Stetful
LegalTrustLegal contact

Security

Subprocessors and Security Disclosure

A factual initial-launch disclosure of Stetful's providers, security posture, and what we do not yet claim.

Documents

Legal

  • Terms
  • Privacy
  • Acceptable Use
  • AI Notice
  • Security
  • Changelog

Trust

  • Trust Principles

Document version

Effective
July 15, 2026
Updated
July 22, 2026
Service scope
U.S. business use

Contact routing

Use the right inbox.

  • Legal notices and terms questionslegal@stetful.com
  • Privacy, data protection, and data-rights requestsprivacy@stetful.com
  • Security reports and vulnerability disclosuressecurity@stetful.com

Effective date: July 15, 2026

Last updated: July 22, 2026

Short version

  • Stetful uses service providers to host, authenticate, store, process, secure, and operate the Service.
  • Application logging rules prohibit customer legal content, raw extracted text, source identity, filenames, and storage keys from broad logs; security and provider systems may still process bounded request data under their stated purposes.
  • Stetful does not use Customer Legal Content to train foundation models or third-party models. This no-training commitment is separate from provider retention for service delivery, abuse and security monitoring, support, or legal compliance.
  • Optional voice dictation sends raw audio transiently through Stetful to OpenAI for transcription. Stetful does not persist the recording or maintain a separate dictation transcript history.
  • This disclosure does not promise an SLA, DPA, data residency, certification, processor-only mode, zero data retention, or “eyes off” processing.
  • Report vulnerabilities to security@stetful.com.

1. Scope

This disclosure summarizes Stetful’s subprocessors and security posture for the initial U.S. launch. It is factual and modest. It is not a SOC 2 report, SLA, DPA, BAA, penetration-test report, or security certification.

2. Subprocessor list

ProviderPurposeData categoriesLocation / region notesAI training / retention notes
VercelHosting, deployment, runtime infrastructure for web and marketing appsRequest and response metadata, runtime data necessary to serve the app, deployment and build dataU.S. and global infrastructure; exact region variesNot an AI model provider. Application logging rules prohibit customer legal content in broad logs.
ClerkAuthentication, sessions, user and organization managementUser account data, email, authentication and session data, organization and role dataU.S. and global infrastructureNot an AI model provider.
Neon / PostgresOperational database and durable worker queueOperational records, Legal-State Data, metadata, review receipts, job metadataU.S. production configurationNot an AI model provider.
Cloudflare R2 or other S3-compatible object storageEvidence object storageUploaded evidence files, pre-account attachments, object metadataU.S. and global infrastructure; provider and region depend on production configurationNot an AI model provider. Object keys are tenant-scoped and opaque.
OpenAIOptional voice transcription, AI-assisted classification, extraction support, answer drafting, structured outputs, and related AI processingRaw audio submitted for dictation, transcript output, bounded inputs, extracted text where needed, other outputs, and request metadataProcessed according to configured API settingsAPI inputs and outputs are not used for model training by default. Default abuse-monitoring logs may retain content for up to 30 days; eligible approved controls can differ. Limited human review may occur for abuse, security, support, or legal purposes under provider controls. Stetful's transient handling does not override OpenAI's applicable retention settings.
GitHubSource control, CI, deployment and operations automationCode, configuration, CI logs, synthetic test data, repository metadataU.S. and global infrastructureCustomer legal content and secrets must not be placed in source control or CI logs.
Google Workspace / GmailInbound and outbound support, legal, privacy, and security communicationsEmail address, message contents, attachments intentionally sent to StetfulU.S. and global infrastructureDo not include unnecessary Customer Legal Content in email.

Provider names describe the current supported architecture and must be reverified against production configuration before activation and before material changes. “Other S3-compatible object storage” is not a promise that every listed alternative is active.

3. Security posture

Stetful’s initial security posture is built around minimum viable trust:

  • tenant boundaries for organization-scoped objects and role or capability checks for write and review surfaces;
  • tenant-scoped, opaque object-storage keys for uploaded evidence;
  • application logs and worker results designed to exclude customer legal content, raw extracted text, source identity, filenames, storage keys, tenant interpretations, accepted state, and operational conclusions;
  • source-redacted party-scoped presentation that does not reveal a contributing customer or artifact;
  • authorization that distinguishes a named contractual party from an unrelated third party;
  • proposed state changes that require company review before accepted state;
  • secrets kept in secret stores rather than committed to the repository;
  • tracked-file secret scanning and CI gates; and
  • a public vulnerability contact at security@stetful.com.

No system is perfectly secure. Provider infrastructure may process bounded request, security, and abuse-monitoring data under provider terms even where Stetful application logs exclude legal content.

4. What Stetful does not claim at initial launch

Unless separately true, agreed, operationally supported, and published, Stetful does not claim:

  • SOC 2, ISO 27001, HIPAA, FedRAMP, PCI DSS, or another certification or regulated-service status;
  • a penetration-test cadence, public bug-bounty program, uptime SLA, support SLA, recovery SLA, or deletion SLA;
  • a signed DPA, BAA, SCC package, processor-only mode, customer-managed keys, dedicated infrastructure, regional pinning, data residency, universal zero data retention, or “eyes off” provider processing;
  • that no service provider can ever access customer data; or
  • that the Service is perfectly secure, uninterrupted, or error-free.

Enterprise restrictions are separately negotiated overlays that narrow the standard customer profile. This page does not itself offer or promise those restrictions.

5. Vulnerability reporting

If you believe you found a vulnerability, contact security@stetful.com.

Please include enough information to help Stetful understand and reproduce the issue, but do not include unnecessary Customer Legal Content, secrets, personal data, or third-party confidential information.

Stetful does not authorize destructive testing, denial-of-service testing, social engineering, spam, physical attacks, or attempts to access another customer’s data.

6. Updates

Stetful will update this disclosure before adding a new subprocessor that materially processes customer legal content or before materially changing the AI-provider, storage, auth, hosting, or database posture.

© 2026 Stetful, Inc.

Legal
  • Terms
  • Privacy
  • Acceptable Use
  • AI Notice
  • Security
  • Changelog
Trust
  • Trust Principles

Contact

  • legal@stetful.com
  • privacy@stetful.com
  • security@stetful.com