Provider evidence, not a finished legal register.
The table is limited to providers whose production use is stated by current repository product context. It does not invent processing locations, DPA status or complete data-flow scope.
| Provider | Purpose evidenced in repository | Verification boundary |
|---|---|---|
| Supabase | Shared database, authentication and backend services | Production platform use is stated in current product context; region and contract terms remain unverified |
| Twilio | SMS and communications infrastructure | Current product context identifies Twilio in active messaging flows; exact production channel scope and contract detail remain unverified |
| ElevenLabs | AI outbound calling and conversational voice | Outbound calling is recorded as verified live; retention and contract detail remain unverified |
Corporate website delivery path
When the corporate contact forms are enabled in production, Vercel will host and execute the form endpoint and Brevo will deliver the submitted enquiry to an approved Chatur Systems mailbox. This is implemented but not presented as an active production flow until deployment, processor terms and transfer safeguards are verified.
Not presented as active product subprocessors
Stripe, OpenAI and Brevo have implemented product code or configuration, but their current production data-flow status is not conclusively recorded in the evidence reviewed. Sentry is explicitly unconfigured. Apple, Google and Expo/EAS relate to partial mobile distribution work. None is added to the public product register until deployment and contractual facts are confirmed.
A legal register needs contract facts.
Locations, data categories, DPAs, SCCs and dates added remain approval inputs.