← Legal hub

Trust · Subprocessors

Subprocessor list

Every third party we engage to process Customer Data on our behalf, plus what they do, what data they touch, where they're located, and whether they offer a BAA.

Effective Last updated June 9, 2026. This is a first-draft document and will be superseded by a lawyer-reviewed version before general availability. Questions: contact@skdaddle.com.

How to read this list

  • Purpose: what the subprocessor does for us in the service.
  • Data categories: what specific data the subprocessor sees.
  • Location: where the data is processed. We operate entirely in the United States today.
  • BAA available: whether the subprocessor offers a HIPAA Business Associate Agreement. Required for any subprocessor that touches Protected Health Information when our customer is a HIPAA Covered Entity.

Current subprocessors

SubprocessorPurposeData categoriesLocationBAA

Clerk

Not used for PHI. Clerk is the identity layer only.

Authentication, organization management, multi-factor authentication, invite emailsUser name, email address, authentication state, organization membership, session tokensUnited StatesNot used for PHI

Supabase

Primary database (PostgreSQL) and storageAll customer data including report content, resident records, audit logsUnited StatesAvailable

Anthropic (Claude API)

Anthropic does not train on Customer Data per their commercial agreement. Anthropic offers BAA terms; Skdaddle is responsible for executing them where required.

AI report review and Ace advisorReport narrative text and structured context fields submitted for AI review or advisor chatUnited StatesAvailable

Voyage AI

Embedding of approved narratives is enabled as of September 2026. Narratives are de-identified with the same pass used for AI review before they reach Voyage; the embeddings themselves live in ClearReport's database, not with Voyage. Voyage has not executed a BAA with us, and we do not send identified PHI to this vendor.

Vector embeddings used to retrieve the most relevant regulation text, your organization's reporting criteria, and your organization's own approved past reports during AI report reviewThree flows, all de-identified before transmission. (1) Organization- and facility-level reporting criteria text entered by administrators. (2) Approved incident narratives from your organization, with resident names, room numbers, dates of birth and other direct identifiers stripped before they are sent; the resulting embedding is stored in ClearReport's own database, scoped to your organization, and is never retrieved for any other organization. (3) When AI review runs, a de-identified search text derived from the draft is sent to compute a query embedding. Voyage does not retain the text or the embeddings.United StatesNot used for PHI

Resend

Notification emails intentionally carry deadline metadata only, not report narratives.

Transactional email delivery (compliance-deadline digest notifications to administrators)Administrator name and email address, facility name, form type and deadline dates for overdue or due-soon regulatory deadlines. No resident names and no report narrative content.United StatesNot used for PHI

Sentry

Error monitoring only. Configured to omit query strings; no report narratives, resident records, or PDFs are sent.

Application error monitoring (unhandled exceptions and swallowed server-side failures)Error messages, stack traces, request paths, and the authenticated user identifier associated with a failing request. Query strings are stripped before transmission. Not a destination for report content; incidental inclusion of a field value in an error message is possible, which is why access is limited and retention is short.United StatesNot used for PHI

Stripe

PCI DSS Level 1 certified. Not used for PHI.

Billing, subscriptions, payment processing, custom-quote managementOrganization name, billing contact email, subscription state, invoice history. Card numbers held by Stripe — never reach our servers.United StatesNot used for PHI

AWS Amplify

AWS BAA required if customer operates as a HIPAA Covered Entity; we have AWS BAA terms in place.

Application hosting and CDNAll customer data, in transit through our application serversUnited States (Amplify US regions)Available

Infisical

Secrets management for our infrastructureOur own API keys and configuration. No Customer Data.United StatesN/A

Change notification

We will notify customers in writing at least 30 days before adding a new subprocessor with access to report content. Customers may reasonably object on data-protection grounds; see Section 4 of our Data Processing Addendum for details.

The most recent revision date is shown above. This page is the authoritative record of subprocessor changes.

Subscribe to updates

To be notified of subprocessor changes, email contact@skdaddle.com from the contact you want notifications delivered to.