Skip to main content
This page is updated whenever we add, remove, or change a subprocessor. Our BAA requires 30 days’ advance notice before any new subprocessor begins processing customer data.

Infrastructure subprocessors

These providers host the Denialbase platform itself. All customer data lives inside GCP regions we control, encrypted with customer-managed keys (CMEK).
SubprocessorRoleRegionPHI?BAA
Google Cloud Platform — Cloud SQLPrimary PostgreSQL databaseus-central1Yes (encrypted)In progress — Q3 2026
Google Cloud Platform — Cloud RunApplication runtimeus-central1Yes (in-memory during request)In progress — Q3 2026
Google Cloud Platform — Cloud StorageDocument storage (EOBs, appeal letters)us-central1 (CMEK)Yes (encrypted, virus-scanned)In progress — Q3 2026
Google Cloud Platform — MemorystoreRedis (caching, rate limits, 2FA tokens)us-central1No PHI — session IDs onlyIn progress — Q3 2026
Google Cloud Platform — Secret ManagerApplication secrets (JWT keys, AR encryption keys)us-central1NoIn progress — Q3 2026
Google Cloud Platform — Artifact RegistryContainer imagesus-central1NoIn progress — Q3 2026

Operational subprocessors

SubprocessorRolePHI exposureBAA
AnthropicLLM inference (Claude) for denial detection, strategy recommendation, and appeal draft generationPHI-scrubbed prompts only — no raw PHI sentIn progress — Q3 2026
SentryError and exception monitoringPII scrubbing rules drop known PHI fields before ingestionIn progress — Q3 2026
Amazon SESTransactional email (magic links, notifications)No PHI in email bodies — subject lines and content reference only metadataIn progress — Q3 2026
DocuSealCustomer-facing e-signature for appeal submissionsCustomer-executed; PHI rendered in browser via signed URLsNot required (customer-controlled)
GitHubSource code hosting, CI/CDNo customer data — code onlyNot required

Commercial / support subprocessors

SubprocessorRolePHI exposureNotes
StripePayment processing (planned, Q3 2026)No PHI — billing metadata onlyBAA not required; card data tokenized by Stripe
CloudflareDNS for denialbase.comNo

Data residency

All customer PHI processed by Denialbase is stored in the United States (us-central1). We do not replicate to secondary regions without explicit customer opt-in.

How we evaluate subprocessors

1

Risk assessment

We score each vendor on security posture (SOC 2 / ISO 27001 status, data handling, encryption), HIPAA willingness (BAA availability), data residency, and business continuity.
2

BAA execution

For any subprocessor that may touch PHI, we require a signed BAA before PHI flows to them.
3

Annual review

Each subprocessor is reviewed annually. Changes are notified to customers per the BAA’s notice clause.
4

Offboarding

When we remove a subprocessor, we confirm data deletion per their terms and document it in our vendor register.

Changelog

DateChange
2026-04Initial published subprocessor list