Subprocessors
Subprocessors and where your data is stored
Where is docivault data stored?
Data is stored in India today. The database and authentication run on Supabase in Mumbai (ap-south-1), files are stored in Cloudflare R2 with no jurisdiction pinned, and the application is hosted on Vercel, whose functions default to US East. It is not stored in the EU.
Subprocessors
Every third party that touches your data, in one place
| Vendor | What it does | Data it touches | Region |
|---|---|---|---|
| Supabase | Postgres database and authentication | Account data, workspace data, document metadata, audit records | ap-south-1, Mumbai, India |
| Cloudflare R2 | Document file storage | The files themselves | Default endpoint, region: auto — no jurisdiction pinned |
| Cloudflare | DNS and CDN | Network traffic only, no document data | Global network |
| Cloudflare Turnstile | Bot protection on authentication forms | No document data | Global network |
| Vercel | Application hosting | Application requests and logs | Functions default to iad1, US East |
| Resend | Transactional email — invites and password resets | Email addresses and names | Not specified by vendor |
Also true: there is no analytics vendor, no error tracker, no AI vendor processing customer data, and no payment processor live today. We use no analytics or advertising vendors — a genuine differentiator, not a checkbox.
Data location
Data is stored in India today — not in the EU
Data is stored in India today. It is not stored in the EU. EU data residency is on the compliance roadmap — it is a migration project rather than a setting, and we will not claim it is done before it is. See the compliance roadmap for the full, honest position on certifications and data residency.