retireforge

Subprocessors

Last updated 2026-07-09

This is the current list of third-party service providers (subprocessors) RetireForge uses to operate the platform, and the categories of data shared with each. It mirrors our internal subprocessor register (compliance/subprocessors.md), maintained as a versioned repo artifact under our SOC 2 evidence program.

VendorPurposeData categories sharedRegion
GitHub (Microsoft)Source control, CI, deploy logSource code, CI logs (no production data)US
SupabaseManaged Postgres (advisor OS database), storage — project “retireforge-platform” (us-west-1, PostgreSQL 17, pgvector)Tenant business data; PII (census: date of birth, Social Security number, compensation) once liveUS
VercelWeb hosting + deploy-from-CIApp traffic, logsUS
ClerkAuthentication, organization/tenant managementUser identity (name, email), organization membershipUS
AnthropicLLM API via a typed agent gatewayPII-minimized prompts (masking by default; document-parsing is a documented exception)US
Voyage AIDense embeddings for the ERISA legal-authority retrieval corpusPublic law text only — no PII or participant dataUS
FinchPayroll/HRIS connector (sponsor OAuth consent)Census PII once wired to real accounts: name, date of birth, compensation, employment dates (no Social Security number)US

Planned (added when wired): Railway/Fly (Python services), Stripe (token billing), Cloudflare R2 or AWS S3 (vault documents), Inngest (job runner), Finch (payroll), custodian partner, Nestimate, licensed 5500 filing engine.

Copyright (c) 2026 RetireForge. All rights reserved.Back to the app