Service providers we use
Sealinn runs on other companies’ infrastructure, the same as every tool you use. Here is the whole list, what each one does, and what it actually receives — routine disclosure, published rather than sent on request.
Last updated: August 1, 2026 · 12 providers · we give at least 30 days’ notice before adding another, and every change is logged below.
The list
| Provider | What it does | What it receives |
|---|---|---|
| Vercel | Runs the web application and serves every page | Everything you send or view through the browser passes through it in transit, plus request logs (IP address, page requested). |
| Neon | The Postgres database | All structured data at rest: your subcontractors, projects, requirements, the fields read off each document, and the audit log. |
| Cloudflare R2 | Stores the uploaded files themselves | Every document uploaded to your workspace — certificates, W-9s, licenses, safety cards — and the reports and archives you generate. |
| Clerk | Signs your team in | The name, email address and login credentials of people on your team. Never subcontractor documents. |
| OpenAI | Reads the fields off an uploaded document | An image of each document sent for extraction. See the section below — this is the one worth reading in full. |
| Resend | Sends email | The recipient's email address and the message: reminders, upload links, rejection notes. |
| Twilio | Sends text messages, where you have enabled them | The recipient's phone number and the message body. |
| Upstash | Job queue and rate limiting | Identifiers for work in progress — which document is being read, which reminder is queued. Not document contents. |
| Stripe | Takes payment | Your billing contact and payment details, which go to Stripe directly. We never see or store a card number. |
| Railway | Runs the background worker and the antivirus scanner | The same data as the application, for the work that happens outside a request: reading documents, sending reminders, generating reports. |
| Sentry | Error monitoring | Diagnostic detail when something breaks — the error, the page, and identifiers for the workspace and user involved. |
| PostHog | Product analytics | Which pages are used and which actions are taken, tied to a user and workspace identifier. Not document contents. |
What happens when AI reads a certificate
This is the part most people want to know and most vendors skip, so here it is in full. When a document is uploaded, Sealinn sends an image of it to OpenAI to read the fields off it. Three things are true about that, and all three come from OpenAI’s published API policy rather than from us:
- Your documents are not used to train their models. That is the default for the API, which is what we use — not the consumer chat product.
- They keep a copy for up to 30 days, then delete it. It is held for abuse monitoring, not for training or for resale.
- We do not have zero-data-retention in place. It exists, it has to be applied for and approved, and we have not been approved, so we are not going to imply otherwise. If that changes this page changes with it.
One consequence worth stating plainly rather than leaving you to work out: we send an image of the document. So even though Sealinn deliberately never reads or stores a taxpayer number off a W-9 — it records only that one is present — the number is visible in the image we transmit. If that is a problem for a document you were about to upload, do not upload it, and privacy@sealinn.com will get a real answer from a person.
Where the data sits
Two places hold your data at rest. Both were checked against the running production system, not taken from a diagram:
- The database
- AWS us-east-1 (Northern Virginia, United States)
- Uploaded documents
- Cloudflare R2, Eastern North America (the ENAM location hint — a placement preference, not a guarantee)
The other providers on this list process data in transit or hold operational records rather than your documents. We have not printed a region for each of them, because we cannot verify those from here and a column filled in by assumption would be worth less than no column.
See also the privacy policy and how your records are kept separate.
Changes to this list
Before another provider starts handling your data we write to your workspace owner at least 30 days beforehand, naming it and saying what it receives — set out in section 5 of the data processing addendum. An email is not a record, though, so every change is dated here as well. If a new provider is a problem for your business, say so before the effective date.
August 1, 2026 — list first published
First publication of this list. Every provider named above was already in use when the list was published — nothing was added to make it, and nothing was left off it.
All providers listed above.
Looking for a different document? They are all listed on the Legal page.
