# Briard-AI subprocessor register

Version 1.0 — reviewed August 11, 2026

| Provider | Service purpose | Data categories that may be processed | Location/residency fact | Current status |
| --- | --- | --- | --- | --- |
| Vercel | Application and documentation hosting, edge delivery, runtime logging | HTTP request metadata, application responses, operational logs | Provider-operated infrastructure; Briard-AI does not currently offer a contractual residency commitment | Active |
| Supabase | Authentication, PostgreSQL database, private object storage | Account identifiers, tenant metadata, evidence objects deliberately uploaded by the customer | Project-region and provider infrastructure; exact contractual residency is not currently offered | Active |
| Stripe | Subscription checkout, invoices, billing portal, webhook events | Billing contact, organization, subscription and transaction identifiers; Stripe receives payment-card data directly | Provider-operated global payment infrastructure | Active for billing |
| Resend | Transactional and operational email | Recipient email address, delivery metadata, and the requested transactional message | Provider-operated email infrastructure; no contractual residency commitment offered by Briard-AI | Active when configured |
| Google | Consent-gated analytics and advertising measurement | Pseudonymous browser/device and campaign attribution data when the visitor grants analytics permission | Provider-operated global analytics infrastructure | Optional and consent-gated |
| RFC 3161 timestamp provider | External timestamp receipt for a ledger head | One-way SHA-256 ledger-head digest and timestamp request metadata | Provider endpoint infrastructure; no customer document or ledger payload is sent | Active when configured |

## Change notice

The current public register is versioned and dated. Briard-AI will update this page before or when a material provider change is placed into production when practicable. A contractual advance-notice period is not currently offered and requires approved contract terms.

## Data boundary

Customers must not submit CUI, PHI, credentials, customer production records, or raw prompt/output content. Service-provider processing does not expand that boundary.
