Sub-Processor Registry
Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21 · Purpose: the customer-facing disclosure register that attaches to the BAA flow-down. Because the deployed environment carries synthetic data only, the PHI columns below describe gated exposure, not current processing.
1. Current processing vendors (deployed, synthetic environment)
| Vendor | Purpose | Data today | Location |
|---|---|---|---|
| Google Cloud | Cloud Run compute, Cloud SQL database, storage, Secret Manager, Vertex AI (investor-room agent) | Synthetic corpus, application data, diligence content | United States |
| Cloudflare | DNS and selected public or static delivery | Public content only | Global edge |
| GitHub | Source code hosting and CI | Source code, no PHI | United States |
2. PHI-contingent vendors (gated behind real-data activation)
These vendor classes process regulated data only after the real-data gates pass and the applicable agreement is executed. Execution status is stated only with the signed document on file.
| Vendor class | Purpose | Data if activated | Gate |
|---|---|---|---|
| Cloud provider (Google Cloud) | PHI storage and compute | PHI at rest and in transit | Cloud BAA on HIPAA-covered services |
| AI model providers | Extraction, drafting, agent workflows | Minimized credential metadata | Provider BAA plus the 06.5 configuration, minimization, and logging gates |
| Identity verification | Government-ID identity proofing | Identity documents, PII | BAA or equivalent before real workers onboard |
| Background screening | Background checks where required | PII and screening data | BAA plus counsel review of the FCRA workflow |
| Enterprise SSO | Customer SSO federation | Organization user identity | Contract review; BAA if scope includes PHI |
| Communications (email, SMS) | Workflow notifications | Contact details; PHI excluded by design | BAA before any PHI-bearing content |
| Error tracking | Application faults | Scrubbed frames only | Scrub verification as a real-data gate |
| Billing | Invoicing | Billing metadata only, never PHI | No BAA required by design |
3. Source authorities (not sub-processors)
Primary sources and registries (practitioner data banks, licensure systems, exclusion lists, certification boards) are verification destinations, not processors of customer data on Rōvn's behalf. Rōvn queries them under their own terms, preserves the response as a Source Receipt, and labels the evidence class accordingly.
- Adapter states vary: registered, contract-ready, sandbox, and live transport-proven are different states.
- A source is described as live only with contract, credentials, allowed-use review, and current transport proof.
- Where automation is not live, manual primary source verification is the documented fallback.
4. Customer disclosure language (template)
Rōvn engages the sub-processors disclosed in this register to perform services on the customer's behalf. Rōvn maintains a Business Associate Agreement or equivalent with each PHI-touching sub-processor before PHI reaches it. The customer may raise objections to specific sub-processors, subject to feasibility, via legal@rovn.to.
Rōvn provides 30 days' advance notice of material changes to this register: addition of a PHI-touching sub-processor, a change in jurisdiction, or termination of a vendor agreement.
5. Review cadence
The register is reviewed quarterly with outside counsel. Changes are logged in the audit ledger, communicated per the disclosure language above, and reflected in the vendor BAA matrix (06.4) and the flow-down narrative (08.11).
End of sub-processor registry.