The vendors in the loop
Quordo relies on a small, defined set of sub-processors to run the service. This is the current list — the same one your own vendor-risk assessment should start from. We keep it honest and current, and we give notice of material changes as our agreements require.
Supabase
Primary database, authentication, and file storage.
Data handled: Account data (names, work emails, hashed passwords), organization and team membership, and the estate data customers connect (usage, cost, missions, traces), isolated per organization with row-level security.
Processing region: United States or EU, depending on the hosted tenant region.
DigitalOcean
Cloud compute and hosting for the Quordo application and workers.
Data handled: Application traffic and any personal data in transit while requests are served; no separate long-term store of customer data beyond operational logs.
Processing region: United States or EU, depending on the deployment region.
Stripe
Subscription billing and payment processing.
Data handled: Company billing details and a tokenised payment reference. Quordo never stores full card numbers.
Processing region: United States, with global processing under Stripe's safeguards.
Resend
Transactional email (sign-in, invitations, and account notices).
Data handled: Recipient work email address and the contents of the transactional message. Not used for marketing without separate consent.
Processing region: United States.
PostHog
Product analytics — understanding which features help and where users get stuck. Loads only with consent where required.
Data handled: A pseudonymous identifier, page and feature events, browser type, and approximate region from IP. No provider credentials or estate content.
Processing region: EU Cloud (EU-hosted).
Sentry
Error monitoring — capturing JavaScript and backend errors so we can fix bugs. Loads only with consent where required.
Data handled: Stack traces, the page URL, browser type, and a pseudonymous session identifier. No provider credentials or estate data.
Processing region: United States, with an EU data region option.
AI providers
The providers a customer connects on the Spend surface — OpenAI, Anthropic, Azure OpenAI, Amazon Bedrock, and Google Vertex — queried with the credentials the customer supplies.
Data handled: Only the requests needed to read usage and cost data using the customer's own credentials. Estate content is not sent to a provider the customer did not connect.
Processing region: United States or the region of the customer's own provider account; each provider applies its own safeguards.
Keeping this list current
We update this list when we add, remove, or change a sub-processor. Under a signed Data Processing Agreement, we give affected customers a reasonable opportunity to object to a new sub-processor before it starts processing their data. The full commitments live in our Privacy Policy and our DPA template — email [email protected] with any questions.