Legal
Subprocessors
Draft v0.1·Last updated 2026-07-31
1. Overview
Saintrac engages the subprocessors listed below to provide the infrastructure and services that operate the Verela platform. Each subprocessor is engaged under a data processing agreement that imposes obligations equivalent to those in the Data Processing Addendum. This list identifies the vendor, the processing purpose, and the general processing region. It does not include account identifiers, endpoints, or configuration details.2. Current subprocessors
| Vendor | Processing purpose | Processing region |
|---|---|---|
| WorkOS | Authentication, user management, and organization membership | United States |
| Stripe | Payment processing and subscription billing | United States |
| Resend | Transactional email delivery | United States |
| Amazon Web Services | S3-compatible encrypted object storage for evidence | United States (us-east-1) |
| Neon | PostgreSQL database hosting | United States |
| Aiven | Redis-compatible cache and job queue hosting | United States / European Union |
| Cloudflare | DNS, TLS termination, and web application firewall | United States |
3. Notification of changes
Saintrac will provide notice of material changes to this list, including the addition or replacement of a subprocessor, through the platform or by email to the organization owner. The customer may object to a new subprocessor by contacting Saintrac before the change takes effect.4. Data categories transferred
- Identity providerThe identity provider receives team member names, email addresses, and role assignments for authentication and organization management.
- Payment providerThe payment provider receives billing email, tax country, and payment method details. Full card numbers are handled by the provider and never reach Verela's servers.
- Email providerThe email delivery provider receives transactional email content and recipient email addresses for account and billing notifications.
- Storage providerThe storage provider receives encrypted evidence files and encrypted metadata. The provider does not have access to encryption keys managed by Verela.
- Database and cache providersThe database and cache providers receive operational data stored in PostgreSQL and Redis. Data is encrypted in transit.
- DNS and firewall providerThe DNS and firewall provider receives DNS queries and HTTP request metadata for routing and protection. It does not receive evidence or identity data.
5. Related documents
See the Data Processing Addendum for the controller and processor roles and obligations, the Privacy Policy for the data categories handled and retention behavior, and the Trust and security page for the security model.Related documents
Other legal documents
- Terms of ServiceDraft terms of service for the Verela synthetic identity verification platform. Pending qualified legal review.
- Privacy PolicyDraft privacy policy describing how Verela handles account, synthetic identity, and operational data. Pending qualified legal review.
- Data Processing AddendumDraft data processing addendum identifying controller and processor roles for Verela. Pending qualified legal review.
- Acceptable Use PolicyDraft acceptable use policy for the Verela synthetic identity verification platform. Pending qualified legal review.
- Trust and securityUnderstand the security model, evidence protection, and controlled-pilot boundaries that shape these documents.