subprocessors,
who processes data, and where.
draft for the preview / waitlist phase — review with counsel before relying on it. today, only the waitlist site is operating — the rows marked waitlist apply now; the rest apply once the product and billing go live.
last updated: [TODO: date]
Vercel
purpose: hosting, CDN / edge delivery, cookieless analytics, and Blob storage.
data: site delivery and aggregate analytics with no PII in analytics, plus product blob artifacts once the product is live.
scope: waitlist + product.
Neon
purpose: managed Postgres.
data: the dedicated database hosted on Neon for the waitlist (soravio_waitlist) today; the control plane plus per-tenant databases for the product.
scope: waitlist + product.
Polar
purpose: Merchant-of-Record billing and payments.
data: customer and payment data.
scope: product only, when billing goes live — not used by the waitlist.
AI Gateway + model provider
purpose: running the product agent and model inference.
data: customer queries and connected data at run time.
scope: product only — explicitly not used by the waitlist.
a note on Better Auth
Better Auth is not a subprocessor — it is an open-source (MIT) library we run inside our own Vercel / Neon infrastructure, so no third party receives your identity data through it.
certifications
soravio does not currently hold SOC 2 or ISO 27001; our infrastructure subprocessors Vercel and Neon are each SOC 2 / ISO 27001 certified, so those infrastructure controls are inherited.
contact
questions about subprocessors or a DPA: privacy@soravio.app.
subprocessors · preview draft · soravio.app