Trust Center

Subprocessors

Current subprocessors, and the role each plays. This register is limited to services with evidence in the codebase:

  • Supabase — authentication and database for accounts and entitlements.
  • Vercel — website and API hosting, CDN, and scheduled jobs.
  • Stripe — payment processing and tax for web subscriptions.
  • RevenueCat — mobile subscription and entitlement management.
  • Sentry — crash and error monitoring; message, prompt, header, and cookie content is scrubbed.
  • Apple and Google — platform sign-in and app-store payment processing.
  • Cloudflare — optional cookieless web analytics.
  • Hugging Face — model catalog metadata and download links (no customer personal data).
  • OpenAI — generation of Fortaify's internal news article; it receives no customer content.
  • Email delivery — the operator-configured SMTP provider used for verification, reset, and newsletter email.

Microsoft Entra ID and other identity providers are configured in the customer's own tenant and are not Fortaify subprocessors. Cloud AI model providers you choose in the app are not subprocessors either: they receive content because you selected them as a destination, under your own agreement with them. Optional internet search in the Glyph client is provided by a third party; that integration is part of the client and should be verified for your deployment.

Automated change-notification subscriptions are in development. Material changes to this register are announced here and in the Privacy Policy; contact support@fortaify.com with questions.