage and Edge Functions. Workspace/account/source/evidence data may be processed as required by the deployed RUNSHIFT environment.
OPENAI API
LIMITED MODEL PROCESSINGUsed for server-side candidate-generation and planning functions. The model receives explicitly constructed structural context for those functions. HubSpot OAuth tokens, call transcripts and email bodies are not part of the required model input.
APPLICATION / HOSTING RUNTIME
DEPLOYMENT SPECIFICThe production hosting/runtime serving RUNSHIFT processes application and request traffic according to the deployed architecture. The actual provider, region and contractual terms are recorded for the production environment rather than inferred here.
HUBSPOT
CONNECTED SOURCE — NOT SILENTLY CLASSIFIED AS A SUBPROCESSORHubSpot is the customer's connected CRM/source system. Its contractual role in the customer's stack is addressed in the customer-specific data-flow and DPA review where legally appropriate.
CHANGE CONTROL
A new production service that can receive or process customer data is added to the production register before that access occurs.