Skip to content

Subprocessor Register

Field Value
Owner Puneet Gupta (Co-Founder)
Classification Internal (shareable under NDA)
Version 1.0
Effective date 2026-06-11
Last verified 2026-07-12
Next review 2027-06-11

This register lists the third-party subprocessors used to deliver the Revzio service, the data they handle, and their attestation / DPA status. It supports the Third-Party Risk Management and Data Privacy policies. Attestation status was verified against each provider's public trust page on 2026-07-12.

Scope note. The core Revzio-appointed subprocessors are the managed database (Supabase, on AWS) and the LLM providers (OpenAI, Google). The ERP / billing systems (Zoho Books, QuickBooks, NetSuite, Oracle, Stripe) are generally the customer's own systems that Revzio integrates with on the customer's instruction, rather than subprocessors Revzio independently appoints.

Subprocessor Purpose Data handled Attestation (verified 2026-07-12) DPA Notes
Supabase Managed PostgreSQL database / hosting All customer data (encrypted at rest) SOC 2 Type II; ISO 27001:2022; HIPAA (BAA) Available (supabase.com/legal/dpa) — to execute Primary data store; runs on AWS
AWS Underlying cloud infrastructure Hosting SOC 1/2/3; ISO 27001/27017/27018/27701; PCI-DSS Level 1 Incorporated in AWS service terms (automatic) Fourth-party under Supabase's managed hosting
OpenAI LLM processing (API) Document / transaction text as needed for features SOC 2 Type II + SOC 3; ISO 27001/27017/27018/27701; ISO 42001 Available (openai.com DPA) — to execute Paid API — business / API data not used for model training
Google (Gemini) LLM processing Document / transaction text as needed Google Cloud / Vertex: SOC 1/2/3; ISO 27001/27017/27018; PCI-DSS Google Cloud DPA (CDPA) — to execute Paid tier — content not used to train / improve models
Google (Workspace / auth) Authentication / workspace User identity (name / email) ISO 27001/27017/27018/27701; SOC 1/2/3 Google Cloud DPA (CDPA) — to execute
Stripe Billing integration Customer billing / invoice data PCI-DSS Level 1; SOC 1 & SOC 2 Type II; SOC 3 Incorporated in Stripe Services Agreement (automatic) Not ISO 27001-certified per Stripe's trust page
Zoho Books ERP integration Accounting records SOC 1 Type 2; SOC 2 Type II; ISO 27001/27701/27017/27018; PCI-DSS Available (self-serve, console) — to execute Documented no-ads / no-data-sale commitment
QuickBooks (Intuit) ERP integration Accounting records PCI-DSS; SOC 2 Type II (SOC 1 for payroll); ISO 27001 Available (QuickBooks Online DPA) Customer's own ERP where applicable
NetSuite (Oracle) ERP integration Accounting records SOC 1 & SOC 2 Type II; ISO 27001:2013; ISO 27018; PCI-DSS Incorporated in NetSuite SSA Customer's own ERP where applicable
Oracle Fusion (OCI) ERP integration Accounting records OCI: SOC 1/2/3; ISO 27001/27017/27018/27701; PCI-DSS Oracle Services DPA Customer's own ERP where applicable

Maintenance

  • Reviewed periodically and on any change to subprocessors or their sub-processing.
  • New subprocessors are added only after the onboarding review in the Third-Party Risk Management Policy.
  • DPAs marked "to execute" are being formally accepted; those marked "automatic" are incorporated into the provider's standard service terms.

Revision history

Version Date Author Change Approved by
1.0 2026-07-12 Puneet Gupta Initial register; attestations verified against provider trust pages Puneet Gupta (Co-Founder)