Subprocessors
Last updated: May 6, 2026
Auditshore uses the third-party service providers ("subprocessors") listed below to deliver the Service. Each subprocessor is contractually bound to handle customer data only as needed to provide its service to us, and only in accordance with applicable data protection terms.
We will provide reasonable notice of material changes to this list (additions or replacements of subprocessors that handle customer data) prior to the change taking effect, where practicable. Customers requiring a Data Processing Agreement (DPA) may request one from legal@auditshore.io.
Current Subprocessors
| Subprocessor | Purpose | Data Handled | Region | Notes |
|---|---|---|---|---|
| Anthropic, PBC Privacy Policy | AI processing (Claude API) | Document content sent for analysis | United States | Inputs and outputs retained up to 30 days for trust and safety. Feedback submission is disabled, so customer data is not used to train Anthropic models. |
| Google LLC Privacy Policy | AI processing (Gemini API) | Document content sent for analysis | United States | Paid-tier inputs and outputs retained for a short period (typically 24–72 hours) to detect policy violations. Paid-tier Gemini data is not used to train Google models. |
| Supabase, Inc. Privacy Policy | Database, authentication, file storage | Account information, uploaded SOC reports, customer data | United States | Encryption at rest. Row-level security enforces organization-level isolation. Retention follows customer account lifecycle. |
| Vercel, Inc. Privacy Policy | Application hosting, traffic analytics, performance monitoring | Page views, IP addresses, performance metrics | Global edge network (data primarily processed in US) | Analytics is cookieless. No advertising cookies are set. |
| Inngest, Inc. Privacy Policy | Asynchronous job orchestration for long-running analysis | Job metadata and execution context (no SOC report content stored beyond execution) | United States | Used to coordinate the AI analysis pipeline. Job records retained for execution history. |
| Functional Software, Inc. (Sentry) Privacy Policy | Error monitoring and reliability | Stack traces, browser metadata, error context (no SOC report content) | United States | Used to detect and diagnose bugs. SOC report content is excluded from error reports. |
| Calendly, LLC Privacy Policy | Demo scheduling | Booker name, email, scheduling preferences (only when user books a demo) | United States | Engaged only when prospects interact with the demo booking widget. May set third-party cookies at point of interaction. |
Contact
For questions about our subprocessors or to request our standard Data Processing Agreement, contact legal@auditshore.io.