Compliance Center
Vendors

Vendor Assessments

Completed vendor risk assessments for the subprocessors EcoService OS relies on, with residual risk scores and review dates.

Vendor / Sub-processor Assessments — Completed

Last full sweep: July 14, 2026 · Reviewer: Security Lead · Approver: CEO

All vendors below have a signed DPA (or equivalent ToS provision) and were assessed with the Vendor Risk Assessment Template. Full completed forms are archived in the Company 1Password vault "Compliance / Vendors".

VendorPurposeData classResidencyCertificationsL × IDecisionNext review
SupabasePostgres, Auth, Storage, RealtimeConfidential (PII, job data, invoices)AWS us-east-1SOC 2 Type II, HIPAA, ISO 270012 × 5 = 10✅ Approved2027-07-14
CloudflareCDN, WAF, DNS, Workers hostingConfidential (in-transit)Global anycastSOC 2 Type II, ISO 27001, PCI DSS2 × 4 = 8✅ Approved2027-07-14
StripePayment processing, Connect payoutsRestricted (card, bank) — tokenized onlyUS / EUPCI DSS L1, SOC 1/2, ISO 270012 × 5 = 10✅ Approved2027-07-14
Lovable AI GatewayLLM inference (OpenAI, Gemini)Confidential (prompts, image descriptions)USVendor-managed; upstream: OpenAI SOC 2, Google ISO 270013 × 3 = 9✅ Approved2027-07-14
xAI (Grok)Optional co-pilot inferenceConfidential (prompts only, no PII by design)USEmerging; contractually bound not to train on our data3 × 3 = 9✅ Approved with control (opt-in toggle, PII redaction)2027-01-14
DFINITY / Internet Computeroracle-ai-v2 canister inferenceInternal (prompts, no PII)IC subnetPublic chain, deterministic canisters3 × 2 = 6✅ Approved2027-07-14
PostHogProduct analytics (opt-in)Internal (anonymized events)EU (Frankfurt)SOC 2 Type II, GDPR-ready2 × 2 = 4✅ Approved2027-07-14
SentryError monitoringConfidential (stack traces may contain identifiers)USSOC 2 Type II, ISO 27001, GDPR2 × 3 = 6✅ Approved with control (PII scrubbing enabled)2027-07-14
ResendTransactional email deliveryConfidential (email addresses, content)US / EUSOC 2 Type II, GDPR2 × 3 = 6✅ Approved2027-07-14
Microsoft Graph (Outlook/Teams)Calendar & mail integration (per-user OAuth)Confidential (per end-user, scoped tokens)Per user tenantSOC 2, ISO 27001, HIPAA2 × 3 = 6✅ Approved2027-07-14
Google (OAuth + Gmail)Sign-in and calendar (per-user OAuth)Confidential (per end-user, scoped tokens)Per userSOC 2, ISO 270012 × 3 = 6✅ Approved2027-07-14
GitHubSource code, CIInternal (source), Restricted (secrets in Actions)USSOC 1/2, ISO 270012 × 4 = 8✅ Approved2027-07-14

Compensating controls in effect

  • xAI (Grok): disabled by default; user must toggle on. Server strips known PII patterns (email, phone, address) before send.
  • Sentry: beforeSend scrubs Authorization, cookie, and known PII fields.

Change log

  • 2026-07-14 — Full sweep of 12 vendors; all approved. Next annual review: 2027-07-14.