Subprocessors

Every third-party service that processes customer data on our behalf. Publicly mirrored to /security/subprocessors on the marketing site.

No-BAA perimeter. Because Blue Trust does not process PHI, no subprocessor needs a Business Associate Agreement. Customers are informed of this posture at signup and in our privacy notice.
SubprocessorPurposeCountryTouches PHIBAA
ClerkAuthentication + user managementUSNoN/A (no PHI)
NeonPostgres databaseUSNoN/A (no PHI stored)
Fly.ioScanner worker runtimeUSNoN/A (no PHI)
Cloudflare R2Report storageUSNoN/A (no PHI)
CloudflareCDN + DNS + WAFUSNoN/A (no PHI)
VercelMarketing + app hostingUSNoN/A (no PHI)
PostmarkTransactional email (alerts)USNoN/A — alerts contain no PHI
TwilioSMS alerts (Pro)USNoN/A — SMS contains no PHI
StripePaymentsUSNoN/A (no PHI)
AnthropicLLM classification of public review textUSNoN/A — input is public review content only
SentryError trackingUSNoLogs scrubbed; no PHI
PostHogProduct analyticsUSNoPII-only event tagging