Facilitate engages a small set of third-party service providers to deliver the platform. We list each one here so you always know who else may process data you share with us, what they do, and where your data sits.
Last updated: 2026-08-01
Each subprocessor below has a current SOC 2 Type 2 attestation, an ISO 27001 certification, or both. We sign Data Processing Agreements with every subprocessor whose terms are no less protective than the ones we offer our own customers.
When we add or replace a subprocessor, customers under an active Data Processing Agreement receive at least 30 days’ notice and have the right to object. Updates to this list are tracked in git so the history is auditable.
Service: Application hosting, edge network, content delivery
Data processed: All platform traffic transits Vercel edge; serverless functions execute in Vercel's infrastructure.
Region: US East (iad1) primary; multi-region edge
Service: Postgres database, authentication, file storage, realtime
Data processed: All application data, user accounts, and persisted media (private storage buckets).
Region: AWS us-east-1
Service: Claude AI text generation (via Vercel AI Gateway)
Data processed: AI prompts containing aggregated platform context; AI completions returned.
Region: US
Service: GPT text generation (via Vercel AI Gateway)
Data processed: AI prompts and completions, same shape as Anthropic.
Region: US
Service: Gemini text generation (via Vercel AI Gateway) and Gemini image generation
Data processed: Text prompts and completions for Gemini; image-generation prompts for Gemini image generation.
Region: Google Cloud US
Service: Transactional email delivery
Data processed: Recipient email addresses, email subject lines, and email body content (including magic-link tokens, invite tokens, and user-facing PII).
Region: US
Service: Error tracking and performance monitoring
Data processed: Exception stack traces, request URLs, user IDs, structured tags, debug context. Sensitive parameters scrubbed at capture.
Region: US
Service: Redis-based rate limiting
Data processed: Rate-limit keys (user IDs / IP addresses). Transient TTLs from 60s to 24h. No PII in key payloads.
Region: US
Service: Source code hosting, continuous integration, dependency scanning, code scanning
Data processed: Source code, issue and PR metadata, build logs. No production customer data is committed to source control.
Region: Multi-region (Microsoft Azure)
Several of the subprocessors above themselves rely on well-known infrastructure providers. We surface these for transparency:
Customers with an active Data Processing Agreement receive notifications when this list changes. To request a copy of our DPA, ask about a specific subprocessor, or object to a proposed change, email support@getfacilitate.com.