This is the current list of third-party service providers (subprocessors) RetireForge uses to operate the platform, and the categories of data shared with each. It mirrors our internal subprocessor register (compliance/subprocessors.md), maintained as a versioned repo artifact under our SOC 2 evidence program.
| Vendor | Purpose | Data categories shared | Region |
|---|---|---|---|
| GitHub (Microsoft) | Source control, CI, deploy log | Source code, CI logs (no production data) | US |
| Supabase | Managed Postgres (advisor OS database), storage — project “retireforge-platform” (us-west-1, PostgreSQL 17, pgvector) | Tenant business data; PII (census: date of birth, Social Security number, compensation) once live | US |
| Vercel | Web hosting + deploy-from-CI | App traffic, logs | US |
| Clerk | Authentication, organization/tenant management | User identity (name, email), organization membership | US |
| Anthropic | LLM API via a typed agent gateway | PII-minimized prompts (masking by default; document-parsing is a documented exception) | US |
| Voyage AI | Dense embeddings for the ERISA legal-authority retrieval corpus | Public law text only — no PII or participant data | US |
| Finch | Payroll/HRIS connector (sponsor OAuth consent) | Census PII once wired to real accounts: name, date of birth, compensation, employment dates (no Social Security number) | US |
Planned (added when wired): Railway/Fly (Python services), Stripe (token billing), Cloudflare R2 or AWS S3 (vault documents), Inngest (job runner), Finch (payroll), custodian partner, Nestimate, licensed 5500 filing engine.