Subprocessor List

Last updated

In plain English

  • These are the providers that help deliver the service, and what each one does.
  • Enterprise customers get at least 10 days notice before a new subprocessor handling Customer Personal Data is added.
  • AI model providers receive query content to generate responses, and are barred from training on it.
  • CourtListener and SEC EDGAR are public data sources. They hold no customer accounts and store no customer data.
  • All customer data is stored and processed in the United States.

This summary is here to help you find things. It is not the agreement. The full text below is what governs.

This page lists the service providers KillDebt uses to deliver its services, including KillDebt for Enterprise. It is referenced by the Data Processing Agreement, the Enterprise Terms, and the Privacy Policy.

For enterprise customers, KillDebt gives at least 10 days’ notice before adding a new subprocessor that processes Customer Personal Data. To receive notifications, email support@killdebt.com with the subject "Subprocessor notifications".

Core infrastructure

ProviderFunctionCertification / posture
Supabase (on AWS)Database and file storage; dedicated enterprise database projectSOC 2 Type II
VercelApplication hosting and deliverySOC 2 Type II; ISO 27001
StripePayment processing (KillDebt never receives card numbers)PCI DSS Level 1; SOC 2
ResendTransactional email (account and billing notices)SOC 2 Type II
UpstashRate limiting (short-lived request counters only)SOC 2 Type II
LangfuseService observability (query logs)SOC 2 Type II; ISO 27001
ActiveCampaignContact records (name, email, account status) for account lifecycle communicationsSOC 2

AI pipeline

Receives research query content and processes generation.

ProviderFunctionCertification / posture
AI model providers, routed through the Vercel AI Gateway: OpenAI, Anthropic, GoogleLanguage-model inferenceSOC 2 Type II (each); API inputs are not used to train models
CourtListener (Free Law Project)Case-law search and citation verificationNon-profit public legal data service
U.S. SEC EDGARPublic-company and debt-buyer filingsU.S. government public data source
Voyage AIText embeddings for semantic searchSOC 2 Type II

Document features

Engaged only when files are uploaded.

ProviderFunctionCertification / posture
Mistral AIDocument OCR (text extraction from uploaded PDFs and images)SOC 2 Type II; API inputs are not used to train models

Notes

CourtListener and U.S. SEC EDGAR are public data sources that receive research query content to execute searches; they do not host customer accounts or store customer data.

All customer data is stored and processed in the United States.

Questions about this document

Write to support@killdebt.com. KillDebt is a product of CollectionStopperMembership, LLC, Jacksonville, Florida.

All legal documents