Skip to content
docivault

Subprocessors

Subprocessors and where your data is stored

Where is docivault data stored?

Data is stored in India today. The database and authentication run on Supabase in Mumbai (ap-south-1), files are stored in Cloudflare R2 with no jurisdiction pinned, and the application is hosted on Vercel, whose functions default to US East. It is not stored in the EU.

Subprocessors

Every third party that touches your data, in one place

Subprocessors used by docivault, what each does, what data it touches, and its region
VendorWhat it doesData it touchesRegion
SupabasePostgres database and authenticationAccount data, workspace data, document metadata, audit recordsap-south-1, Mumbai, India
Cloudflare R2Document file storageThe files themselvesDefault endpoint, region: auto — no jurisdiction pinned
CloudflareDNS and CDNNetwork traffic only, no document dataGlobal network
Cloudflare TurnstileBot protection on authentication formsNo document dataGlobal network
VercelApplication hostingApplication requests and logsFunctions default to iad1, US East
ResendTransactional email — invites and password resetsEmail addresses and namesNot specified by vendor

Also true: there is no analytics vendor, no error tracker, no AI vendor processing customer data, and no payment processor live today. We use no analytics or advertising vendors — a genuine differentiator, not a checkbox.

Data location

Data is stored in India today — not in the EU

Data is stored in India today. It is not stored in the EU. EU data residency is on the compliance roadmap — it is a migration project rather than a setting, and we will not claim it is done before it is. See the compliance roadmap for the full, honest position on certifications and data residency.