Subprocessors

The third-party services ScrublyIQ uses to deliver the platform, what each one is used for, and the category of data it can receive. Every vendor is contractually bound to process data on ScrublyIQ’s behalf only. We do not sell merchant data.

Core Infrastructure and Platform Services

These services are always part of running ScrublyIQ. Bank-statement content is sent only to the AI extraction and document-parsing services (and, as a fallback, the backup extraction service listed below), never to the verification and enrichment services.

ServicePurposeData SharedLocation
AnthropicAI processingBank statement text and statement page imagesUnited States
Google Cloud Document AIStatement OCR and bank-statement parsingBank statement pages and extracted textUnited States
SupabaseDatabase and file storageAll merchant dataUnited States
VercelHostingAll application trafficUnited States
Upstash RedisRate limiting counters onlyNo merchant dataUnited States
StripeBillingBroker payment onlyUnited States
ClerkAuthenticationBroker identity onlyUnited States
ResendTransactional email to brokers and administratorsBroker email address, and the merchant business name in accidental-scan notificationsUnited States
SentryError monitoringScrubbed of PIIUnited States
AxiomObservability logsScrubbed of PIIUnited States
PostHogProduct and usage analyticsBroker feature-usage telemetry and pageviews. No merchant financial dataUnited States
InngestBackground scan-job queueScan job payload: broker and organization ids, stored-file references, file hash, encrypted merchant name and location, and the referral lead sourceUnited States

Optional Verification and Enrichment Services

These services power optional business-verification and enrichment checks. They are controlled by a feature flag that is off by default. While the flag is off, no request is made to any of them and no data leaves ScrublyIQ for these purposes. When enabled, each service receives only the narrow data category shown, never bank-statement transactions, account numbers, or balances.

ServicePurposeData SharedLocation
OFAC SDN APISanctions screeningMerchant name onlyUnited States
MiddeskBusiness verificationMerchant name, EIN, addressUnited States
IRS TIN MatchingEIN and business-name match against IRS recordsMerchant EIN and business nameUnited States
SmartyAddress validationMerchant address onlyUnited States
Google PlacesBusiness lookupMerchant name and addressUnited States
OpenCorporatesBusiness registration lookupMerchant name and jurisdictionUnited Kingdom
Melissa DataContact intelligence (email and phone risk)Merchant owner email and phoneUnited States
UniCourtCourt-records search (bankruptcies, judgments, liens)Merchant name only, as a case partyUnited States
FirecrawlBackup statement extraction, used only when the primary parser cannot read a PDFA short-lived signed link to the bank statement PDFUnited States

Keeping this list current

This list is maintained alongside our Privacy Policy and may change as services are added or removed. Questions: support@scrublyiq.com.