Trust and vendor file Subprocessors
Subprocessors
Last reviewed: [DATE]
A subprocessor is a third party that Innorve uses to process customer data for Innorve Academy. This is the complete list.
Current subprocessors
| Subprocessor | Purpose | Location | Data processed | Independent assurance |
|---|---|---|---|---|
| Vercel Inc. (United States) | Hosts the Next.js web application; runs serverless functions | United States; functions in a US region [VERCEL REGION] | All traffic between users and the platform, in transit. Server request logs, including IP addresses. Stored data is encrypted at rest. | Vercel publishes compliance reports, including a SOC 2 report, through its trust center. [CONFIRM current reports at time of review] |
| Supabase Inc. (United States) | Managed PostgreSQL database, authentication (passwordless email sign-in) and daily backups | Amazon Web Services, United States region [SUPABASE REGION] | All stored platform data: accounts, memberships, enrollments, learning records, submissions, reviews, pilot and oversight records, evidence-binder links, audit events, website leads. Sign-in records and service logs, including IP addresses. Backups. Encrypted at rest. | Supabase publishes compliance reports, including a SOC 2 report, through its trust center. [CONFIRM current reports at time of review] |
| Email provider: planned Resend, Inc. (United States) [CONFIRM before first pilot] | Sends sign-in links, 6-digit sign-in codes and platform notifications | United States [CONFIRM sending region] | Recipient email address, message content (including one-time sign-in codes and links) and delivery records | [CONFIRM what the provider publishes] |
Provider infrastructure
Supabase runs its managed database on Amazon Web Services (AWS). AWS is Supabase's own subprocessor, not a direct Innorve subprocessor. Vercel also relies on cloud infrastructure providers for its platform. Each provider's own subprocessor list is available from that provider.
Not subprocessors
| Service | Why it is listed here |
|---|---|
| GitHub | Holds Innorve's source code in a private repository. GitHub holds no customer data. |
| Google Fonts | The public AI Obligations Navigator page loads fonts from Google Fonts, so a visitor's browser contacts Google when opening that page. Google receives the visitor's IP address and browser details from that request. No platform data is sent to Google. |
No AI provider is used. Nothing in the platform sends data to an AI model.
How to get the providers' reports
The subprocessors' SOC 2 reports are usually available from their trust centers, often under a non-disclosure agreement. You can request them directly from the provider. If you need help, ask Innorve at [SECURITY CONTACT EMAIL].
These reports cover the providers' infrastructure and operations. They do not cover Innorve's own controls. Innorve does not have its own SOC 2 report.
Changes to this list
- The draft DPA commits Innorve to give credit-union customers at least 30 days' written notice before adding or replacing a subprocessor. [CONFIRM]
- The notice will name the subprocessor, its service, its location and the data it will process.
- Customers may object on reasonable data protection grounds during the notice period.
- In an emergency (for example, a provider failure), Innorve may replace a subprocessor with shorter notice and will tell customers as soon as possible. [CONFIRM]
Change log
| Date | Change |
|---|---|
| [DATE] | First version of this list |