Trust
Subprocessors
Last updated: 8 August 2026
Providers that may process data to run PhishGuard for you. This list is referenced by our pilot DPA. Material changes are notified to active customers before go-live (default 10 business days).
| Provider | Purpose | Data involved | Region posture |
|---|---|---|---|
| Vercel Inc. | Application hosting, edge delivery, serverless functions, TLS | Application traffic, request logs, deploy configuration | Configurable; production targets Canada-friendly routing where available |
| Neon, Inc. | Managed PostgreSQL (primary application database) | Tenant data, campaign metadata, admin accounts, marketing lead submissions | Prefer AWS ca-central-1 (Canada) for production |
| Cloudflare, Inc. (Turnstile) | Bot protection on public contact / pilot request forms | Browser/device signals and challenge tokens (not used for marketing) | Global Cloudflare network (challenge verification) |
| Transactional email provider (e.g. Resend) | Product and notification email when enabled | Admin notification addresses, limited message metadata | Per provider; disclosed in customer onboarding if used |
| Error / performance monitoring (when enabled) | Application reliability and debugging | Technical diagnostics; PII minimized in payloads | Per provider configuration |
| Google Workspace (customer’s tenant) | Directory sync and simulation delivery under customer authorization | Directory attributes and mail delivery as authorized by customer | Customer’s Google Workspace regions |
How we notify you of changes
Under our pilot DPA, if we add or materially change a subprocessor that will process your organization’s personal information, we:
- Complete an internal privacy and security review of the provider.
- Email your pilot / privacy contact before the change goes live (target: at least 10 business days).
- Give you a window to object on reasonable privacy or security grounds.
- Update this page so the public list stays current.
Non-material changes (for example a vendor rebrand with the same entity, region, and purpose) may be updated here without a separate email. Emergency security changes may proceed faster, with notice as soon as practicable.
Internally, each provider is mapped to ISO/IEC 27001:2022 supplier and cloud controls — see ISO 27001 readiness (not a certificate).
Changelog
8 August 2026
Named production stack: Vercel (host), Neon (Postgres, Canada preferred), Cloudflare Turnstile (form bot protection). Category-level list retired for these core services.
8 August 2026
Published initial subprocessor list and notification process for customer due diligence.
Customer Google Workspace is not our subprocessor in the classic sense — it is your environment that you authorize us to access for the service.
Questions: privacy@phishguard.ca · Privacy Policy · Security