Subprocessors

Last updated August 17, 2026

Epitaph LLC engages the third-party service providers below to help us operate Artifact. We engage each of them under their standard business terms, which include data-protection commitments requiring them to protect personal data and to process it only as needed to provide their service to us.

Current subprocessors

ProviderPurposeData processedLocation
Supabase, Inc.Database, authentication, and file/photo storageAccount data, inspection records, uploaded photos & attachmentsUnited States
Vercel, Inc.Application hosting and content deliveryRequest metadata, IP addresses (transient)United States
Cloudflare, Inc.Encrypted off-site backup storage for disaster recovery (Cloudflare R2)Nightly backups of account data, inspection records, and uploaded photos & attachmentsUnited States
Stripe, Inc.Subscription billing and payment processingBilling contact, payment-method data (held by Stripe), plan & seat countsUnited States
Resend (Plus Five Five, Inc.)Transactional email delivery (invites, password reset, notifications)Recipient email address, message contentUnited States
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsError events, technical/request metadataUnited States
Anthropic, PBCAI-assisted template generation (only when a manager/admin uploads a document or pastes text to draft an inspection template)The document or checklist text you submit for template generationUnited States

Customer-directed integrations

Separate from the subprocessors above, your organization can choose to send data to destinations it controls: outbound webhooks to endpoints you configure (for example, Jira, Zapier, Microsoft Teams, or any HTTP endpoint), a Procore account you connect, or API keys you issue to pull your own data. Those destinations act on your instructions rather than ours and are governed by your agreements with those providers, so they are not Artifact subprocessors, and we are not responsible for how they handle data once it reaches them.

To be straightforward about the division of responsibility: your organization decides whether to enable an integration and where the data goes, while we design what each integration sends and when it sends it. The Procore integration, for example, pushes a complete inspection report PDF on every completed inspection, and webhook deliveries include the inspector’s name and email address. Those payload contents are our design decision, not something you configure, so we describe them precisely in the Privacy Policy before you turn an integration on. If we materially expand what an enabled integration sends, we will treat that as a material change and give notice under our Terms.

Changes to this list

We may add or replace subprocessors as the Service evolves. When we do, we will update this page. If your agreement with us entitles you to advance notice of new subprocessors, we will provide it as described in that agreement so you have an opportunity to object.

Questions

To put a Data Processing Addendum in place, or to ask about a specific subprocessor, contact us at privacy@epitaph.llc.