Notice & Objection Policy
1.1 Advance notice. Verdict will notify Customers at least 30 days before adding or replacing a subprocessor with access to Customer Personal Data, by email and by updating this page.
1.2 Customer objection. A Customer may object to a new subprocessor within the 30-day window for documented data-protection concerns. The parties will work in good faith to resolve. If unresolved, the Customer may terminate the affected portion of the Service for the unused remainder of its prepaid term and receive a prorated refund.
1.3 Emergency replacements. Where a subprocessor must be replaced urgently to address a security or availability incident, Verdict will notify Customers as soon as practicable and explain the reason. The objection right continues to apply.
Infrastructure
| Subprocessor | Service | Data categories | Region | Transfer basis | Status |
|---|---|---|---|---|---|
| Vercel, Inc. | Edge hosting, CDN, deploy infrastructure (web + API) | Customer identifiers, IPs (truncated), API metadata, telemetry | Global (primary US-east) | EU SCCs + DPA | Active |
| Cloudflare, Inc. | DDoS mitigation, R2 object storage (evidence payloads), DNS | Edge logs, Customer Content payloads | Global (data plane US-east, EU-west) | EU SCCs + DPA | Active |
| Supabase, Inc. | Postgres database + auth metadata | Account, billing metadata, evidence index records | us-east-1, eu-west-1 | EU SCCs + DPA | Active |
| Amazon Web Services, Inc. | S3 cold storage, networking, CloudHSM (see § 3) | Backup data, archived telemetry, signing keys (HSM only) | us-east-1 primary; eu-central-1 for EU residency | EU SCCs + DPA | Active |
Cryptographic Keys (HSM)
| Subprocessor | Service | Data categories | Region | Transfer basis | Status |
|---|---|---|---|---|---|
| AWS CloudHSM | FIPS 140-2 Level 3 hardware security modules — Ed25519 signing key generation, storage, signing | Signing-key material only. No Customer Content. Keys are non-exportable. | us-east-1 | EU SCCs + DPA | Active |
The HSM provider never has access to Customer Content. The HSM holds Ed25519 signing keys that operate on 32-byte Merkle roots produced inside Verdict's production network. Keys are generated inside the HSM, are non-exportable, and are rotated quarterly.
Transparency Log
| Subprocessor | Service | Data categories | Region | Transfer basis | Status |
|---|---|---|---|---|---|
| Sigstore Public Good Instance | Public transparency log (Rekor) — anchors Merkle roots only | Merkle root hash (32 bytes), timestamp, public key, batch metadata. No Customer Content, no Personal Data. | Global public infrastructure (operated by Linux Foundation / OpenSSF) | Public service; no Personal Data transferred | Active |
Sigstore Rekor receives only the Merkle root and metadata identifying the entry as a Verdict batch. Customer Content and Personal Data are never written to Rekor. See Privacy § 6 and Terms § 9.
Operational
| Subprocessor | Service | Data categories | Region | Transfer basis | Status |
|---|---|---|---|---|---|
| Stripe, Inc. | Payment processing, invoicing | Billing identifiers, payment last-4, transaction history (no full card data ever touches Verdict) | Global (US data controller) | EU SCCs + DPA | Active |
| Resend | Transactional and audience email | Email address, message content, delivery metadata | us-east-1 | EU SCCs + DPA | Active |
| Google LLC (Google Workspace + Analytics 4) | Business email, calendar, drive; opt-in website analytics with IP anonymization | Business communications; truncated technical identifiers | Global | EU SCCs + DPA | Active |
| Plain (or equivalent ticketing) | Customer support ticketing | Support correspondence and metadata | us-east-1 | EU SCCs + DPA | Roadmap |
| Linear | Engineering issue tracking (where Customer data is referenced in tickets) | Issue metadata; redacted Customer references | us-east-1 | EU SCCs + DPA | Active |
AI / Model Providers
| Subprocessor | Service | Data categories | Region | Transfer basis | Status |
|---|---|---|---|---|---|
| Anthropic, PBC | Claude models — assistive features (summaries, search, conformance helpers) | Only prompts you submit to AI features; zero-retention enterprise terms requested | us-east, eu-west | EU SCCs + Verdict no-train terms | Active |
| OpenAI, L.L.C. | Optional model provider for select features | Only prompts you submit to AI features; enterprise API (no training) | us-east | EU SCCs + Verdict no-train terms | Roadmap |
AI providers receive only the prompts and content that you specifically submit through AI-powered features of the Service. Where commercially available, Verdict opts in to zero-retention and no-trainingterms with the provider so that prompts and outputs are not used to train shared models. Confirm the terms applicable to a specific feature in the feature's in-product disclosure or in your Order.
Subscribe to Changes
Email privacy@verdict.systems with subject "Subprocessor notifications" and the account or Order ID for which you want to receive notice. We confirm subscription within five business days.
Email privacy@verdict.systems. For all other legal matters: legal@verdict.systems.
Postal: Verdict Systems Inc. · Attn: Legal · Houston, Texas, USA