Legal

Subprocessors

Draft v0.1·Last updated 2026-07-31

1. Overview

Saintrac engages the subprocessors listed below to provide the infrastructure and services that operate the Verela platform. Each subprocessor is engaged under a data processing agreement that imposes obligations equivalent to those in the Data Processing Addendum. This list identifies the vendor, the processing purpose, and the general processing region. It does not include account identifiers, endpoints, or configuration details.

2. Current subprocessors

VendorProcessing purposeProcessing region
WorkOSAuthentication, user management, and organization membershipUnited States
StripePayment processing and subscription billingUnited States
ResendTransactional email deliveryUnited States
Amazon Web ServicesS3-compatible encrypted object storage for evidenceUnited States (us-east-1)
NeonPostgreSQL database hostingUnited States
AivenRedis-compatible cache and job queue hostingUnited States / European Union
CloudflareDNS, TLS termination, and web application firewallUnited States

3. Notification of changes

Saintrac will provide notice of material changes to this list, including the addition or replacement of a subprocessor, through the platform or by email to the organization owner. The customer may object to a new subprocessor by contacting Saintrac before the change takes effect.

4. Data categories transferred

  • Identity providerThe identity provider receives team member names, email addresses, and role assignments for authentication and organization management.
  • Payment providerThe payment provider receives billing email, tax country, and payment method details. Full card numbers are handled by the provider and never reach Verela's servers.
  • Email providerThe email delivery provider receives transactional email content and recipient email addresses for account and billing notifications.
  • Storage providerThe storage provider receives encrypted evidence files and encrypted metadata. The provider does not have access to encryption keys managed by Verela.
  • Database and cache providersThe database and cache providers receive operational data stored in PostgreSQL and Redis. Data is encrypted in transit.
  • DNS and firewall providerThe DNS and firewall provider receives DNS queries and HTTP request metadata for routing and protection. It does not receive evidence or identity data.

5. Related documents

See the Data Processing Addendum for the controller and processor roles and obligations, the Privacy Policy for the data categories handled and retention behavior, and the Trust and security page for the security model.