Subprocessor List
Status: DRAFT — pending licensed-attorney review. Not yet published; not yet in force. Version 1.0-draft · Grounded in docs/legal/FACT_REGISTER.md §B (code facts verified 2026-07-23; owner decisions D1–D14 updated 2026-08-04) Intended effective date: 2026-08-04 · Last updated: 2026-08-04 — takes effect when published, which happens only after attorney sign-off.
Publisher: Single Case Informatics, PBC — a Delaware public benefit corporation. Service: SingleCase.ai. Contact for this list: [email protected]
This page is a draft prepared for attorney review. It is not legal advice and is not yet in force. Its intended effective date takes effect on publication, which happens only after counsel signs off.
What a "subprocessor" is
When you use SingleCase.ai, Single Case Informatics, PBC ("SCI", "we") relies on a small set of third-party service providers to operate the service. Those providers process data on our behalf and under our instructions — they are our subprocessors. This page lists the subprocessors that receive customer or personal data in our production environment, what each one does, the category of data it receives, and where it processes that data.
Development-only and disabled integrations are not listed here, because they do not receive production customer data. If we enable any additional subprocessor in production, we will update this page first (see Changes to this list).
Production subprocessors
All five providers below process data in the United States.
| # | Subprocessor (legal entity) | Service role | Category of data received | Processing location |
|---|---|---|---|---|
| 1 | Supabase — Supabase, Inc. | Authentication, primary application database (Postgres), file storage, and realtime messaging. | Account and authentication data (email, password credential, 6-digit email one-time codes, session tokens); organization / workspace / study membership and roles; study metadata; the uploaded-documents index; AI interaction logs; comments; activity events; beta-program applications; and user-uploaded images and files (organization logos, poster images, observation-import uploads). Transactional email (email address + one-time code) is delivered through Supabase's own email service. | USA |
| 2 | Vercel — Vercel Inc. | Application hosting, serverless functions, scheduled jobs, and the document-parsing runtime. | Application request and response traffic (effectively any data that passes through the service in use); the document-parsing function additionally receives user-uploaded documents. | USA |
| 3 | MongoDB Atlas — MongoDB, Inc. | Document database for large research records. | Research protocols, observation/data-collection records, graph configurations, APA-style tables, and their version history. | USA |
| 4 | Google (Gemini) — Google LLC | AI inference (default, always-on AI provider). | The AI request payload: protocol, graph, table, and poster text; uploaded document text and images; observation data; and identifiable participant fields and IRB fields. See the AI Use / Transparency Notice for the exact data sent. Reached via the Google AI Studio (generative-language) API. | USA |
| 5 | LlamaCloud / LlamaParse — LlamaIndex, Inc. | Parsing of user-uploaded research documents. | The full content of user-uploaded research files (PDF, Word, text/Markdown, PNG/JPEG up to 50 MB) and datasheet / figure images. | USA |
Vendor security attestations
The three infrastructure providers below publish independent security attestations, as reported by each vendor:
| Subprocessor | Attestations (per the vendor's published attestations) |
|---|---|
| MongoDB Atlas | SOC 2 Type 2, ISO 27001, HIPAA-ready |
| Supabase | SOC 2 Type 2, HIPAA (with paid add-on) |
| Vercel | SOC 2 Type 2, HIPAA (with BAA) |
Important: These attestations belong to the named vendors. SCI has not independently audited any vendor, does not itself hold SOC 2, ISO 27001, HIPAA, or any comparable certification, and does not currently hold a Business Associate Agreement (BAA) with any subprocessor. SingleCase.ai is not offered as a HIPAA-covered service; do not upload Protected Health Information. The presence of a vendor's attestation does not make SCI or SingleCase.ai certified or compliant.
Changes to this list
We keep this list current. We commit to giving advance notice before we add a new subprocessor that will process production customer data.
- To subscribe to change notifications: email [email protected] and ask to be added to the Subprocessor List notification list.
- Advance-notice period: 30 days before a new production subprocessor begins processing customer data (Fact Register §A, D12). Exception: where we must replace a subprocessor urgently for security or continuity reasons, we will make the change as needed and notify subscribers as promptly as practicable rather than waiting out the 30 days.
- How to object: if you are an institution with a written agreement with us, that agreement governs your objection rights. Individual users who object to a new subprocessor may stop using the Service and request deletion of their data (see the Privacy Policy).
- The "Last updated" date at the top of this page reflects the most recent change.