Subprocessor Register
| Field |
Value |
| Owner |
Puneet Gupta (Co-Founder) |
| Classification |
Internal (shareable under NDA) |
| Version |
1.0 |
| Effective date |
2026-06-11 |
| Last verified |
2026-07-12 |
| Next review |
2027-06-11 |
This register lists the third-party subprocessors used to deliver the Revzio service, the data
they handle, and their attestation / DPA status. It supports the Third-Party Risk Management and
Data Privacy policies. Attestation status was verified against each provider's public trust page
on 2026-07-12.
Scope note. The core Revzio-appointed subprocessors are the managed database (Supabase, on
AWS) and the LLM providers (OpenAI, Google). The ERP / billing systems (Zoho Books, QuickBooks,
NetSuite, Oracle, Stripe) are generally the customer's own systems that Revzio integrates
with on the customer's instruction, rather than subprocessors Revzio independently appoints.
| Subprocessor |
Purpose |
Data handled |
Attestation (verified 2026-07-12) |
DPA |
Notes |
| Supabase |
Managed PostgreSQL database / hosting |
All customer data (encrypted at rest) |
SOC 2 Type II; ISO 27001:2022; HIPAA (BAA) |
Available (supabase.com/legal/dpa) — to execute |
Primary data store; runs on AWS |
| AWS |
Underlying cloud infrastructure |
Hosting |
SOC 1/2/3; ISO 27001/27017/27018/27701; PCI-DSS Level 1 |
Incorporated in AWS service terms (automatic) |
Fourth-party under Supabase's managed hosting |
| OpenAI |
LLM processing (API) |
Document / transaction text as needed for features |
SOC 2 Type II + SOC 3; ISO 27001/27017/27018/27701; ISO 42001 |
Available (openai.com DPA) — to execute |
Paid API — business / API data not used for model training |
| Google (Gemini) |
LLM processing |
Document / transaction text as needed |
Google Cloud / Vertex: SOC 1/2/3; ISO 27001/27017/27018; PCI-DSS |
Google Cloud DPA (CDPA) — to execute |
Paid tier — content not used to train / improve models |
| Google (Workspace / auth) |
Authentication / workspace |
User identity (name / email) |
ISO 27001/27017/27018/27701; SOC 1/2/3 |
Google Cloud DPA (CDPA) — to execute |
|
| Stripe |
Billing integration |
Customer billing / invoice data |
PCI-DSS Level 1; SOC 1 & SOC 2 Type II; SOC 3 |
Incorporated in Stripe Services Agreement (automatic) |
Not ISO 27001-certified per Stripe's trust page |
| Zoho Books |
ERP integration |
Accounting records |
SOC 1 Type 2; SOC 2 Type II; ISO 27001/27701/27017/27018; PCI-DSS |
Available (self-serve, console) — to execute |
Documented no-ads / no-data-sale commitment |
| QuickBooks (Intuit) |
ERP integration |
Accounting records |
PCI-DSS; SOC 2 Type II (SOC 1 for payroll); ISO 27001 |
Available (QuickBooks Online DPA) |
Customer's own ERP where applicable |
| NetSuite (Oracle) |
ERP integration |
Accounting records |
SOC 1 & SOC 2 Type II; ISO 27001:2013; ISO 27018; PCI-DSS |
Incorporated in NetSuite SSA |
Customer's own ERP where applicable |
| Oracle Fusion (OCI) |
ERP integration |
Accounting records |
OCI: SOC 1/2/3; ISO 27001/27017/27018/27701; PCI-DSS |
Oracle Services DPA |
Customer's own ERP where applicable |
Maintenance
- Reviewed periodically and on any change to subprocessors or their sub-processing.
- New subprocessors are added only after the onboarding review in the Third-Party Risk
Management Policy.
- DPAs marked "to execute" are being formally accepted; those marked "automatic" are
incorporated into the provider's standard service terms.
Revision history
| Version |
Date |
Author |
Change |
Approved by |
| 1.0 |
2026-07-12 |
Puneet Gupta |
Initial register; attestations verified against provider trust pages |
Puneet Gupta (Co-Founder) |