SurePortal uses a deliberately small set of infrastructure providers. No client PII is shared with any provider beyond what is required to operate the service—and secure links reach your clients from your own device (your phone's messages or your email app), so no provider ever receives your client's phone number or email address.
Last updated: July 12, 2026
| Provider | Purpose | Location | Client PII exposure |
|---|---|---|---|
| Vercel | Application hosting and delivery | United States | Handles requests in transit; stores no client PII. |
| Supabase | Database and authentication | United States (us-east-1) | Client PII stored only field-level encrypted (AES-256-GCM) and only until purge. Encryption keys are held outside Supabase. |
| Stripe | Subscription billing for brokers | United States | None — never receives client submission data. |
| Resend | Transactional email to brokers (account security notices) | United States | None — never receives client submission data. |
| Sentry | Application error monitoring | United States | None — error events are scrubbed of client PII before send. |
We will update this page before any new subprocessor handles client data. To be notified of changes, email security@surehelp.app with the subject "Subscribe to subprocessor updates." Questions about our vendor management practices are welcome at the same address.
The full picture—zero-retention lifecycle, field-level encryption, and the controls behind the promise—is on our security page. IMOs, BGAs, and agencies can request the complete security documentation package under NDA.