Security & trust
Frozen archiveSubprocessor and Third-Party Provider Notice
A release-controlled inventory that distinguishes configured subprocessors from independent and Customer-directed providers.
1. Register governance
This Register identifies technical providers currently configured or conditionally available for the stated functions. Provider classification follows the actual contract, account configuration, and data flow. Before enabling an optional production flow, Nightvault reviews the applicable provider identity, role, terms, processing locations, retention, deletion, incident, downstream-provider, support-access, and configuration information then reasonably available. This public inventory does not represent that every provider offers the same terms, region, retention, or transfer mechanism.
2. Nightvault-selected subprocessors
| Provider / product | Purpose | Role |
|---|---|---|
| Vercel | Application hosting, routing, functions, deployment, and related request logs | Configured infrastructure subprocessor; processing locations follow the applicable account, DPA, and provider subprocessor notice |
| Supabase | Database, authentication, storage, and realtime functions | Configured infrastructure subprocessor; primary region and downstream locations follow the selected project and provider terms |
| OpenAI API | Selected AI inference, OCR, classification, generation, summaries, and recommendations | Configured AI subprocessor for enabled functions; processing and retention follow the applicable business terms, DPA, and account controls |
| Unified | Brokered third-party integrations, connection mapping, and provider passthrough | Configured integration subprocessor for Customer-enabled brokered connections; destination providers remain Customer-directed |
| Resend | Transactional application email and delivery-event processing | Conditional email subprocessor; production system-mail remains disabled until the authenticated mail canary and release controls pass |
3. Independent or Customer-directed providers
| Provider / category | Typical role |
|---|---|
| Stripe | Independent controller for some payment, fraud, and legal-compliance functions and processor or service provider for specified billing functions. |
| Google and Microsoft identity | Independent identity providers used for first-party application sign-in under their respective terms. |
| Google Gmail and Microsoft Outlook mailbox integrations | Direct, Customer-directed mailbox providers under the Customer/provider relationship and selected OAuth scopes; separate from application login. |
| Google Workspace corporate mail | Nightvault business mailbox infrastructure for monitored contact, billing, security, privacy, and support correspondence. |
| AfterShip and connected commerce or logistics providers | Customer-directed providers selected by Customer for the instructed exchange. |
4. Excluded providers and changes
LanguageTool and Sapling are not approved production subprocessors and must not receive production Customer Personal Data. Any future activation requires a new reviewed Register version covering exact data categories, locations, retention, training or use, deletion, incident obligations, and production configuration.
Nightvault provides reasonable advance notice of a new material Subprocessor where practicable through the Legal Center or another durable channel. An urgent replacement required for security, law, or provider failure may occur sooner, with notice as soon as reasonably practicable. A Customer may object on reasonable documented data-protection grounds under the DPA.