Version subprocessors-2026-07-11
Subprocessors
Effective date: June 29, 2026. Draft for attorney review.
This page lists every vendor wired into the current application implementation, checkout flow, document parsing pipeline, or AI processing pipeline — including vendors that only receive Customer Data once the corresponding product feature is turned on. DiliPilot should execute vendor DPAs, confirm locations and transfer terms, and keep this table current before processing material customer datasets at scale.
| Subprocessor | Purpose | Data categories | When it receives data | Processing location | Transfer mechanism |
|---|---|---|---|---|---|
| Supabase | Authentication, database, and private storage used by the application. | Account identifiers, workspace records, uploaded documents, logs, and metadata. | In every deployment | Not publicly asserted. | To be confirmed by vendor agreement. |
| Stripe | Checkout, billing, invoices, and payment processing when a customer starts paid checkout. | Billing contact, subscription, invoice, tax, payment status, and Stripe-hosted payment details. | In every deployment | Not publicly asserted. | Stripe terms and any applicable DPA or independent-controller terms. |
| Vercel | Application hosting, edge network, and request routing for the DiliPilot web application. | All application request traffic, which can include uploaded documents in transit. | In every deployment | Not publicly asserted. | To be confirmed by vendor agreement. |
| LlamaParse (LlamaIndex) | Document parsing for PDF and spreadsheet uploads. | Entire uploaded document files, sent for parsing. | Only when the feature is enabled | Not publicly asserted. | To be confirmed by vendor agreement. |
| AI model providers (Anthropic; OpenAI and Google Gemini if enabled) | Financial data extraction, classification, and diligence-finding generation. | Uploaded document text and extracted financial figures included in model prompts. | Only when the feature is enabled | Not publicly asserted. | To be confirmed by vendor agreement. |
| PostHog | Product analytics. | Event names and metadata such as tenant and deal identifiers, timestamps, and file byte sizes. Not document content. | Only when the feature is enabled | Not publicly asserted. | To be confirmed by vendor agreement. |
| Sentry | Error monitoring and application diagnostics. | Stack traces and request context. Not intentionally document content. | Only when the feature is enabled | Not publicly asserted. | To be confirmed by vendor agreement. |
| Upstash | Rate limiting for API requests. | Request identifiers used as rate-limit keys. Not document content. | Only when the feature is enabled | Not publicly asserted. | To be confirmed by vendor agreement. |
Document parsing and AI model providers on this list are wired into the product but are only active in deployments where the corresponding parser or model provider is configured; DiliPilot does not send Customer Data to a provider that is not both listed here and enabled. See the AI and Due Diligence Disclosure for how AI-processed document content is handled. Vendor DPA execution, processing-location confirmation, and transfer-mechanism terms are still in progress for every vendor on this page. To ask about subprocessors, contact zayyanlatif@dilipilot.com.
