Trust · Subprocessors
Subprocessor list
Every third party we engage to process Customer Data on our behalf, plus what they do, what data they touch, where they're located, and whether they offer a BAA.
Effective Last updated June 9, 2026. This is a first-draft document and will be superseded by a lawyer-reviewed version before general availability. Questions: contact@skdaddle.com.
How to read this list
- Purpose: what the subprocessor does for us in the service.
- Data categories: what specific data the subprocessor sees.
- Location: where the data is processed. We operate entirely in the United States today.
- BAA available: whether the subprocessor offers a HIPAA Business Associate Agreement. Required for any subprocessor that touches Protected Health Information when our customer is a HIPAA Covered Entity.
Current subprocessors
| Subprocessor | Purpose | Data categories | Location | BAA |
|---|---|---|---|---|
Clerk Not used for PHI. Clerk is the identity layer only. | Authentication, organization management, multi-factor authentication, invite emails | User name, email address, authentication state, organization membership, session tokens | United States | Not used for PHI |
Supabase | Primary database (PostgreSQL) and storage | All customer data including report content, resident records, audit logs | United States | Available |
Anthropic (Claude API) Anthropic does not train on Customer Data per their commercial agreement. Anthropic offers BAA terms; Skdaddle is responsible for executing them where required. | AI report review and Ace advisor | Report narrative text and structured context fields submitted for AI review or advisor chat | United States | Available |
Voyage AI Embedding of approved narratives is enabled as of September 2026. Narratives are de-identified with the same pass used for AI review before they reach Voyage; the embeddings themselves live in ClearReport's database, not with Voyage. Voyage has not executed a BAA with us, and we do not send identified PHI to this vendor. | Vector embeddings used to retrieve the most relevant regulation text, your organization's reporting criteria, and your organization's own approved past reports during AI report review | Three flows, all de-identified before transmission. (1) Organization- and facility-level reporting criteria text entered by administrators. (2) Approved incident narratives from your organization, with resident names, room numbers, dates of birth and other direct identifiers stripped before they are sent; the resulting embedding is stored in ClearReport's own database, scoped to your organization, and is never retrieved for any other organization. (3) When AI review runs, a de-identified search text derived from the draft is sent to compute a query embedding. Voyage does not retain the text or the embeddings. | United States | Not used for PHI |
Resend Notification emails intentionally carry deadline metadata only, not report narratives. | Transactional email delivery (compliance-deadline digest notifications to administrators) | Administrator name and email address, facility name, form type and deadline dates for overdue or due-soon regulatory deadlines. No resident names and no report narrative content. | United States | Not used for PHI |
Sentry Error monitoring only. Configured to omit query strings; no report narratives, resident records, or PDFs are sent. | Application error monitoring (unhandled exceptions and swallowed server-side failures) | Error messages, stack traces, request paths, and the authenticated user identifier associated with a failing request. Query strings are stripped before transmission. Not a destination for report content; incidental inclusion of a field value in an error message is possible, which is why access is limited and retention is short. | United States | Not used for PHI |
Stripe PCI DSS Level 1 certified. Not used for PHI. | Billing, subscriptions, payment processing, custom-quote management | Organization name, billing contact email, subscription state, invoice history. Card numbers held by Stripe — never reach our servers. | United States | Not used for PHI |
AWS Amplify AWS BAA required if customer operates as a HIPAA Covered Entity; we have AWS BAA terms in place. | Application hosting and CDN | All customer data, in transit through our application servers | United States (Amplify US regions) | Available |
Infisical | Secrets management for our infrastructure | Our own API keys and configuration. No Customer Data. | United States | N/A |
Change notification
We will notify customers in writing at least 30 days before adding a new subprocessor with access to report content. Customers may reasonably object on data-protection grounds; see Section 4 of our Data Processing Addendum for details.
The most recent revision date is shown above. This page is the authoritative record of subprocessor changes.
Subscribe to updates
To be notified of subprocessor changes, email contact@skdaddle.com from the contact you want notifications delivered to.