Trust Centre
Sub-processors
Last updated 10 July 2026
Current runtime suppliers, reviewed 15 July 2026. Contract and account-level assurance actions are shown rather than implied to be complete.
| Sub-processor | Service | Data processed | Location | Assurance status |
|---|---|---|---|---|
| Supabase (on AWS) | Database, authentication, private file storage and Edge Functions | Workspace records and files, account identities and audit events | London, UK (AWS eu-west-2) | DPA execution and account-level configuration evidence required before real-data pilot |
| Amazon Web Services (Bedrock) | Optional AI analysis and drafting | Minimised document text; sensitive staff/complaint/incident AI is disabled by default | London, UK (eu-west-2, direct in-region model only) | AWS DPA and provider terms must be filed before real-data pilot |
| Cloudflare | Web hosting, TLS, DNS and CDN | Traffic and request metadata in transit; operational logs | Global edge network; UK edge processing is not contractually guaranteed | Cloudflare DPA/addendum must be filed before real-data pilot |
| Resend | Transactional email | Recipient name/email and fixed-template notification content | EU (Ireland) | DPA must be filed before real-data pilot |
| Sentry (Functional Software) | Browser error reporting | Scrubbed error, stack, route and device metadata; no replay or tracing | EU (Germany) | DPA and retention settings must be filed before real-data pilot |
What we deliberately don't use
- No behavioural analytics, advertising pixels or data brokers.
- Sentry is used for error reporting. Session replay and performance tracing are disabled; error data is scrubbed before sending.
Changes
Supplier changes must be recorded here and in the internal processing register before use. Executed DPAs, retention settings and transfer evidence are launch gates for any real-data pilot; they are not represented as complete until filed. Supporting evidence is available through the evidence room when complete.
