This page lists every third-party data processor Plumbline Evidence uses, the region each one stores data in, and a short note on what data flows to them. We publish this list publicly so your InfoSec and procurement teams can review it without a vendor-questionnaire exchange. Any change to this list is announced in writing on a published notice window before it takes effect.
The managed compute and database layer that stores all customer data, evaluation records, and the signed audit ledger.
| Processor | Service | Region | Data handled |
|---|---|---|---|
| Render | Managed compute & Postgres | US (Oregon, AWS us-west-2) | All customer data, evaluation records, the signed ledger |
Session management and user-account storage. better-auth is self-hosted in the same Postgres instance as customer data — there is no external auth processor and no data leaves your region.
| Processor | Service | Region | Data handled |
|---|---|---|---|
| better-auth (self-hosted) | Session management & user accounts | Same region as customer data (no external processor) | Auth tokens, user records — stored in the customer’s own Postgres |
Transactional email delivery — account confirmations, alert notifications, and export-ready notifications. Email is routed through the Polsia-managed email proxy; the body is not stored after delivery.
| Processor | Service | Region | Data handled |
|---|---|---|---|
| Postmark (via Polsia email proxy) | Transactional email | US (Polsia-managed; does not store body after delivery) | Email address, subject, notification body |
Subscription billing and hosted checkout. Plumbline Evidencenever sees or stores raw card data — that stays entirely within Stripe's PCI DSS Level 1 environment. Billing goes through the Polsia Stripe Connect account.
| Processor | Service | Region | Data handled |
|---|---|---|---|
| Stripe (via Polsia Stripe Connect) | Subscription billing & checkout | US (Stripe’s servers) | Payment card data, billing address — Stripe is PCI DSS Level 1; Plumbline Evidence never touches raw card data |
Application logs and service metrics used for incident detection and performance monitoring. Raw evaluation-record payloads are never written to the log stream — only structured operational events.
| Processor | Service | Region | Data handled |
|---|---|---|---|
| Render (built-in) | Application logs & metrics | Same region as the compute tier | Structured app logs; no raw evaluation-record payloads |
This list was last updated August 2026. Before adding, replacing, or removing a sub-processor, we provide written notice on a published window so buyers have time to object before any new vendor accesses their data. The notice window and the full sub-processor disclosure obligations are incorporated into the Data Processing Addendum (DPA) at signature.
To request the full DPA, or if you have questions about a specific processor, contact us.