Skip to content

Trust

Subprocessors

Last updated: 8 August 2026

Providers that may process data to run PhishGuard for you. This list is referenced by our pilot DPA. Material changes are notified to active customers before go-live (default 10 business days).

ProviderPurposeData involvedRegion posture
Vercel Inc.Application hosting, edge delivery, serverless functions, TLSApplication traffic, request logs, deploy configurationConfigurable; production targets Canada-friendly routing where available
Neon, Inc.Managed PostgreSQL (primary application database)Tenant data, campaign metadata, admin accounts, marketing lead submissionsPrefer AWS ca-central-1 (Canada) for production
Cloudflare, Inc. (Turnstile)Bot protection on public contact / pilot request formsBrowser/device signals and challenge tokens (not used for marketing)Global Cloudflare network (challenge verification)
Transactional email provider (e.g. Resend)Product and notification email when enabledAdmin notification addresses, limited message metadataPer provider; disclosed in customer onboarding if used
Error / performance monitoring (when enabled)Application reliability and debuggingTechnical diagnostics; PII minimized in payloadsPer provider configuration
Google Workspace (customer’s tenant)Directory sync and simulation delivery under customer authorizationDirectory attributes and mail delivery as authorized by customerCustomer’s Google Workspace regions

How we notify you of changes

Under our pilot DPA, if we add or materially change a subprocessor that will process your organization’s personal information, we:

  1. Complete an internal privacy and security review of the provider.
  2. Email your pilot / privacy contact before the change goes live (target: at least 10 business days).
  3. Give you a window to object on reasonable privacy or security grounds.
  4. Update this page so the public list stays current.

Non-material changes (for example a vendor rebrand with the same entity, region, and purpose) may be updated here without a separate email. Emergency security changes may proceed faster, with notice as soon as practicable.

Internally, each provider is mapped to ISO/IEC 27001:2022 supplier and cloud controls — see ISO 27001 readiness (not a certificate).

Changelog

  • 8 August 2026

    Named production stack: Vercel (host), Neon (Postgres, Canada preferred), Cloudflare Turnstile (form bot protection). Category-level list retired for these core services.

  • 8 August 2026

    Published initial subprocessor list and notification process for customer due diligence.

Customer Google Workspace is not our subprocessor in the classic sense — it is your environment that you authorize us to access for the service.

Questions: privacy@phishguard.ca · Privacy Policy · Security