Sub-Processors
Status: Phase 30 G4.T2 deliverable — sub-processor list with vendor + data category + region + DPA status. Companion docs:
docs/trust-center/index.md— Trust Center root.docs/compliance/soc-2-tsc-2017-control-mapping.md— CC9.2 vendor + business partner risk mapping.
§1 Purpose
This is the public-facing list of sub-processors Claimful uses to provide the platform. Each row carries:
- Vendor — sub-processor name.
- Data category — what data the vendor processes (none / metadata / PHI / PII / payment).
- Region — where the vendor processes the data.
- DPA status — Data Processing Agreement status (
In place/Pending/n/a). - Purpose — why Claimful uses the vendor.
Update cadence: quarterly + on any new vendor onboarding. Customer-facing change notification is delivered via the marketing email list + the platform announcement bar (see ADR 0009 webhook delivery semantics for the change-notification cadence).
§2 Current sub-processor list
Infrastructure
| Vendor | Data category | Region | DPA status | Purpose | |---|---|---|---|---| | Cloudflare | Metadata + access logs | US + global edge | In place | Edge CDN + DDoS protection + Rate limiting + DNS | | Vercel | Metadata + frontend deploy artifacts | US | In place | Frontend hosting (marketing, portal, dev-portal, widget) | | Forge (Laravel Forge) | Metadata + deploy configuration | US | In place | Backend API server provisioning + deployment | | AWS (R2 via Cloudflare; Postgres via managed provider) | PHI + PII + payment data | US | In place | Object storage + database hosting | | Postmark | Email content (transactional) + recipient PII | US | In place | Transactional email delivery |
Third-party processors
| Vendor | Data category | Region | DPA status | Purpose | |---|---|---|---|---| | Stripe | Payment data + recipient PII | US + global | In place | Payment processing + Connect payouts (ADR 0030) | | Anthropic | Claim evidence text (PHI-redacted pre-egress per ADR 0012) | US | In place (ZDR) | AI triage + RAG (ADR 0007) | | Mistral | OCR input bytes (PHI-redacted pre-egress per ADR 0012) | EU | In place (ZRA) | OCR fallback (ADR 0002) | | GLM (self-host) | OCR input bytes (PHI-redacted pre-egress per ADR 0012) | Self-host | In place (self-attestation) | OCR primary (ADR 0046 proposed) | | Sentry | Error metadata (PII-scrubbed per ADR 0020) | US | In place | Error observability | | Helicone | AI request metadata (token usage; no payload content) | US | In place | AI cost + latency observability (ADR 0022) |
Operational
| Vendor | Data category | Region | DPA status | Purpose | |---|---|---|---|---| | Linear | Engineering task metadata (no customer data) | US | In place | Task tracking | | GitHub | Source code + build artifacts (no customer data) | US | In place | Source control + CI/CD | | 1Password | Credentials (employees only) | US | In place | Secret management |
§3 Change notification commitment
Per ADR 0009 webhook delivery semantics + CC9.2:
- New sub-processor onboarded → 30-day notice via marketing email list + platform announcement bar before processing begins.
- Sub-processor offboarded → 30-day notice + data deletion timeline (per ADR 0029 GDPR right-to-erasure).
- Sub-processor changes data category (e.g. starts handling PHI) → 30-day notice + customer right to object (terminate without penalty).
§4 Sub-processor SOC 2 / ISO 27001 status
The infrastructure + third-party sub-processors listed above all carry their own SOC 2 Type II reports (or equivalent ISO 27001 certification). The auditor consumes the sub-processor SOC 2 attestations during the CC9.2 vendor risk evaluation.
| Vendor | SOC 2 status | Letter availability | |---|---|---| | Cloudflare | SOC 2 Type II | Public summary; full letter under NDA | | Vercel | SOC 2 Type II | Public summary; full letter under NDA | | Forge (Laravel Forge) | n/a (PaaS for AWS) | n/a | | AWS | SOC 2 Type II + ISO 27001 | Public summary; full letter under NDA | | Postmark | SOC 2 Type II | Public summary; full letter under NDA | | Stripe | SOC 2 Type II + PCI-DSS Level 1 | Public summary; full letter under NDA | | Anthropic | SOC 2 Type II + HIPAA BAA | Public summary; full letter under NDA | | Mistral | SOC 2 Type II in progress | PENDING | | Sentry | SOC 2 Type II + ISO 27001 | Public summary; full letter under NDA | | Helicone | SOC 2 Type II in progress | PENDING | | Linear | SOC 2 Type II + ISO 27001 | Public summary; full letter under NDA | | GitHub | SOC 2 Type II + ISO 27001 | Public summary; full letter under NDA | | 1Password | SOC 2 Type II | Public summary; full letter under NDA |