Subprocessors
Last updated August 17, 2026
Epitaph LLC engages the third-party service providers below to help us operate Artifact. We engage each of them under their standard business terms, which include data-protection commitments requiring them to protect personal data and to process it only as needed to provide their service to us.
Current subprocessors
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, and file/photo storage | Account data, inspection records, uploaded photos & attachments | United States |
| Vercel, Inc. | Application hosting and content delivery | Request metadata, IP addresses (transient) | United States |
| Cloudflare, Inc. | Encrypted off-site backup storage for disaster recovery (Cloudflare R2) | Nightly backups of account data, inspection records, and uploaded photos & attachments | United States |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact, payment-method data (held by Stripe), plan & seat counts | United States |
| Resend (Plus Five Five, Inc.) | Transactional email delivery (invites, password reset, notifications) | Recipient email address, message content | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | Error events, technical/request metadata | United States |
| Anthropic, PBC | AI-assisted template generation (only when a manager/admin uploads a document or pastes text to draft an inspection template) | The document or checklist text you submit for template generation | United States |
Customer-directed integrations
Separate from the subprocessors above, your organization can choose to send data to destinations it controls: outbound webhooks to endpoints you configure (for example, Jira, Zapier, Microsoft Teams, or any HTTP endpoint), a Procore account you connect, or API keys you issue to pull your own data. Those destinations act on your instructions rather than ours and are governed by your agreements with those providers, so they are not Artifact subprocessors, and we are not responsible for how they handle data once it reaches them.
To be straightforward about the division of responsibility: your organization decides whether to enable an integration and where the data goes, while we design what each integration sends and when it sends it. The Procore integration, for example, pushes a complete inspection report PDF on every completed inspection, and webhook deliveries include the inspector’s name and email address. Those payload contents are our design decision, not something you configure, so we describe them precisely in the Privacy Policy before you turn an integration on. If we materially expand what an enabled integration sends, we will treat that as a material change and give notice under our Terms.
Changes to this list
We may add or replace subprocessors as the Service evolves. When we do, we will update this page. If your agreement with us entitles you to advance notice of new subprocessors, we will provide it as described in that agreement so you have an opportunity to object.
Questions
To put a Data Processing Addendum in place, or to ask about a specific subprocessor, contact us at privacy@epitaph.llc.