Subprocessors
Every third party that handles RigorMD data, what it does, and the terms it is held to. Published so a procurement review can start here instead of with an email.
§01 The list
10 subprocessors. 4 of them can see manuscript content; the rest handle accounts, payments, hosting, delivery, or diagnostics. Who sees a report inside RigorMD is a separate question, answered on Security & confidentiality.
| Subprocessor | What it does | Manuscript content | Terms in force |
|---|---|---|---|
| Anthropic | One of the two independent appraisal engines, via the commercial API | Yes | DPA and standard contractual clauses incorporated into the Commercial Terms |
| OpenAI | The second independent appraisal engine, via the commercial API | Yes | Executed DPA (countersigned), EU Commission 2021 SCCs Module Two, UK Addendum; EEA and Swiss data contracted with OpenAI Ireland Ltd |
| Cloudflare (R2) | Object storage for manuscript files, processing artifacts, and reports | Yes | DPA forming part of the subscription agreement, SCCs Modules 2 and 3, UK addendum |
| Northflank | Application workers and the managed Postgres database | Yes | DPA auto-incorporated by use, with sub-processor flow-down, breach notification, and audit rights; transfers are a commitment to maintain appropriate safeguards rather than an attached SCC module. Our services and database run in Northflank's US East region |
| Clerk | Authentication and organization accounts | No | DPA incorporated into the agreement, SCCs Modules 1/2/3, UK addendum, and an Australian Privacy Principles addendum |
| Stripe | Payment processing — card details never reach RigorMD systems | No | DPA forming part of the agreement, SCCs via the Data Transfers Addendum, UK IDTA. Stripe is our processor for payment handling and an independent controller for its own fraud and compliance duties |
| Vercel | Web hosting for the marketing site and application | No | DPA applying automatically on our plan, 2021 SCCs (all modules), UK IDTA |
| Resend | Transactional email — content-free report-ready and lifecycle notices | No | DPA binding on entering the agreement, SCCs Modules 1/2/3, plus Swiss terms |
| Sentry | Error monitoring — technical diagnostics and timing only | No | DPA accepted by us in-product, SCCs, UK addendum |
| Plausible Analytics | Cookieless, aggregate visit measurement on the public marketing pages only — never loaded on a dashboard, submission, or report page | No | DPA accepted by use. Hosted in the EU (Germany), so no international transfer occurs and no transfer mechanism is required |
§02 Notice before the list changes
Before a new subprocessor begins handling customer data, or an existing one is replaced, we publish the change here and notify institutional customers at least 30 days in advance. Each version of this page is dated and numbered above, so you can tell at a glance whether the list you reviewed is the list in force. If a change is unacceptable to you, tell us before it takes effect and we will work out the alternative — including ending the agreement and refunding unused service — rather than proceeding over your objection.
To be told directly rather than checking the page, write to support@abigailmd.com and ask to be added to subprocessor change notices.
§03 Deliberately not on this list
Crossref, NCBI, the DOI Foundation. Reference verification sends a bare DOI or PMID to a public registry and reads back the record. No manuscript text, no personal data, and no user identifier travels that path, so these are public lookups rather than subprocessors acting on our behalf. We list them on Privacy for completeness and name them here so the omission is deliberate rather than an oversight.