Service providers we use

Sealinn runs on other companies’ infrastructure, the same as every tool you use. Here is the whole list, what each one does, and what it actually receives — routine disclosure, published rather than sent on request.

Last updated: August 1, 2026 · 12 providers · we give at least 30 days’ notice before adding another, and every change is logged below.

The list

ProviderWhat it doesWhat it receives
VercelRuns the web application and serves every pageEverything you send or view through the browser passes through it in transit, plus request logs (IP address, page requested).
NeonThe Postgres databaseAll structured data at rest: your subcontractors, projects, requirements, the fields read off each document, and the audit log.
Cloudflare R2Stores the uploaded files themselvesEvery document uploaded to your workspace — certificates, W-9s, licenses, safety cards — and the reports and archives you generate.
ClerkSigns your team inThe name, email address and login credentials of people on your team. Never subcontractor documents.
OpenAIReads the fields off an uploaded documentAn image of each document sent for extraction. See the section below — this is the one worth reading in full.
ResendSends emailThe recipient's email address and the message: reminders, upload links, rejection notes.
TwilioSends text messages, where you have enabled themThe recipient's phone number and the message body.
UpstashJob queue and rate limitingIdentifiers for work in progress — which document is being read, which reminder is queued. Not document contents.
StripeTakes paymentYour billing contact and payment details, which go to Stripe directly. We never see or store a card number.
RailwayRuns the background worker and the antivirus scannerThe same data as the application, for the work that happens outside a request: reading documents, sending reminders, generating reports.
SentryError monitoringDiagnostic detail when something breaks — the error, the page, and identifiers for the workspace and user involved.
PostHogProduct analyticsWhich pages are used and which actions are taken, tied to a user and workspace identifier. Not document contents.

What happens when AI reads a certificate

This is the part most people want to know and most vendors skip, so here it is in full. When a document is uploaded, Sealinn sends an image of it to OpenAI to read the fields off it. Three things are true about that, and all three come from OpenAI’s published API policy rather than from us:

  • Your documents are not used to train their models. That is the default for the API, which is what we use — not the consumer chat product.
  • They keep a copy for up to 30 days, then delete it. It is held for abuse monitoring, not for training or for resale.
  • We do not have zero-data-retention in place. It exists, it has to be applied for and approved, and we have not been approved, so we are not going to imply otherwise. If that changes this page changes with it.

One consequence worth stating plainly rather than leaving you to work out: we send an image of the document. So even though Sealinn deliberately never reads or stores a taxpayer number off a W-9 — it records only that one is present — the number is visible in the image we transmit. If that is a problem for a document you were about to upload, do not upload it, and privacy@sealinn.com will get a real answer from a person.

Where the data sits

Two places hold your data at rest. Both were checked against the running production system, not taken from a diagram:

The database
AWS us-east-1 (Northern Virginia, United States)
Uploaded documents
Cloudflare R2, Eastern North America (the ENAM location hint — a placement preference, not a guarantee)

The other providers on this list process data in transit or hold operational records rather than your documents. We have not printed a region for each of them, because we cannot verify those from here and a column filled in by assumption would be worth less than no column.

See also the privacy policy and how your records are kept separate.

Changes to this list

Before another provider starts handling your data we write to your workspace owner at least 30 days beforehand, naming it and saying what it receives — set out in section 5 of the data processing addendum. An email is not a record, though, so every change is dated here as well. If a new provider is a problem for your business, say so before the effective date.

  1. August 1, 2026 list first published

    First publication of this list. Every provider named above was already in use when the list was published — nothing was added to make it, and nothing was left off it.

    All providers listed above.

Looking for a different document? They are all listed on the Legal page.