| Clerk, Inc. | User authentication, sign-in and session management | Email, name, sign-in events and session identifiers | International processing under provider contractual safeguards |
| Vercel, Inc. | Application delivery, serverless API runtime and deployment previews | Request metadata and application data processed in transit | Configured regions; international transfers under provider safeguards |
| Supabase, Inc. | Managed PostgreSQL database and object storage | Tenant application data and stored files | London, United Kingdom (eu-west-2) |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing where enabled | Billing contact, plan and payment metadata; Journey does not store card numbers | Ireland / EEA |
| Resend, Inc. | Transactional email, including invitations and notifications | Recipient address, message content and delivery events | International processing under provider contractual safeguards |
| Anthropic, PBC | Legacy compatibility processor; not active unless an operator explicitly enables the disabled compatibility runtime | No processing by default; bounded authorised prompt content only if the legacy compatibility runtime is explicitly activated | United States; international transfers under provider safeguards |
| OpenAI, L.L.C. | Advance-only governed AI assistance for authorised evidence and feedback drafts and K/S suggestions, after provider, DPIA and release approval | Bounded authorised workflow content; pattern-based redaction is applied where direct identifiers are detected but cannot guarantee all personal data is removed; credentials, payment data, raw signatures and document bytes are excluded | Provider-configured processing under the applicable provider terms and contractual safeguards |
| Functional Software, Inc. (Sentry) | Operational application error, performance and replay diagnostics | Authenticated account, tenant, role, workflow, release, request/session and bounded replay context; credentials, tokens, payment-card data, raw signatures and document bytes are excluded | Provider-configured processing under contractual safeguards |
| PostHog, Inc. | Consent-based product analytics and session diagnostics | After consent: authenticated account, tenant, role, workflow, release, request/session, interaction and bounded replay context; credentials, tokens, payment-card data, raw signatures and document bytes are excluded | European Union cloud endpoint |
| Google LLC | Consent-based analytics and optional Google sign-in | Analytics events after consent; identity data when Google sign-in is chosen | International processing under provider contractual safeguards |
| Cloudflare, Inc. | DNS, domain security and edge protection | Network and request metadata | Global network under provider contractual safeguards |