1. Overview
Compliance Locker uses carefully selected subprocessors to host the application, store account and vault metadata, and hold encrypted file payloads. We contractually require subprocessors to protect personal data and process it only on our instructions.
Document contents are encrypted in your browser before upload. Object storage providers receive ciphertext and cannot decrypt your files without your master password and cryptographic keys.
This page supplements our Privacy Policy with current infrastructure provider details for security and compliance reviewers.
2. Current subprocessors
| Provider | Purpose | Data processed | Typical locations |
|---|---|---|---|
Vercel Inc. Privacy notice | Application hosting, serverless compute, and content delivery | Account email, session identifiers, request metadata, application logs | United States and other regions where Vercel operates |
Neon Inc. Privacy notice | Managed PostgreSQL database for application metadata | Account records, encrypted file metadata, share link records, audit ledger entries | United States and other regions where Neon operates |
Cloudflare, Inc. Privacy notice | R2 object storage for encrypted document payloads | Encrypted file blobs (ciphertext), storage keys tied to opaque object paths | Global; bucket region depends on deployment configuration |
PostHog, Inc. Privacy notice | Product analytics and usage telemetry | Account identifiers, anonymized event properties, browser metadata (no document plaintext) | United States and EU depending on project configuration |
Dodo Payments Privacy notice | Subscription billing and payment processing | Billing email, customer and subscription identifiers, payment status metadata | As operated by Dodo Payments and its payment partners |
3. Changes to this list
We may add or replace subprocessors as the Service evolves. Where required by applicable law or contract, we will provide notice of material changes. Enterprise customers with data processing agreements may receive additional notification rights under their agreements.
To ask about subprocessors or request notifications, contact support@compliancelocker.app.
4. Customer responsibilities
If you are subject to vendor-management, transfer, or subprocessor approval obligations, you are responsible for reviewing this list against your policies and contracts. Compliance Locker does not guarantee that these providers meet your specific regulatory or contractual requirements without a separate written agreement.
The information on this page is provided for general informational purposes only and does not constitute legal, regulatory, or professional advice. You are responsible for determining whether the Service meets your compliance obligations.