Compliance / Subprocessors / Last updated July 1, 2026
Subprocessors
These are the third-party providers Five Star Solutions uses or plans to use to run the platform. Some providers are always in the platform path; others are used only when a customer enables a channel, identity provider, or connected tool.
Platform subprocessors
| Provider | Role and data |
|---|---|
| Cloudflare | Hosts the public/app Worker, protects the web edge, runs Turnstile, and may deliver login email. PHI workloads require confirmed BAA scope for Cloudflare services in the request path. |
| Amazon Web Services | Runs AI/document services through HIPAA-eligible services such as Bedrock and Textract, and stores WORM audit exports in S3 Object Lock. |
| Supabase | Provides Postgres, Auth, Vault, realtime, and storage primitives. Customer account data, tenant data, encrypted secrets, and agent memory live here. |
| Trigger.dev | Runs scheduled and triggered operator tasks and stores task/run state. PHI workloads require Trigger.dev HIPAA infrastructure and a signed BAA before PHI is sent through tasks. |
| Composio | Connects and executes customer tools for non-PHI organizations. Composio is blocked from PHI connector paths unless a future BAA-covered route is verified. |
| Nango | The planned connector path for PHI organizations and connector gaps, after Nango Enterprise/BAA is contracted and each provider key is allowlisted for PHI. |
Customer-directed services
| Service | When it is used |
|---|---|
| Google OAuth | Used only when a user chooses Google sign-in. Google handles that identity flow under its own terms. |
| Connected client tools | Examples include email, spreadsheets, CRMs, accounting tools, and booking systems. We access them only when the customer connects them and within configured scope. |
| Messaging channels | Slack and Telegram can be configured for operator conversations and OTP delivery paths when covered by the needed vendor terms. |
PHI rule
PHI does not flow through a provider just because that provider appears on this page. PHI workloads require a customer BAA, signed subprocessor BAAs or confirmed BAA scope, and a provider allowlist for the specific connector involved.