Trust & Security

SubprocessorPurposeData locationGDPR basis
Supabase (supabase.com)Database, authentication, storage, edge functionsEU (Frankfurt)DPA + EU hosting
CloudflareCDN, DDoS protection, Pages, Workers, R2 backupsGlobal edge / EU R2DPA + Standard Contractual Clauses
ResendTransactional email (magic-link, RFP outreach, notifications)US (EU residency on enterprise tier)DPA + SCC
StripePayment processing, billing, customer portalUS/EU dualDPA + SCC + PCI-DSS Level 1
OpenAIAI proposal parser (GPT-4o verifier) — zero data retention enabledUSDPA + SCC + zero retention
AnthropicAI proposal parser (Claude Sonnet primary) — zero data retention enabledUSDPA + SCC + zero retention
PostHogProduct analytics (funnel events, no PII)EU (eu.i.posthog.com)DPA + EU hosting
SentryError monitoring (no PII captured)EUDPA + EU hosting
StandardStatusTarget date
GDPR DPAAvailable nowDownload at /dpa/
Cookie consent (EU)LiveIAB TCF v2 compliant
SOC 2 Type IIPlannedQ1 2027 target audit window
ISO 27001PlannedH2 2027 (after SOC 2 foundation)
Penetration testAnnual cadence plannedFirst test Q3 2026
PCI-DSSInherited via StripeNo card data touches Easy RFP servers