Skip to content

Compliance / Subprocessors / Last updated July 1, 2026

Subprocessors

These are the third-party providers Five Star Solutions uses or plans to use to run the platform. Some providers are always in the platform path; others are used only when a customer enables a channel, identity provider, or connected tool.

Platform subprocessors

Provider Role and data
Cloudflare Hosts the public/app Worker, protects the web edge, runs Turnstile, and may deliver login email. PHI workloads require confirmed BAA scope for Cloudflare services in the request path.
Amazon Web Services Runs AI/document services through HIPAA-eligible services such as Bedrock and Textract, and stores WORM audit exports in S3 Object Lock.
Supabase Provides Postgres, Auth, Vault, realtime, and storage primitives. Customer account data, tenant data, encrypted secrets, and agent memory live here.
Trigger.dev Runs scheduled and triggered operator tasks and stores task/run state. PHI workloads require Trigger.dev HIPAA infrastructure and a signed BAA before PHI is sent through tasks.
Composio Connects and executes customer tools for non-PHI organizations. Composio is blocked from PHI connector paths unless a future BAA-covered route is verified.
Nango The planned connector path for PHI organizations and connector gaps, after Nango Enterprise/BAA is contracted and each provider key is allowlisted for PHI.

Customer-directed services

Service When it is used
Google OAuth Used only when a user chooses Google sign-in. Google handles that identity flow under its own terms.
Connected client tools Examples include email, spreadsheets, CRMs, accounting tools, and booking systems. We access them only when the customer connects them and within configured scope.
Messaging channels Slack and Telegram can be configured for operator conversations and OTP delivery paths when covered by the needed vendor terms.

PHI rule

PHI does not flow through a provider just because that provider appears on this page. PHI workloads require a customer BAA, signed subprocessor BAAs or confirmed BAA scope, and a provider allowlist for the specific connector involved.