§08 · Sub-processors

Our sub-processors & data residency.

This page lists every third-party data processor Plumbline Evidence uses, the region each one stores data in, and a short note on what data flows to them. We publish this list publicly so your InfoSec and procurement teams can review it without a vendor-questionnaire exchange. Any change to this list is announced in writing on a published notice window before it takes effect.

Hosting & infrastructure

The managed compute and database layer that stores all customer data, evaluation records, and the signed audit ledger.

ProcessorServiceRegionData handled
RenderManaged compute & PostgresUS (Oregon, AWS us-west-2)All customer data, evaluation records, the signed ledger

Authentication

Session management and user-account storage. better-auth is self-hosted in the same Postgres instance as customer data — there is no external auth processor and no data leaves your region.

ProcessorServiceRegionData handled
better-auth (self-hosted)Session management & user accountsSame region as customer data (no external processor)Auth tokens, user records — stored in the customer’s own Postgres

Email

Transactional email delivery — account confirmations, alert notifications, and export-ready notifications. Email is routed through the Polsia-managed email proxy; the body is not stored after delivery.

ProcessorServiceRegionData handled
Postmark (via Polsia email proxy)Transactional emailUS (Polsia-managed; does not store body after delivery)Email address, subject, notification body

Payments

Subscription billing and hosted checkout. Plumbline Evidencenever sees or stores raw card data — that stays entirely within Stripe's PCI DSS Level 1 environment. Billing goes through the Polsia Stripe Connect account.

ProcessorServiceRegionData handled
Stripe (via Polsia Stripe Connect)Subscription billing & checkoutUS (Stripe’s servers)Payment card data, billing address — Stripe is PCI DSS Level 1; Plumbline Evidence never touches raw card data

Observability

Application logs and service metrics used for incident detection and performance monitoring. Raw evaluation-record payloads are never written to the log stream — only structured operational events.

ProcessorServiceRegionData handled
Render (built-in)Application logs & metricsSame region as the compute tierStructured app logs; no raw evaluation-record payloads

Change notice & last updated

This list was last updated August 2026. Before adding, replacing, or removing a sub-processor, we provide written notice on a published window so buyers have time to object before any new vendor accesses their data. The notice window and the full sub-processor disclosure obligations are incorporated into the Data Processing Addendum (DPA) at signature.

To request the full DPA, or if you have questions about a specific processor, contact us.