Security · Sub-processors

Sub-processors used by SoFaaS™.

Hospital security teams ask for the sub-processor list early. This is the standing answer — what each provider does, where they operate, and whether a BAA is in place.

Last reviewed: May 12, 2026. Material changes are communicated to deployed customers ahead of the change.

Sub-processorPurposeRegionBAA
Amazon Web Services (AWS)Compliant cloud hosting for the SoFaaS™ runtimeUnited States (us-east, us-west)Yes
SupabaseManaged Postgres, auth, storage for runtime metadataUnited StatesYes
CloudflareEdge network, DDoS protection, bot management for marketing surfaceGlobal edgeNot applicable — no PHI processed
ResendTransactional email delivery (notifications, auth)United StatesNot applicable — no PHI in transactional email content
StripeBilling and subscription managementUnited StatesNot applicable — no PHI processed

Notes for hospital security review

PHI handling. PHI inside the SoFaaS™ runtime is processed and stored only by sub-processors operating under a BAA. Sub-processors marked “not applicable” do not receive PHI in the course of providing their service.

Per-deployment additions. If a vendor on SoFaaS™ uses a sub-processor specific to their product (for example, a model provider for an AI ambient app), it is disclosed as part of that vendor's deployment posture, not as a SoFaaS™-wide sub-processor.

Change notifications. Material changes to the sub-processor list — additions, removals, or region changes that affect data residency — are communicated to deployed customers ahead of the change. Marketing-only sub-processors that never receive PHI may change without notice.

Need the full evidence packet?

SOC 2 Type II report, BAA template, and the standardized hospital security questionnaire response — shareable under NDA the same week procurement asks.

Talk to us