Third-party services that process data on behalf of FlowPilot Studio, what they receive, where it is processed, and how they handle it.
Version 1.2 — Last updated: February 24, 2026
Prior versions of this document are available upon request at support@flowpilot.studio.
| Subprocessor | Purpose | Region | Certifications |
|---|---|---|---|
| Supabase | Database & authentication | US East (Virginia) | SOC 2 Type II |
| Anthropic | AI language model | US | SOC 2 Type II |
| Stripe | Payment processing | US | PCI DSS Level 1, SOC 2 Type II |
| AWS | Webhook & automation workers | US East (us-east-1) | SOC 2 Type II, ISO 27001 |
| Vercel | Application hosting & edge network | US East (iad1), global edge | SOC 2 Type II |
| Grafana Labs | Centralized logging & security monitoring | US | SOC 2 Type II |
Supabase provides the PostgreSQL database and authentication layer that powers FlowPilot. All persistent application data is stored here, protected by Row-Level Security policies that enforce strict organization isolation.
Anthropic provides the Claude language model that translates natural language queries into Flow PT API calls. The model operates on schema metadata only — it generates queries but never sees your production data or query results.
Not received: production FPT data, credentials, or file contents
Stripe handles all payment processing and subscription billing for FlowPilot. Raw payment card data is collected and stored entirely by Stripe — it never touches FlowPilot servers.
AWS hosts the webhook worker infrastructure that processes Flow Production Tracking events for FlowPilot’s automation features. Event payloads from FPT are received, matched against automation rules, and discarded after processing.
Not received: user credentials, file contents, or media assets
Vercel hosts the FlowPilot web application and serverless API functions. HTTP requests transit through Vercel’s global edge network for TLS termination and routing, then execute in the primary deployment region.
Grafana Labs provides the centralized logging platform (Grafana Cloud Loki) that aggregates application logs, structured security events, and infrastructure logs from all FlowPilot services for monitoring and incident detection.
Not received: FPT production data, user credentials, personal data beyond IP addresses, email addresses
If you have questions about our subprocessors or need additional information for your organization’s vendor review, please reach out to us at support@flowpilot.studio.
Our Data Processing Agreement (DPA) covers FlowPilot’s use of the subprocessors listed on this page, including processing details, security measures, and your audit rights. A downloadable PDF is available from the DPA page.
We will provide at least 30 days’ notice before adding new subprocessors or making material changes to existing ones. Notifications will be sent to the billing email address on file for your organization.
See also our Privacy Policy, Terms of Service, and Security pages.