Sub-processors used by SoFaaS™.
Hospital security teams ask for the sub-processor list early. This is the standing answer — what each provider does, where they operate, and whether a BAA is in place.
Last reviewed: May 12, 2026. Material changes are communicated to deployed customers ahead of the change.
| Sub-processor | Purpose | Region | BAA |
|---|---|---|---|
| Amazon Web Services (AWS) | Compliant cloud hosting for the SoFaaS™ runtime | United States (us-east, us-west) | Yes |
| Supabase | Managed Postgres, auth, storage for runtime metadata | United States | Yes |
| Cloudflare | Edge network, DDoS protection, bot management for marketing surface | Global edge | Not applicable — no PHI processed |
| Resend | Transactional email delivery (notifications, auth) | United States | Not applicable — no PHI in transactional email content |
| Stripe | Billing and subscription management | United States | Not applicable — no PHI processed |
Notes for hospital security review
PHI handling. PHI inside the SoFaaS™ runtime is processed and stored only by sub-processors operating under a BAA. Sub-processors marked “not applicable” do not receive PHI in the course of providing their service.
Per-deployment additions. If a vendor on SoFaaS™ uses a sub-processor specific to their product (for example, a model provider for an AI ambient app), it is disclosed as part of that vendor's deployment posture, not as a SoFaaS™-wide sub-processor.
Change notifications. Material changes to the sub-processor list — additions, removals, or region changes that affect data residency — are communicated to deployed customers ahead of the change. Marketing-only sub-processors that never receive PHI may change without notice.
Need the full evidence packet?
SOC 2 Type II report, BAA template, and the standardized hospital security questionnaire response — shareable under NDA the same week procurement asks.
Talk to us