ClearPoint LogicStatus

Legal

Subprocessor matrix

Auditor-facing processor, retention, and deletion-path inventory for ClearPoint Logic customer data handling.

Last reviewed
2026-08-18
Records
19 processor records

Refresh policy

Quarterly security-led review, plus update within 24 hours of vendor adoption decision and subscriber notice at least 30 days before new subprocessors handle customer data.

Get notified of changes

Subscribe to be emailed whenever this subprocessor list changes. We send a one-time confirmation link (double opt-in) and never share your address; every notice includes a one-click unsubscribe. Prefer a feed reader? Subscribe to the RSS change feed.

ClearPoint Logic subprocessor matrix
ProcessorPurposeData accessedLocationSecurity statusDeletion pathRetention exceptionOwner
Supabase Postgres (tenant data store)SubprocessorPrimary tenant data store for Meridian, Studio, Nexus, audit-adjacent relational records, and platform records, hosted on Supabase-managed Postgres (RLS-isolated). Supabase is disclosed as the subprocessor that hosts and processes tenant data and backups; the deployment is not Cloud SQL.
  • tenant application data
  • policy data
  • customer-owned workflow records

confidential, restricted, regulated

Supabase-managed Postgres (US region)SOC 2: YesTier-1 database provider hosting CPL tenant data; SOC 2 Type 2, ISO 27001, and HIPAA add-on posture listed in vendor compliance summary. Protected by provider-managed AES-256 encryption at rest, TLS in transit, RLS, and application tenant guards. CPL does not hold per-tenant customer-managed keys (CMEK). Transfers governed by the Supabase DPA and Standard Contractual Clauses per CPL-CONTRACTS-CANONICAL §4.Hard delete via tenant-scoped row deletion at Day 60 plus signed tombstone audit event; backup purge by Day 90. (Cryptographic erasure via per-tenant CMEK destruction is a deferred future capability requiring a Cloud SQL re-platform per §Y.7, not the current mechanism.)None for customer-owned data.Operations Agent
CPL audit_events chainCPL-controlled storeImmutable signed audit evidence for material customer and platform actions.
  • audit evidence
  • redacted payload summaries
  • correlation identifiers

confidential, restricted, regulated

GCP us-central1SOC 2: CPL control evidenceCPL-controlled; immutable audit chain with payload redaction where allowed.Retain immutable event records; redact PII payload fields where data class permits.Audit evidence retained 7 years per CPL audit evidence policy and legal hold.Security Agent
Anthropic APISubprocessorClaude API model inference for Sonnet escalation paths and customer-explicit premium Anthropic routing.
  • customer prompts
  • model context
  • generated outputs
  • model-call metadata

confidential, restricted, regulated

Anthropic provider-hosted processing regionsSOC 2: YesTier-1 LLM provider; SOC 2 Type 2 and ISO 27001 listed in vendor compliance summary.CPL deletes local prompt, context, and output records through the customer-data lifecycle pipeline; provider-side handling follows Anthropic commercial terms and DPA.Provider contractual retention and abuse-monitoring windows may apply under the Anthropic DPA.Operations Agent
Google Cloud Vertex AISubprocessorDefault Gemini model inference, Gemini Flash-Lite routing, and Vertex text-embedding provider for model and semantic-search workloads.
  • customer prompts
  • model context
  • generated outputs
  • embedding inputs
  • model-call metadata

confidential, restricted, regulated

Google Cloud / Vertex AI configured regions; CPL primary workload region us-central1SOC 2: Inherits GCPTier-1 LLM and embedding provider; inherits GCP SOC 2 Type 2, ISO 27001, and BAA posture in vendor compliance summary.CPL deletes local prompt, context, output, and embedding records through the customer-data lifecycle pipeline; Google Cloud handling follows the Cloud DPA and configured service controls.Provider contractual retention and service-control windows may apply under the Google Cloud DPA.Operations Agent
OpenAI APISubprocessorOpenAI model inference for customer-explicit GPT-5.5 routing and code-strength surfaces governed by ADR-0021.
  • customer prompts
  • model context
  • generated outputs
  • model-call metadata
  • code-generation context when customer-approved

confidential, restricted, regulated

OpenAI provider-hosted processing regionsSOC 2: YesTier-1 LLM provider; SOC 2 Type 2 and ISO 27001 listed in vendor compliance summary.CPL deletes local prompt, context, and output records through the customer-data lifecycle pipeline; provider-side handling follows OpenAI business terms and DPA.Provider contractual retention and abuse-monitoring windows may apply under the OpenAI DPA.Operations Agent
StripeSubprocessorPayment processing, subscription billing, invoicing, and tax-required transaction records.
  • billing customer IDs
  • subscription metadata
  • payment method references
  • transaction records

confidential

United States / global Stripe processing regionsSOC 2: YesTier-1 billing provider; SOC 2 Type 2 and ISO 27001 listed in vendor compliance summary.Customer detach through Stripe API, subscription cancellation, and payment method deletion.Tax-required transaction records retained by Stripe and applicable jurisdictions, typically 7 years.Operations Agent
Supabase AuthSubprocessorCanonical identity provider for authentication, MFA, SAML SSO, and user identity lifecycle.
  • user identity records
  • authentication metadata
  • MFA state
  • SSO metadata

confidential, restricted

Supabase hosted regions for CPL projectsSOC 2: YesTier-1 identity and database provider; SOC 2 Type 2, ISO 27001, and HIPAA add-on posture listed in vendor compliance summary.User deletion through Supabase admin API; identity records anonymized.Auth audit log retention follows Supabase Pro tier retention: 90 days hot and 1 year cold.Operations Agent
SentrySubprocessorSanitized application error tracking and release health monitoring.
  • sanitized error context
  • tenant tags
  • release metadata
  • user context when needed for debugging

internal, confidential

Sentry hosted regionsSOC 2: YesTier-1 error tracking provider; SOC 2 Type 2 and ISO 27001 listed in vendor compliance summary.Issue and event purge by tenant tag; user-context deletion through Sentry data privacy API.Aggregated or anonymized error metrics retained per Sentry default retention.Operations Agent
DatadogSubprocessorSecurity monitoring layer for SIEM, security logs, selected synthetic checks, and cross-correlation.
  • security logs
  • audit-forwarded event summaries
  • tenant-tagged operational logs
  • aggregated metrics

internal, confidential, restricted

Datadog hosted regionsSOC 2: YesTier-1 security monitoring provider; SOC 2 Type 2, ISO 27001, and BAA posture listed in vendor compliance summary.Log retention window expiry, with customer-tenant-tagged logs deleted through Datadog GDPR endpoint where applicable.Aggregated metrics retained at lower fidelity for SOC 2 evidence.Security Agent
AttioSubprocessorCRM and deal-state tracking for sales, agreement status, and customer relationship operations.
  • company records
  • contact records
  • deal metadata
  • sales notes

internal, confidential

Attio hosted regionsSOC 2: In progressTier-3 CRM provider; SOC 2 listed as in progress in vendor compliance summary.Contact and deal records anonymized; names replaced with Deleted Customer label and email replaced with hash.Sales-cycle records retained under CPL contract retention policy for 7 years.Operations Agent
GitHub Issues / LinearSubprocessorEngineering issue tracking, customer support ticket coordination, and operational work tracking.
  • support ticket content
  • engineering issue metadata
  • customer-identifiable support text when present

internal, confidential

GitHub and Linear hosted regionsSOC 2: YesGitHub is Tier-1 source-code provider; Linear is Tier-2 issue tracking provider. Both list SOC 2 Type 2 in vendor compliance summary.Customer-identifiable text in support tickets redacted; ticket records retained.Ticket structure retained for SOC 2 evidence; customer-identifying content redacted.Operations Agent
SlackSubprocessorInternal communications and Slack Connect customer support communications.
  • customer support mentions
  • incident coordination messages
  • internal operational messages

internal, confidential

Slack hosted regionsSOC 2: YesTier-2 communications provider; SOC 2 Type 2, ISO 27001, and Enterprise BAA posture listed in vendor compliance summary.Customer-identifiable mentions in CPL-internal Slack scrubbed through Slack admin API where supported.Slack message retention follows CPL workspace policy.Operations Agent
DocuSign envelopesSubprocessorCustomer contract execution, NDA workflow, DPA/BAA signing, and agreement evidence.
  • contract metadata
  • signature records
  • agreement documents
  • requester identity

confidential, restricted

DocuSign hosted regionsSOC 2: YesTier-2 e-signature provider; SOC 2 Type 2, ISO 27001, and BAA posture listed in vendor compliance summary.Envelope metadata retained and envelope content access revoked.Signed contracts retained for legal contract retention, minimum 7 years.Operations Agent
Resend transactional emailSubprocessorTransactional email provider. Per the status-page activation runbook, Resend is the PRIMARY production sender for public status-site subscriber confirmation (double opt-in) and incident-notification email: the production status Lambda carries RESEND_API_KEY, so lib/status/email.ts selects Resend first and falls back to AWS SES only if that key is absent (see the aws-ses row). Resend also delivers product CSAT, welcome, and system email. For the separate subprocessor-change notification fan-out (a GitHub Actions job), Resend is used only if a key is mirrored into that environment; otherwise that job sends via SES.
  • email addresses
  • delivery metadata
  • transactional notification content

internal, confidential

Resend hosted regionsSOC 2: YesTier-3 transactional email provider; primary production sender for the public status-site subscriber path (RESEND_API_KEY present in the production status Lambda per the activation runbook), with AWS SES as the AWS-resident fallback. SOC 2 Type 2 listed in vendor compliance summary.Email send-history records retained 90 days and then auto-purged.None.Operations Agent
AWS SES (public status-site email)SubprocessorAWS SES is the AWS-resident sender for public status-site email. It sends the subprocessor-change notification fan-out run by scripts/notify-subprocessor-change.mjs (SES is the send path for that GitHub Actions job when no Resend key is mirrored into its environment), and it is the configured fallback / code-default for status-subscriber confirmation (double opt-in) and incident-notification email when RESEND_API_KEY is absent. Per the status-page activation runbook the production status Lambda currently carries RESEND_API_KEY, so the status-subscriber path uses Resend first and falls back to SES (see the resend row); SES production access is granted. Sender domain status.clearpointlogic.com with Easy DKIM and a TLS-REQUIRE configuration set.
  • subscriber email addresses (legal-notice opt-ins)
  • delivery metadata
  • notification content

confidential

AWS us-east-1 (SES) — public status site per ADR-0052SOC 2: YesTier-1 IaaS subprocessor (AWS); SES sends DKIM-signed over a TLS-required configuration set. Standard AWS DPA with Standard Contractual Clauses, SOC 2 Type 2, and ISO 27001 posture per vendor SLA matrix §2.1. Access is keyless GitHub OIDC; no long-lived AWS keys. Status-page AWS architecture (including SES) is canonized in cpl-ops ADR-0052 and CPL-STATUS-PAGE-CANONICAL.CPL retains no separate SES-side copy of subscriber email; the subscriber record lives in the AWS DynamoDB store (see aws-status-subscriber-store) and is deleted there on unsubscribe/tenant deletion. SES message logs follow AWS default retention.Provider-side SES delivery/log retention per the AWS DPA.Operations Agent
AWS DynamoDB / S3 (public status-site subscriber-notice store)CPL-controlled storeCPL-controlled AWS storage for the public status/marketing site (OpenNext, CPC-231). DynamoDB holds the status-page and subprocessor-change subscriber email opt-ins (status_subscribers, status_subprocessor_subscribers — labelled subscriber PII / legal-notice opt-ins, with point-in-time recovery and deletion protection enabled) plus operational status component/incident records; S3 holds site assets, the OpenNext cache, and access logs.
  • status subscriber email addresses (legal-notice opt-ins)
  • subscription state
  • status component/incident records
  • public site assets and OpenNext cache
  • access logs

confidential

AWS us-east-1 (public status/marketing site per CPC-231)SOC 2: CPL control evidence on AWS SOC 2 Type 2 substrateCPL-controlled AWS store on the Tier-1 AWS substrate. DynamoDB PITR + deletion-protection enabled; server-side encryption at rest; TLS in transit; keyless GitHub OIDC access with no long-lived keys. Underlying AWS posture: standard AWS DPA with Standard Contractual Clauses, SOC 2 Type 2, ISO 27001 per vendor SLA matrix §2.1.Subscriber records hard-deleted from DynamoDB by email key on unsubscribe (stateless expiring unsubscribe token) or tenant/opt-in deletion; S3 log objects age out via lifecycle policy. No customer-tenant data is stored here — subscriber email opt-ins are the only personal data.None for subscriber opt-ins beyond active subscription; S3 access logs follow lifecycle-policy retention.Operations Agent
Cloudflare (authoritative DNS for the public status site)SubprocessorAuthoritative DNS for the public status-site hostname (status.clearpointlogic.com CNAME to the AWS CloudFront distribution) and the SES DKIM/SPF DNS records. Records are NOT proxied (proxied=false), so Cloudflare does not sit in the request path for this surface and does not process subscriber personal data. Disclosed for completeness and to reconcile with the canonical vendor SLA matrix Tier-1 Cloudflare listing.
  • public DNS records for status.clearpointlogic.com
  • SES DKIM/SPF DNS records

internal

Cloudflare global anycast DNSSOC 2: YesTier-1 DNS/CDN/WAF provider per vendor SLA matrix §2.1; SOC 2 Type 2 and ISO 27001 posture. Role for this surface is authoritative DNS only (records not proxied); no subscriber personal data flows through Cloudflare for the status site.DNS records removed on hostname decommission; no personal data is stored by Cloudflare for this surface.None; no personal data processed for this surface.Operations Agent
Cloud Storage / GCS export bucketsCPL-controlled storeTime-limited customer export bundles and signed URL metadata for export delivery.
  • customer export bundles
  • signed URL metadata
  • export package checksums

confidential, restricted, regulated

GCP us-central1SOC 2: CPL control evidenceCPL-controlled GCP storage; lifecycle policy and access logging required.Hard delete of export bundles for deleted tenant; lifecycle policy cleans up signed-URL metadata.None.Operations Agent
Backup snapshotsCPL-controlled storeSupabase-managed Postgres automated backup snapshots and PITR for disaster recovery (not Cloud SQL).
  • tenant database backups
  • PITR metadata

confidential, restricted, regulated

Supabase-managed Postgres (US region)SOC 2: CPL control evidenceCPL-controlled backup substrate (Supabase-managed Postgres); provider-managed AES-256 encryption at rest; lifecycle and purge timing governed by retention canonical.Backup purge at Day 90; snapshots beyond Day 90 do not contain deleted tenant data.None.Operations Agent

Canonical anchors

  • CPL-DATA-CLASSIFICATION-RETENTION-CANONICAL.md §Y.8 and §Z
  • CPL-TRUST-CENTER-CANONICAL.md §3.3, §9.6, §11.4, §11.7, §13.2
  • CPL-VENDOR-SLA-MATRIX-CANONICAL.md §2.1, §9.2
  • CPL-THREAT-MODEL.md CPL-THREAT-DLC-003