Subprocessors
Who helps us run the service
PhlebotomySkills.com uses the following third-party subprocessors to deliver the service. Each is contractually bound by its own DPA / security program. We commit to notifying customers at least 30 days before adding or changing a subprocessor that materially processes personal data.
Last updated: 2026-04-24
| Subprocessor | Purpose | Region | Certifications |
|---|---|---|---|
| Vercel | Application hosting and CDN | Global (US primary) | SOC 2 Type II, ISO 27001 |
| Supabase | Database (Postgres) and auth | US East (AWS) | SOC 2 Type II |
| Stripe | Payment processing | Global | PCI DSS Level 1, SOC 2 |
| Resend | Transactional email (receipts, newsletter, password reset) | US | SOC 2 Type II |
| GitHub | Source code hosting and CI | Global | SOC 2 Type II, ISO 27001 |
| Cloudflare | DNS (not used as proxy) | Global | SOC 2 Type II, ISO 27001 |
Enterprise customers can subscribe to change notifications by emailing security@phlebotomyskills.com. See also our security overview and privacy policy.