Legal

Subprocessors

The companies that help us run SecureCrews. Each one has a data processing agreement (DPA) in place and only sees the data it needs to do its job.

Last updated July 22, 2026 · 9 subprocessors

Stripe
DPA active

Subscription billing and payment processing

stripe.com
Data accessed
Billing name, email address, billing address, payment card details
Security and compliance
PCI DSS Level 1 certified. SOC 2 Type II. Card data never touches SecureCrews servers.
Location
United States
Twilio
DPA active

SMS text message and email delivery

twilio.com
Data accessed
Phone numbers, email addresses, message content
Security and compliance
SOC 2 Type II. CPNI compliant. Messages encrypted in transit.
Location
United States
Amazon Web Services (AWS)
DPA active

Server hosting, encryption key management (KMS), transactional email delivery (SES)

aws.amazon.com
Data accessed
All application data (encrypted at rest). KMS manages encryption keys but never sees plaintext data. SES sees email addresses and email content.
Security and compliance
SOC 2 Type II. ISO 27001. FedRAMP authorized. AES-256 encryption at rest.
Location
United States (us-east-2)
Cloudflare
DPA active

File storage (R2), CDN, DDoS protection, DNS, and download gatekeeper

cloudflare.com
Data accessed
All uploaded files (documents, photos), encrypted in transit and at rest. Website traffic metadata.
Security and compliance
SOC 2 Type II. ISO 27001. Zero-egress architecture. All files encrypted with AES-256.
Location
Global edge network (data stored in US)
Google Maps Platform
DPA active

Address geocoding, map display, and place search

cloud.google.com/maps-platform
Data accessed
Property addresses submitted for geocoding
Security and compliance
SOC 2 Type II. ISO 27001. Standard Google Cloud terms.
Location
United States
Anthropic (Claude AI)
DPA active

AI-assisted drafting of customer review responses

anthropic.com
Data accessed
Review text only. No names, contact information, addresses, or other personal details are sent.
Security and compliance
Zero data retention on API calls. Inputs are not used for model training. SOC 2 Type II.
Location
United States
Sentry
DPA active

Error monitoring and crash reporting

sentry.io
Data accessed
Error stack traces, browser and device metadata. PII is scrubbed before transmission. No session replay is used.
Security and compliance
SOC 2 Type II. ISO 27001. Data scrubbing enabled.
Location
United States
Google Analytics
DPA activeConsent required

Website usage analytics (marketing site only)

marketingplatform.google.com/about/analytics
Data accessed
Anonymized usage data: pages viewed, approximate location, device and browser type. IP anonymization is enabled.
Security and compliance
SOC 2 Type II. ISO 27001. Loads only after the visitor consents via the cookie banner.
Location
United States
Canopy Connect
DPA activeEnterprise only

Insurance policy verification (Enterprise tier only)

canopyconnect.com
Data accessed
Homeowner name, address, and authorization to pull policy info from their carrier
Security and compliance
SOC 2 Type II. Data encrypted in transit and at rest.
Location
United States

How we handle subprocessor changes

When we add a new subprocessor or make a significant change to an existing one, we update this page and notify Enterprise customers by email at least 30 days in advance. If you have concerns about a subprocessor, contact us at [email protected].

For our full privacy practices, see the Privacy Notice.