Legal
Subprocessors
These are the third parties that process customer data on our behalf. The first table applies to every customer. The second applies only where a customer has enabled the feature that uses that provider.
Last reviewed: September 1, 2026
Core platform
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| Vercel, Inc. | Application hosting, deployments, edge delivery, and runtime logs | Application traffic and request metadata, operational logs | United States (deployment pinned to a US region) |
| Supabase, Inc. | Postgres database, authentication, file storage, and row-level security enforcement | Account, organization, visitor, screening, and audit records; files in private storage buckets | United States |
| Resend, Inc. | Transactional email: visitor and host notifications, invitations, contact and newsletter delivery | Recipient email address and message content necessary for delivery | United States |
| Redis Ltd. (Redis Cloud) | Cache and distributed rate limiting | Cache keys and short-lived cached payloads | United States |
Enabled by the customer
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| Stripe, Inc. | Payment processing and billing state for card-paid plans | Billing contact and subscription metadata; card data is handled by Stripe and never stored by SecurePoint | United States |
| Twilio, Inc. | SMS delivery for arrival alerts, reminders, and signing-session links | Phone number, delivery metadata, and the message content necessary for delivery | United States |
| OpenAI, L.L.C. / Microsoft Azure OpenAI / Groq, Inc. | Optional AI assistance, including text extraction from a scanned identity document at check-in and match explanations for reviewers | Only the content a customer-enabled workflow submits; identity-document images are processed under a zero-data-retention configuration | United States |
| Brother Industries and supported device vendors | Badge printing on customer-owned hardware | Badge render payload sent to the printer on the customer network | On the customer premises |
Data sources that are not subprocessors
Sanctions and restricted-party lists are pulled from the issuing agencies and from public aggregators. Customer data is not sent to those sources; the lists are downloaded and screened against locally.
Changes
Where required by contract or law, we give advance notice of material subprocessor changes. This page is updated when a provider is added, removed, or changes role, and the review date above moves with it.
Related
- Data Processing Agreement
- Privacy Policy, including the data location commitment
- Security Center, including a downloadable copy of this list