Service providers we use
Sealinn runs on other companies’ infrastructure, the same as every tool you use. This page separates providers active in the production configuration from providers disclosed in advance but not yet active, with what each does and what it receives — routine disclosure, published rather than sent on request.
Last updated: September 2, 2026 · 10 active providers · 2 inactive providers · 1 planned provider · we give at least 30 days’ notice before a planned provider starts receiving data, and every change is logged below.
The list
| Provider | What it does | What it receives |
|---|---|---|
| Vercel | Runs the web application and serves every page | Everything you send or view through the browser passes through it in transit, plus request logs (IP address, page requested). |
| Neon | The Postgres database | All structured data at rest: your subcontractors, projects, requirements, the fields read off each document, and the audit log. |
| Cloudflare R2 | Stores the uploaded files themselves | Every document uploaded to your workspace — certificates, W-9s, licenses, safety cards — and the reports and archives you generate. |
| Clerk | Signs your team in | The name, email address and login credentials of people on your team. Never subcontractor documents. |
| OpenAIInactive — no new uploads | Historical automated document reading and any future reviewed activation | No new uploads currently. When automated reading previously ran, it received an image of each document sent for extraction. See the section below for the historical and future-activation details. |
| Resend | Sends email | The recipient's email address and the message: reminders, upload links, rejection notes. |
| TwilioInactive — no new uploads | Historical product SMS and any future separately reviewed activation | No new data currently. If product SMS is reviewed and activated later, it would receive the recipient's phone number and the message body. |
| Upstash | Job queue and rate limiting | Identifiers for work in progress — which document is being read and which reminder is queued — plus IP-address-based keys used to rate-limit public and authenticated requests. Not document contents. |
| Stripe | Takes payment | Your billing contact and payment details, which go to Stripe directly. We never see or store a card number. |
| Railway | Runs the background worker and the antivirus scanner | The same data as the application, for the work that happens outside a request: reading documents, sending reminders, generating reports. |
| Sentry | Error monitoring | Diagnostic detail when something breaks — the error, the page, and identifiers for the workspace and user involved. |
| PostHog | Product analytics | Which pages are used and which actions are taken, tied to a user and workspace identifier with the user's role. Not document contents or the user's email address. |
| Google AnalyticsPlanned — inactive | Planned analytics for public marketing pages only; the production integration is currently dormant | Only after future activation and a visitor's explicit opt-in: an allow-listed public marketing-page path and title, browser/device metadata, and an IP address in transit. No query string, fragment, signed-in app route, bearer-link path, document content, user identifier or workspace identifier. |
AI document-reading status
Automated AI document reading is currently unavailable. New uploads are not sent to OpenAI for field extraction. The facts below apply to historical processing and would apply to a future reviewed activation:
- The published API default says data is not used to train models. That is the default for the API, which is what we use — not the consumer chat product.
- The published default allows abuse-monitoring logs for up to 30 days. It is held for abuse monitoring, not for training or for resale.
- Sealinn’s project-specific data-control setting is not yet verified here. Modified abuse monitoring and zero-data-retention controls depend on endpoint eligibility and provider-side settings or approval. Until the owner records a current dashboard or API readback, assume the published default may apply and do not treat Sealinn as a zero-data-retention deployment.
One historical consequence is worth stating plainly: when automated reading previously ran, Sealinn sent an image of the document. A taxpayer number on a W-9 was visible in that transferred image even though Sealinn did not extract the number into its own fields. New W-9 uploads and automated reads are unavailable. Questions about historical processing can be sent to privacy@sealinn.com.
Where the data sits
Two places hold your data at rest. Both were checked against the running production system, not taken from a diagram:
- The database
- AWS us-east-1 (Northern Virginia, United States)
- Uploaded documents
- Cloudflare R2, Eastern North America (the ENAM location hint — a placement preference, not a guarantee)
The other providers on this list process data in transit or hold operational records rather than your documents. We have not printed a region for each of them, because we cannot verify those from here and a column filled in by assumption would be worth less than no column.
See also the privacy policy and how your records are kept separate.
Changes to this list
Before another provider starts handling your data we write to your workspace owner at least 30 days beforehand, naming it and saying what it receives — set out in section 5 of the data processing addendum. An email is not a record, though, so every change is dated here as well. If a new provider is a problem for your business, say so before the effective date.
August 1, 2026 — list first published
First publication of this list. Every provider covered by this entry was already in use when the list was published — nothing was added to make it, and nothing was left off it.
Vercel, Neon, Cloudflare R2, Clerk, OpenAI, Resend, Twilio, Upstash, Stripe, Railway, Sentry, PostHog
August 27, 2026 — planned
Advance disclosure only. Google Analytics is not active in production and receives no data: its production environment value remains empty. Activation requires the promised owner-notice window to elapse and the consent controls to pass staging verification.
Google Analytics
August 29, 2026 — purpose changed
Automated OpenAI extraction moved to inactive. New uploads are not sent to OpenAI; the provider remains listed for historical processing disclosure and any future reviewed activation.
OpenAI
September 2, 2026 — purpose changed
Product SMS moved to the reviewed disabled posture. No Twilio credential or sender binding is deployed, product SMS controls and sends are unavailable, and Twilio remains listed for historical disclosure and any future separately reviewed activation.
Twilio
Looking for a different document? They are all listed on the Legal page.
