Provider evidence, not a finished legal register.

The table is limited to providers whose production use is stated by current repository product context. It does not invent processing locations, DPA status or complete data-flow scope.

Production-use evidence requiring legal and deployment confirmation
ProviderPurpose evidenced in repositoryVerification boundary
SupabaseShared database, authentication and backend servicesProduction platform use is stated in current product context; region and contract terms remain unverified
TwilioSMS and communications infrastructureCurrent product context identifies Twilio in active messaging flows; exact production channel scope and contract detail remain unverified
ElevenLabsAI outbound calling and conversational voiceOutbound calling is recorded as verified live; retention and contract detail remain unverified

Corporate website delivery path

When the corporate contact forms are enabled in production, Vercel will host and execute the form endpoint and Brevo will deliver the submitted enquiry to an approved Chatur Systems mailbox. This is implemented but not presented as an active production flow until deployment, processor terms and transfer safeguards are verified.

Not presented as active product subprocessors

Stripe, OpenAI and Brevo have implemented product code or configuration, but their current production data-flow status is not conclusively recorded in the evidence reviewed. Sentry is explicitly unconfigured. Apple, Google and Expo/EAS relate to partial mobile distribution work. None is added to the public product register until deployment and contractual facts are confirmed.

A legal register needs contract facts.

Locations, data categories, DPAs, SCCs and dates added remain approval inputs.