← Back to home

Subprocessors

Last updated: October 2, 2026

Certgio uses a small number of third-party services to run the platform. This page lists every one of them that can receive personal information, what reaches it, and where it is processed.

It is deliberately a separate page from our Privacy Policy. The policy is a versioned document — when it changes, people who agreed to it agreed to a specific version, and we keep a record of which one. A vendor list changes on a different clock, and re-versioning a legal agreement because a supplier moved region would make that record less meaningful, not more. The policy states the practice; this page states the current facts.

Where we do not yet know something, this page says so. A confirmed region and an assumed one look identical on a page that only prints regions, so we print the confirmation status too.

Services that process personal information

ServiceWhat it does for usPersonal information it receivesProcessing locationRole
AnthropicAI reading of uploaded documentsSee "What Anthropic receives" below — this is our most sensitive transferUnited States. Region not confirmedProcessor
RailwayHosting for our API, database and cacheEverything stored by the platform: accounts, vendors, certificates, requests, consent recordsRuns on Google Cloud Platform. Our volume's region reads US East (Virginia, USA) in Railway's dashboardProcessor
ResendSending and receiving our emailRecipient address, message content, and — for email sent to us — attachments, including certificates brokers send inUnited States (confirmed)Processor
Cloudflare (R2)Document storageUploaded certificates and contractsEastern North America (confirmed) - this is where the data sits, not a restriction on where it may go. See the note below.Processor
Cloudflare (Turnstile)Confirms a person, not a bot, is using the free COI checkerIP address, user agent, browser signalsCloudflare's global networkProcessor
PostHogProduct analytics — only if you accept analyticsAccount id, email address, account type, signup date, pages viewed, steps completed, and a random visitor idAWS us-east-1, Virginia, USA (confirmed)Processor
SentryCrash reports; session replay only if you accept analyticsError type, stack trace, page URL. Replay is masked — text hidden, media blocked. We don't attach your account, email address or IP address to error reports, and our servers remove email addresses and account IDs from the reports they send. A report can still include other text that was part of the error, such as a company name, and reports from your browser are not filtered this wayUnited States. Org region not confirmedProcessor
Google"Sign in with Google", if you choose itYour Google account identity, plus IP and browser when the sign-in script loadsGoogle's global infrastructureController in its own right — not our processor. See below
Microsoft 365Our own certgio.com mailboxesAnything you email usNot confirmedProcessor

What Anthropic receives, specifically

This is the transfer people should look at hardest, so it gets its own paragraph rather than a table cell.

When you upload a Certificate of Insurance, the entire PDF is sent to Anthropic — not a summary, not selected fields. That document typically contains the insured business's legal name and address, the broker or producer's name, address, phone and email, the certificate holder's name and address, policy numbers, insurer names, effective and expiry dates, coverage limits, and whatever appears in the certificate's description-of-operations box, which often names projects, sites and individuals.

When you upload a contract or lease to state your insurance requirements, the extracted text of that document is sent to Anthropic as well. Those contain party names, premises addresses and commercial terms.

Anthropic acts as our processor. Its terms state that it does not train models on content submitted through its API, and its data processing addendum commits it to delete customer data within 30 days of the end of our agreement. We use Anthropic's standard commercial terms and do not have a zero-retention arrangement. Anthropic does not publish a retention period for inputs while an account is active, and we have not separately confirmed one for ours. We will publish that figure here once we have it.

Where your documents are stored, and who can reach them

Uploaded certificates and contracts are stored in a Cloudflare R2 bucket created on 1 July 2026. Its data is located in Eastern North America.

That is a location, not a guarantee. Cloudflare offers two different things: a location hint, which is where the data is placed, and a jurisdiction, which is a binding restriction Cloudflare enforces on where the data may ever be. We have the first. No jurisdiction was set when the bucket was created, and Cloudflare does not allow one to be added to an existing bucket. We would rather tell you that than print a region and let it read as a commitment we have not made.

The bucket is not reachable from the internet. It has no custom domain and its Public Development URL is switched off, so there is no address that serves an object directly. Every document is fetched by our own servers and streamed to you through an authenticated, permission-checked request - we never hand your browser a link to the storage bucket, not even a temporary signed one. For Compliance Passport documents the permission check runs twice: once when the link is created and again when the file is actually requested, so access revoked in between is refused.

Why Google is listed differently

Every other service on this page is our processor: it handles data on our instructions and for our purposes. Google is not, for sign-in. When you choose "Sign in with Google", you are using your own relationship with Google, under Google's terms and privacy policy, and Google decides for itself what it does with that. We receive a verified identity from it; we do not direct what Google does.

We say this rather than listing Google alongside the others because the distinction changes what you can ask of whom. For a processor, come to us. For what Google holds about your Google account, that is between you and Google.

Google also appears on this page indirectly: Railway, which hosts our infrastructure, runs on Google Cloud Platform.

Two things that used to send data to Google and no longer do. Our Compliance Passport pages used to load a webfont from Google on every view, which sent the viewer's IP address to Google. We now serve that font ourselves. The Google sign-in script used to load on every page of our site, including this one and our Privacy Policy; it now loads only on the sign-in and sign-up pages, where it is actually used.

Configured but not in use

NIPR (National Insurance Producer Registry) — our code can look up insurance producer licences against NIPR, but the integration is switched off and holds no credentials. No personal information reaches NIPR. If that ever changes, this page changes first.

What we have not confirmed yet

ServiceRegion confirmedRetention confirmed
AnthropicNoNo — deletion within 30 days of contract end is published; retention during the term is not
RailwayPartly — GCP confirmed, and Railway reports our volume in US East (Virginia, USA). That is the volume's region as Railway shows it, not an independently verified compute regionNo
ResendYes — United StatesYes — deleted within 90 days of account termination
Cloudflare (R2)Yes - Eastern North America, as a placement hint rather than a set jurisdictionNo
Cloudflare (Turnstile)Global network, no single regionNo
PostHogYes — AWS us-east-1, VirginiaNo
SentryNoNo
Microsoft 365NoNo

Vendor data processing addenda and subprocessor lists: Anthropic · PostHog · Sentry · Cloudflare · Resend · Railway

Questions about any of this: hello@certgio.com.