Subprocessor List

Last Updated: May 27, 2026

Aeopic LLC (“Aeopic”) uses the following third-party service providers (subprocessors) to deliver services to our clients. Each subprocessor has been evaluated for its security practices and data handling capabilities.

This page is maintained as part of our commitment to transparency under applicable data protection regulations, including the Texas Data Privacy and Security Act (TDPSA). For questions about our subprocessors, contact us at privacy@aeopic.com.

SubprocessorPurposeData HandledLocationCompliance
SupabaseDatabase, Authentication, File StorageApplication data, user credentials, uploaded filesUnited States (AWS)SOC 2 Type II, HIPAA BAA available
VercelApplication Hosting, Edge Functions, CDNApplication code, static assets, server-side logicUnited States / Global EdgeSOC 2 Type II
StripePayment Processing, BillingPayment card data, billing informationUnited StatesPCI DSS Level 1, SOC 2 Type II
TwilioSMS and Voice CommunicationsPhone numbers, message contentUnited StatesSOC 2 Type II, HIPAA eligible
ResendTransactional Email DeliveryEmail addresses, email contentUnited StatesSOC 2 Type II
AnthropicAI Processing (Claude API)Prompts and conversation contextUnited StatesSOC 2 Type II, ISO 27001, ISO 42001, BAA available, Zero Data Retention available
SignatureAPIElectronic SignaturesContract data, signature recordsUnited StatesESIGN Act and UETA compliant
Google AnalyticsWebsite Traffic AnalyticsAnonymized usage data, page views, session dataUnited StatesGoogle Cloud SOC 2, DPA available

Changes to This List

We will notify clients of subprocessor changes as specified in applicable Data Processing Agreements. If you have an active DPA with Aeopic, you will receive written notice before any new subprocessor is engaged that processes your data.

Clients may object to a new subprocessor within 30 days of receiving notice. If an objection cannot be resolved, either party may terminate the affected services as described in the applicable agreement.

Our Data Handling Principles

  • All subprocessors are contractually required to maintain appropriate security measures.
  • Client data is processed only for the purposes described in the applicable Service Level Agreement.
  • We select subprocessors with independently audited security programs (SOC 2, ISO 27001, or equivalent) wherever possible.
  • All data processing occurs within the United States unless otherwise specified and agreed upon with the client.

Related Documents