Who is active today?
AWS, Cognito, and CloudWatch are active. Stripe, support, analytics, email, and Slack stay planned or conditional until launch approval.
Review vendorsSubprocessors
This list identifies vendors that operate, secure, bill, monitor, or support buildr-plannr. It documents purpose, region, data categories, status, and the update process used before material vendor changes reach customer data.
Vendor review first
AWS, Cognito, and CloudWatch are active. Stripe, support, analytics, email, and Slack stay planned or conditional until launch approval.
Review vendorsOnly the categories listed for each vendor. Raw card data stays with Stripe, and logs must redact tokens, secrets, and private context.
Review privacyEvery material vendor change needs identify, assess, approve, notify, and review steps before customer data is sent.
Review processUse legal support for subprocessor questions, DPA review, data requests, enterprise notice, or procurement evidence.
Legal supportcloud infrastructure
Hosts application runtime, networking, storage, logs, backups, queues, deployment roles, and infrastructure evidence.
Region
Primary application infrastructure in EU AWS regions; CloudFront and edge services may process requests globally.
Data categories
Customer content is kept in environment-specific AWS accounts and encrypted with AWS-managed encryption unless a customer contract requires a different posture.
authentication
Provides user pools, app clients, token issuance, password reset, signup verification, optional MFA, and hosted UI federation.
Region
Same AWS region as the deployed environment unless an enterprise identity design requires otherwise.
Data categories
Cognito identity data is separated from workspace records and governed through environment-specific callback and logout URLs.
billing
Processes checkout, subscriptions, invoices, payment method references, billing portal sessions, webhooks, and entitlement events.
Region
Stripe-managed regions with customer billing records governed by Stripe's data processing terms.
Data categories
Payment card data is handled by Stripe. buildr-plannr stores Stripe identifiers and entitlement snapshots, not raw card data.
monitoring
Collects application logs, deployment health signals, metrics, alarms, and operational diagnostics.
Region
Same AWS account and region as each deployed environment; edge metrics may be global.
Data categories
Logs must redact tokens, secrets, private context, and full customer email values before ingestion.
analytics
Measures acquisition, activation, conversion, workspace adoption, and launch readiness without collecting sensitive issue bodies.
Region
Provider region to be confirmed before enabling production analytics.
Data categories
Analytics must exclude secrets, tokens, raw prompts, private issue content, and full customer payloads.
Sends signup verification, password reset, support, billing, incident, and lifecycle messages.
Region
Provider region depends on the selected Cognito email sender and support-mail setup.
Data categories
Email templates must avoid sensitive issue content, agent prompts, secrets, and customer-owned source material.
collaboration
Receives operator-facing notifications for blocked agent work, approval gates, import/export recovery, billing limits, support escalations, incidents, and deployment smoke failures.
Region
Slack-managed regions governed by the workspace agreement and customer-approved notification channel.
Data categories
Slack payloads must link to secured buildr-plannr routes and must not include issue titles, export URLs, customer notes, email addresses, tokens, secrets, or webhook URLs.
support
Handles support intake, severity routing, account recovery, refund requests, enterprise security review, and incident communication.
Region
Provider region to be confirmed before production support launch.
Data categories
Support records should use redacted references and avoid raw credentials, Cognito tokens, Stripe secrets, and private customer source material.
Enterprise customers receive notice through their nominated security or legal contact before material subprocessor changes when required by contract.
Emergency replacements may proceed to protect service security or availability, with notice and evidence captured as soon as practical.
Open a Linear issue before adding, replacing, or removing a vendor that can access customer or workspace data.
Record the subprocessor purpose, region, data categories, transfer posture, retention, security terms, and whether a DPA or contract update is required.
Approve the subprocessor change before production traffic or customer data is sent to the vendor.
Publish the updated list and notify affected enterprise customers through the contractually agreed notice channel before material changes take effect.
Review the subprocessor list at least quarterly and during every enterprise security review.
The Markdown source lives at docs/security/subprocessors.md.