Public legal
Subprocessors
Production subprocessor register for DossierCFO.
Subprocessors
This register lists the production providers used to operate DossierCFO. It must be updated before enabling new production providers, external marketing tracking, or a different AI/OCR route.
Last updated: May 26, 2026.
| Provider | Purpose | Data category | Production status |
| ------------ | -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------- |
| Vercel | Web hosting, deployment, CDN, request logs | App traffic, deployment metadata, request metadata | Active infrastructure provider. |
| Convex | Backend, database, storage, auth integration | Account, case, document, analysis, evidence, report, audit, and stored file data | Active application backend. |
| Resend | Transactional email | Email addresses, verification/access emails, delivery metadata | Required for production auth and access email delivery. |
| Google OAuth | Optional account sign-in | Identity and authentication metadata | Optional only when Google auth is configured and publicly claimed. |
| OpenRouter | AI/OCR model routing | Redacted text for analysis; raw scanned PDFs/images only when OCR is triggered after clean scan; provider route metadata | Active AI/OCR route; confirm contract/DPA record before enabling customer AI/OCR access. |
Access enablement rule
Manual AI access enablement remains the control point. A user may upload and manage files while pending, but AI usage, OCR-assisted analysis, report generation, and export creation require Focus Digital enablement.
Change rule
Adding a subprocessor, enabling marketing tracking, or changing the OCR/text-analysis route requires a docs update and privacy review before the provider is used for customer files.