We’re upgrading our email infrastructure — for immediate response, email andrewjgaber@gmail.com meanwhile.
Skip to main content
Part of Digital Empire

EntryProof Sub-processor Disclosure

This page lists every third-party sub-processor EntryProof engages to deliver the service, required for Enterprise customers' GDPR Article 28(3)(d) due diligence and for anyone evaluating EntryProof under an existing Data Processing Agreement (DPA).

1. Current sub-processors

Every processor below is US-based and US-region for data residency as of August 13, 2026.

Sub-processorCountryPurpose / data processedData residencyDPA
Supabase, Inc.United StatesPrimary database — stores readiness-checker submissions, store URLs, HTS codes, hashed IP addresses (rate-limiting only), and account records.US region (AWS us-east-1)DPA
Stripe, Inc.United StatesBilling — processes and stores payment card details and subscription status once paid tiers ship. We never see or store raw card numbers.US region (Stripe global infrastructure, PCI DSS Level 1)DPA
Resend, Inc.United StatesTransactional email — delivers readiness reports and account notifications. No marketing/cold email sent through this processor.US regionDPA
Vercel Inc.United StatesHosting + edge network — serves the application, runs serverless/edge functions, and terminates HTTPS. Vercel edge logs contain IP addresses and request metadata for a limited retention window.US region (primary), global edge network for static/cached assetsDPA
PostHog Inc.United StatesProduct analytics, where enabled. Only loads after cookie consent is granted — see /cpsc-efile/cookies.US region (us.i.posthog.com)DPA
Functional Software, Inc. (Sentry)United StatesClient + server error tracking, so we can find and fix bugs. Client-side Sentry only loads after cookie consent is granted — see /cpsc-efile/cookies.US regionDPA
Apollo.io (Apollo Technologies, Inc.)United StatesBusiness-contact prospecting for outbound cold email to potential customers, run via Instantly. Apollo does not process any data submitted by users of the product itself.US regionDPA
OpenAI / Anthropic (LLM providers)United StatesNot used at runtime. We do NOT use OpenAI, Anthropic, or any other large language model provider to process customer data at runtime. No store URL, HTS code, scan finding, email address, or other customer-submitted data is sent to an LLM API as part of any live product feature. (Internal engineering tooling — e.g. Claude Code sessions used by our team to write and audit application code — is a separate, non-customer-data context and out of scope for this disclosure.)

2. Country and data residency

"Country" is the sub-processor's primary legal jurisdiction. "Data residency" is where the specific data EntryProof sends is physically stored. All seven vendors above store and process EntryProof data exclusively in US-region infrastructure, no transfer to a third country under this disclosure.

3. Notification of new sub-processors

We will notify Enterprise customers 30 days in advance of adding a new sub-processor, giving you the opportunity to object per your Data Processing Agreement. The "Last updated" date above changes whenever the vendor list changes.

4. Subscribe to sub-processor changes

Enterprise customers can request proactive email notification by emailing hello@citationsafe.com with subject "Subscribe to sub-processor updates" from your account email. We confirm by reply within 2 business days.

5. Objecting to a new sub-processor

Enterprise customers with a signed DPA who object to a newly announced sub-processor should contact hello@citationsafe.com within the 30-day notice window for a mitigation plan or termination-for-cause per the DPA.

8. How we vet a sub-processor before adding one

We don't add a new vendor lightly. Before any sub-processor is added to EntryProof's stack, we check: does it have a published DPA (every vendor above does); does it publish SOC 2 Type II or equivalent (Supabase, Stripe, Vercel, Sentry, and PostHog all do as of August 13, 2026); and does it actually need the data we'd send it, or can the same thing be done with a vendor we already disclose. That last question is why EntryProof runs on seven sub-processors, not seventeen.

9. How data actually flows

In plain terms: your browser talks to Vercel's edge network, which runs our application code. That code reads and writes to Supabase (the database) and, where relevant, calls Stripe (billing), Resend (transactional email), PostHog (analytics, only post-consent), or Sentry (error reports, only post-consent). None of those calls fan out further. Apollo sits entirely outside this loop; it never receives a byte of data any EntryProof user submits through the product itself.

12. Frequently asked

Do you use a payment processor other than Stripe? No, Stripe is the only payment processor in the EntryProof stack. Can I request my sub-processor list in a different format for procurement? Yes, email hello@citationsafe.com and we will send a signed PDF version of this table on request, useful for vendor-risk-assessment questionnaires that require a static document rather than a live page.

13. What we don't do with your data

None of the sub-processors above are permitted to use EntryProof customer data for their own marketing, to train a model on it, or to resell it to a third party, every DPA linked in Section 1 contractually forbids exactly that. If a vendor's own terms ever changed in a way that conflicted with this, we would remove them from the stack rather than accept the change, and Enterprise customers would be notified under Section 3 regardless of the 30-day window.

13. Related pages

14. Contact

Questions about this disclosure or a DPA request: hello@citationsafe.com (fallback: hello@citationsafe.com).