Who processes data on our behalf.
This page is the authoritative register of every third party that processes applicant, operator, or corporate data as part of the StabilityLogic platform. Each entry lists the company, its purpose, the jurisdiction it operates from, and the data category involved.
Every vendor. Every purpose. Every data category.
We publish this list in full so enterprise buyers, procurement teams, and vendor-risk reviewers can complete their diligence without a private disclosure request.
| Company | Purpose | Jurisdiction | Data category |
|---|---|---|---|
MongoDB Atlas Core infrastructure | Primary application database. Stores organization records, users, applicants, screening decisions, audit trail, and configuration. | United States (AWS us-east-1) | Applicant identity, income, housing history, scoring outputs, operator audit trail. Encrypted at rest (AES-256) and in transit (TLS 1.2+). |
Emergent Core infrastructure | Application hosting, ingress, TLS termination, secrets management, and delivery of the StabilityLogic frontend and API. | United States | All customer application traffic. Encrypted in transit. No persistent storage of applicant data on the runtime platform. |
Resend Activated per pilot | Transactional email delivery — pilot notifications, decision-workflow emails, adverse-action delivery, and executive briefings. | United States | Recipient email address, subject line, message body. No credit-file or banking data is sent through email. |
Twilio Activated per pilot | SMS delivery — applicant workflow notifications and operator messaging under an A2P 10DLC-registered program. | United States | Recipient phone number, message content, opt-in/opt-out state. |
Plaid Activated per pilot | Consented open-banking connectivity used to verify income adequacy and financial-resilience signals inside HSI. | United States | Bank-account metadata, income transactions, and balance snapshots — collected only with explicit applicant consent per screening. |
Anthropic Internal CRM only | LLM inference for internal AI Opportunity Briefs on inbound sales leads in the Pilot CRM. Not used for applicant screening or decisioning. | United States | Inbound sales-lead submission text only (company, contact, screening description). No applicant personal data is sent to this vendor. |
OpenAI Internal operations only | Optional secondary LLM inference path for internal operations tooling (drafting, summarization). Enabled only where Anthropic is unavailable and never for applicant decisioning. | United States | Operator-authored prompts and internal documents. No applicant personal data is sent to this vendor. |
Google Corporate operations | Google Workspace (Gmail, Drive, Calendar) for corporate operations, contract management, and scheduling with prospects. | United States | Corporate email, documents, calendar metadata. No applicant credit-file or banking data is stored in Workspace. |
Microsoft Corporate operations | Microsoft 365 for corporate documents, procurement artifacts, and enterprise customer communications where required by counterparty policy. | United States | Corporate documents and email metadata. No applicant credit-file or banking data is stored in Microsoft 365. |
- Purpose
- Primary application database. Stores organization records, users, applicants, screening decisions, audit trail, and configuration.
- Jurisdiction
- United States (AWS us-east-1)
- Data category
- Applicant identity, income, housing history, scoring outputs, operator audit trail. Encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Purpose
- Application hosting, ingress, TLS termination, secrets management, and delivery of the StabilityLogic frontend and API.
- Jurisdiction
- United States
- Data category
- All customer application traffic. Encrypted in transit. No persistent storage of applicant data on the runtime platform.
- Purpose
- Transactional email delivery — pilot notifications, decision-workflow emails, adverse-action delivery, and executive briefings.
- Jurisdiction
- United States
- Data category
- Recipient email address, subject line, message body. No credit-file or banking data is sent through email.
- Purpose
- SMS delivery — applicant workflow notifications and operator messaging under an A2P 10DLC-registered program.
- Jurisdiction
- United States
- Data category
- Recipient phone number, message content, opt-in/opt-out state.
- Purpose
- Consented open-banking connectivity used to verify income adequacy and financial-resilience signals inside HSI.
- Jurisdiction
- United States
- Data category
- Bank-account metadata, income transactions, and balance snapshots — collected only with explicit applicant consent per screening.
- Purpose
- LLM inference for internal AI Opportunity Briefs on inbound sales leads in the Pilot CRM. Not used for applicant screening or decisioning.
- Jurisdiction
- United States
- Data category
- Inbound sales-lead submission text only (company, contact, screening description). No applicant personal data is sent to this vendor.
- Purpose
- Optional secondary LLM inference path for internal operations tooling (drafting, summarization). Enabled only where Anthropic is unavailable and never for applicant decisioning.
- Jurisdiction
- United States
- Data category
- Operator-authored prompts and internal documents. No applicant personal data is sent to this vendor.
- Purpose
- Google Workspace (Gmail, Drive, Calendar) for corporate operations, contract management, and scheduling with prospects.
- Jurisdiction
- United States
- Data category
- Corporate email, documents, calendar metadata. No applicant credit-file or banking data is stored in Workspace.
- Purpose
- Microsoft 365 for corporate documents, procurement artifacts, and enterprise customer communications where required by counterparty policy.
- Jurisdiction
- United States
- Data category
- Corporate documents and email metadata. No applicant credit-file or banking data is stored in Microsoft 365.
Enterprise customers can raise concerns before a subprocessor change takes effect.
We notify each enterprise customer of any material subprocessor change at least thirty (30) days in advance. If you believe a change would create an unacceptable risk to your data, contact us during the notice window and we will work with you in good faith on a mitigation or, if necessary, allow you to terminate the affected portion of the underlying agreement without penalty per the executed DPA.