Subprocessors

Where Client Data Is Processed

SurePortal uses a deliberately small set of infrastructure providers. No client PII is shared with any provider beyond what is required to operate the service—and secure links reach your clients from your own device (your phone's messages or your email app), so no provider ever receives your client's phone number or email address.

Last updated: July 12, 2026

ProviderPurposeLocationClient PII exposure
VercelApplication hosting and deliveryUnited StatesHandles requests in transit; stores no client PII.
SupabaseDatabase and authenticationUnited States (us-east-1)Client PII stored only field-level encrypted (AES-256-GCM) and only until purge. Encryption keys are held outside Supabase.
StripeSubscription billing for brokersUnited StatesNone — never receives client submission data.
ResendTransactional email to brokers (account security notices)United StatesNone — never receives client submission data.
SentryApplication error monitoringUnited StatesNone — error events are scrubbed of client PII before send.

We will update this page before any new subprocessor handles client data. To be notified of changes, email security@surehelp.app with the subject "Subscribe to subprocessor updates." Questions about our vendor management practices are welcome at the same address.

How We Protect Client Data

The full picture—zero-retention lifecycle, field-level encryption, and the controls behind the promise—is on our security page. IMOs, BGAs, and agencies can request the complete security documentation package under NDA.