Subprocessors
The complete list of third parties that can touch data we hold on your behalf — what each one does, what it can see, and what it publishes about its own security.
Last updated July 25, 2026
How to read this
A subprocessor is a company we rely on that may process data you entrust to us. We keep the list deliberately short — every additional vendor is another place your data can go — and we list services even when the feature that uses them is switched off for your workspace, because a dormant vendor is still a vendor.
The “posture” line restates what each vendor publishes on its own trust page, linked so you can check it rather than take our word for it. We don’t audit our vendors ourselves and we’re not warranting their certifications — we’re telling you who they are so your own review can proceed.
Subprocessors
These may process client or personal data.
Vercel
trust page ↗- Why we use it
- Hosts and serves the marketing site and the client portal, and provides our cookieless site analytics.
- What it can touch
- Everything you send us passes through Vercel in transit. Request metadata (IP address, timestamp) is processed transiently to serve and protect the request. The analytics product stores no cookie, no IP, and no identifier.
- Where
- United States
- Its posture
- SOC 2 Type II. Publishes a DPA and a subprocessor list.
Supabase
trust page ↗- Why we use it
- Our managed Postgres database and authentication service. This is the system of record for the client portal.
- What it can touch
- All client workspace data: accounts and roles, projects and updates, dashboard content, uploaded assets, messages (stored encrypted by us before they reach the database), and sales inquiries submitted through our website.
- Where
- United States
- Its posture
- SOC 2 Type II; encryption at rest; automated daily backups on our plan. Publishes a DPA and a subprocessor list.
Cloudflare
trust page ↗- Why we use it
- Turnstile bot protection on our public forms. Nothing else — we do not proxy our sites through Cloudflare.
- What it can touch
- A challenge token and the request metadata needed to decide whether a form submission is automated. Turnstile is designed not to track users across sites and sets no advertising cookie.
- Where
- Global edge network
- Its posture
- SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS.
Resend
trust page ↗- Why we use it
- Delivers our transactional email — portal invitations, password resets, and the notification copy of a form submission that reaches our inbox.
- What it can touch
- Recipient email address, sender, subject, and message body of transactional mail. No marketing profiles are built.
- Where
- United States
- Its posture
- Publishes its security posture and a GDPR data-processing agreement. Our sending key is held in our own relay, never in the website.
Google Workspace (Google LLC)
trust page ↗- Why we use it
- Runs our company mailboxes — including the inbox a copy of your inquiry lands in — and the Drive workspace where client deliverables are prepared and shared.
- What it can touch
- Email correspondence with you, and the documents and deliverables produced for your engagement.
- Where
- United States
- Its posture
- ISO/IEC 27001, 27017, 27018, 27701; SOC 1/2/3. Publishes a Cloud Data Processing Addendum.
Stripe
trust page ↗- Why we use it
- Processes platform fees and subscription payments when in-platform billing is enabled for a workspace.
- What it can touch
- Billing contact and payment details. Card numbers are entered on Stripe-hosted checkout pages and never touch our servers, our database, or our logs — we store only Stripe's identifiers and the fact that a charge cleared.
- Where
- United States
- Its posture
- PCI DSS Level 1 service provider; SOC 1 and SOC 2.
Google Maps Platform (Google LLC)
trust page ↗- Why we use it
- Renders the map in the property-tracking dashboard widget. Loaded only in workspaces where that widget is enabled — most workspaces never contact it.
- What it can touch
- When the widget renders, your browser sends the addresses or coordinates being mapped to Google in order to draw the map.
- Where
- United States
- Its posture
- Covered by Google Cloud's ISO/IEC 27001 and SOC 1/2/3 programs and its Data Processing Addendum.
Other vendors in our stack
Listed for completeness. These support how we build and run the platform but do not process client data.
Tailscale
trust page ↗- Why we use it
- Private network between our own machines for internal operations tooling.
- What it can touch
- No client data. It carries our internal administrative traffic and is not in the path of the platform your workspace runs on.
- Where
- United States
- Its posture
- Publishes its security documentation and a DPA.
Apple
trust page ↗- Why we use it
- Distribution of our iOS application.
- What it can touch
- App distribution metadata only. No client workspace data is transferred to Apple by us.
- Where
- United States
- Its posture
- Publishes its privacy and security documentation.
GitHub (Microsoft)
trust page ↗- Why we use it
- Source-code hosting and our CI security checks.
- What it can touch
- Our source code and build logs. No client data, no personal data of your users, and no production credentials — secrets are scanned for and blocked on every push.
- Where
- United States
- Its posture
- SOC 1 Type II, SOC 2 Type II, ISO/IEC 27001.
GoDaddy
trust page ↗- Why we use it
- Domain registration and authoritative DNS for deadpanlabs.com.
- What it can touch
- Domain records only. No client data.
- Where
- United States
- Its posture
- Registrar; publishes its own security and privacy documentation.
Automated analysis and generation
Some of what we deliver — content drafting, competitive analysis, visibility research — involves automated generation. Today, no client data is sent to any third-party model provider as part of running this platform: none of the applications your workspace touches call one. We do use such services for our own first-party content operations, on data we own — we mention it because it is true, not because it touches you.
If an engagement of yours would involve automated processing of your data, the specific provider, what it receives, and its retention and training terms are named in your data-processing agreement and agreed in writing before any of your data reaches it. We would rather tell you that this category exists and is disclosed at contract than let you find the gap yourself.
What this list deliberately excludes
Purely financial and administrative relationships that process no client or personal data — our bank, our accountant, our registered agent — are not listed, because naming them tells you nothing about where your data goes. If you want the full corporate vendor register for a diligence process, ask and we will share it under NDA.
Our own infrastructure
Outbound email from our website is relayed through integration infrastructure we build and operate ourselves rather than a third-party automation service, which is why our email provider key never sits in the website. It is our system, not a subprocessor — but it is in the path, so we name it here rather than let you discover it.
International transfers
Deadpan Labs LLC is a Florida company and our infrastructure is operated in the United States. Where a client is subject to the GDPR or UK GDPR, transfers rely on the Standard Contractual Clauses or equivalent mechanisms offered in each vendor’s data-processing agreement, which we execute with them.
Changes to this list
When we add or remove a subprocessor we update this page and move the date at the top. Clients under contract are notified in accordance with their agreement, and any objection process agreed in a DPA applies. To be told directly when this list changes, email contact@deadpanlabs.com and ask to be added to the notification list.
Need a DPA, or the full picture?
Our security page covers how the platform itself is built. For a data-processing agreement or a completed questionnaire, just ask.
Get in touch →