← Security

CheckTrail subprocessors

Third parties that store or process customer data for CheckTrail. Last updated 2026-09-25. We will give customers notice before adding a subprocessor that sees check or client data.

"Customer data" here means anything a firm puts into CheckTrail: staff details, check details, images, client names and account numbers, and audit records.

Subprocessor Purpose Data it sees Location Security information
Amazon Web Services (S3, KMS) Storage of check images, attachments, import files and exam packages; encryption keys Check images and attachments; deposit-report CSVs as uploaded; exam packages (full blotter, images, audit trail). KMS sees key requests only, never data. US: us-east-1 or us-east-2 (one region, chosen at setup) https://aws.amazon.com/security/ · https://aws.amazon.com/compliance/
Amazon Web Services (Textract) — default OCR Reads check images to pre-fill fields Check image bytes at the moment of reading Same US region https://aws.amazon.com/textract/faqs/ (data use and opt-out) · requires AWS Organizations AI services opt-out policy — not yet applied
Anthropic — alternative OCR, off Reads check images (only if enabled) Check image bytes US https://trust.anthropic.com · Not used with real data until a zero-data-retention agreement is signed (not signed).
Neon Postgres database and backups All structured data (see data-flow.md 3.6): staff accounts, blotter entries and versions, client names, encrypted client account numbers, audit log with IP addresses US (AWS us-east-2 region) https://neon.com/security
Netlify Hosting and running the application; scheduled jobs All traffic in transit, including uploads and pages shown to users; application secrets; short-lived function logs (no check data by design) Global CDN edge; functions in a US region (confirm us-east-2 in site settings) https://www.netlify.com/security/
Resend Transactional email (alerts, digests, invites) Recipient email and name; short alert text: entry numbers, amounts, payer and client names, deadlines. No images or account numbers. US https://resend.com/security
Stripe Subscription billing Firm name, billing admin email, seat count; card/ACH details entered directly by the firm on Stripe's pages. No check data. US / global https://stripe.com/docs/security
Sentry Error monitoring Error messages and stack traces, route, browser type; request bodies, cookies and 6+ digit runs removed before sending US data region (confirm when the CheckTrail project is created) https://sentry.io/security/

Not subprocessors (no customer data)

Service Why listed
GitHub Source code and CI. Must never hold customer data; tests use fake data only.
Google Workspace Founder's email. May receive support emails a customer chooses to send; customers are asked not to email check images or account numbers.
Porkbun (domain registrar) DNS only.
The firm's own identity provider (Okta, Entra ID, etc.) Chosen and contracted by the firm, not by CheckTrail.

Status of contracts

For each subprocessor we must have: accepted terms, a data processing addendum (DPA) where offered, and a current copy of its SOC 2 report or equivalent. None of these have been collected and filed yet. To do before the first live firm:

Subprocessor Terms accepted DPA signed SOC 2 / ISO report on file AI / data-use opt-out
AWS ☐ ☐ (AWS DPA is part of the service terms) ☐ (AWS Artifact) ☐ AI services opt-out policy
Neon ☐ ☐ ☐ n/a
Netlify ☐ ☐ ☐ n/a
Resend ☐ ☐ ☐ n/a
Stripe ☐ ☐ ☐ n/a
Sentry ☐ ☐ ☐ n/a
Anthropic (only if enabled) ☐ ☐ ☐ ☐ zero-data-retention agreement

Plan tiers matter: some providers only offer a DPA, SSO for admins, or longer log retention on paid plans. Sentry is currently on its free plan; confirm what that plan's terms allow before sending production errors to it.