Phase 0 · Pre-launch. Attorney review pending. Commercial activity has not commenced.
SRAReady ← Back to site

Subprocessors

Last updated: July 2026

What this page is. SRAReady (a product of Ellis Intelligence LLC) engages the third parties below ("Subprocessors") to process Customer Data on our behalf in delivering the Service. This is the public disclosure required by our Data Processing Addendum ("DPA") §5.1, kept current as our stack changes.

Update cadence & your objection right

We review this list quarterly. Before we engage a new Subprocessor, we specifically inform affected customers in writing — by email to the account's designated contacts, or by in-product notice — with notice deemed given when sent, and we post the change here in addition to (not instead of) that written notice. Customers have 30 days from the date notice is given to object on reasonable data-protection grounds; a timely objection suspends our use of the new Subprocessor for that customer pending resolution, per DPA §5.3.

Current Subprocessors

SRAReady — current Subprocessor list
SubprocessorPurposeData accessedRegionNotes
Cloudflare, Inc.Edge, DNS, DDoS, WAF, Access gating, tunnel; marketing site on Cloudflare PagesNetwork metadata; request bodies in transit, not at restUS (global edge)
Fly.io, Inc.Production application hosting + database (Fly Volume holds the SQLite file)Tenant data in transit and at restUS (`iad` / Ashburn, VA)Launch gate: self-hosted pre-launch today; production hosting migrates to Fly.io before public launch.
Cloudflare R2 (via Litestream)Continuous SQLite backup → point-in-time restoreEncrypted copies of the tenant database fileUS (R2)Launch gate: continuous backup replication begins with the Fly.io cutover, before public launch.
Anthropic, PBC (a zero-data-retention arrangement will be verified in writing before first production processing)LLM inference for remediation guidance in Security Risk Assessments under HIPAASystem/process descriptions + control answers (yes/no/partial) — no ePHI, excluded by designUSno BAA required — an SRA evaluates safeguards, not patient data; no ePHI is created, received, maintained, or transmitted.
Stripe, Inc.Subscription billingBilling contact + tokenized payment methodUS
Resend Inc.Transactional emailRecipient address + message contentUS
Google LLC (Workspace)Our internal business emailOur internal email only; not customer-product dataUS
Subprocessors NOT used. The Service is architecturally designed to never process ePHI; see our Privacy Policy, "Information We Do Not Want."

Data Residency

All Subprocessors above maintain Customer Data at rest in the United States under our current configuration. Cloudflare and Anthropic operate global edge infrastructure for delivery, but data at rest stays U.S.-only under our contracts. Data at rest is stored in the United States. Fly.io production hosting and Cloudflare R2 backup replication are launch gates — required to be in place, U.S.-region-pinned, before public launch and before the first production customer.

Customers Outside the United States

We do not currently market to or onboard customers in jurisdictions that prohibit U.S. data processing under their data-protection law. Customers in the EU/EEA, UK, or Switzerland may onboard subject to the Standard Contractual Clauses ("SCCs") incorporated by reference into our DPA (together with the UK Addendum, for UK transfers).

Audit Rights

You may request a summary of our subprocessor-management practices by emailing [email protected]. SOC 2 Type I is planned; an auditor has not yet been engaged; our report will be available under NDA once complete. We do not permit direct audit of our Subprocessors; we share their relevant audit reports under NDA.

Contact Us

Ellis Intelligence LLC
Attn: Privacy & Security — SRAReady
Email: [email protected]

This list is referenced by, and generated in accordance with, our Data Processing Addendum.