Subprocessors
The third-party services ScrublyIQ uses to deliver the platform, what each one is used for, and the category of data it can receive. Every vendor is contractually bound to process data on ScrublyIQ’s behalf only. We do not sell merchant data.
Core Infrastructure and Platform Services
These services are always part of running ScrublyIQ. Bank-statement content is sent only to the AI extraction and document-parsing services (and, as a fallback, the backup extraction service listed below), never to the verification and enrichment services.
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Anthropic | AI processing | Bank statement text and statement page images | United States |
| Google Cloud Document AI | Statement OCR and bank-statement parsing | Bank statement pages and extracted text | United States |
| Supabase | Database and file storage | All merchant data | United States |
| Vercel | Hosting | All application traffic | United States |
| Upstash Redis | Rate limiting counters only | No merchant data | United States |
| Stripe | Billing | Broker payment only | United States |
| Clerk | Authentication | Broker identity only | United States |
| Resend | Transactional email to brokers and administrators | Broker email address, and the merchant business name in accidental-scan notifications | United States |
| Sentry | Error monitoring | Scrubbed of PII | United States |
| Axiom | Observability logs | Scrubbed of PII | United States |
| PostHog | Product and usage analytics | Broker feature-usage telemetry and pageviews. No merchant financial data | United States |
| Inngest | Background scan-job queue | Scan job payload: broker and organization ids, stored-file references, file hash, encrypted merchant name and location, and the referral lead source | United States |
Optional Verification and Enrichment Services
These services power optional business-verification and enrichment checks. They are controlled by a feature flag that is off by default. While the flag is off, no request is made to any of them and no data leaves ScrublyIQ for these purposes. When enabled, each service receives only the narrow data category shown, never bank-statement transactions, account numbers, or balances.
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| OFAC SDN API | Sanctions screening | Merchant name only | United States |
| Middesk | Business verification | Merchant name, EIN, address | United States |
| IRS TIN Matching | EIN and business-name match against IRS records | Merchant EIN and business name | United States |
| Smarty | Address validation | Merchant address only | United States |
| Google Places | Business lookup | Merchant name and address | United States |
| OpenCorporates | Business registration lookup | Merchant name and jurisdiction | United Kingdom |
| Melissa Data | Contact intelligence (email and phone risk) | Merchant owner email and phone | United States |
| UniCourt | Court-records search (bankruptcies, judgments, liens) | Merchant name only, as a case party | United States |
| Firecrawl | Backup statement extraction, used only when the primary parser cannot read a PDF | A short-lived signed link to the bank statement PDF | United States |
Keeping this list current
This list is maintained alongside our Privacy Policy and may change as services are added or removed. Questions: support@scrublyiq.com.