← Back to Trust Center

Sub-processors.

Sub-processors are third parties Evenhand engages to deliver the platform. Each is bound by a written agreement that imposes data-protection obligations substantially equivalent to those Evenhand owes its customers. This list is the same registry referenced by Privacy Policy §5 and Data Processing Addendum Annex 3.

Change notification.

Evenhand posts at least thirty (30) days' prior notice before adding or replacing a sub-processor. For Brokerages with an executed DPA, notice is also delivered by email to the contact on file. Until the in-product notification subscription form is published, customers who want change notifications should email legal@evenhandhq.com to be added to the notification list.

Current sub-processors (13).

ProviderPurposeData categoriesLocation
Clerk, Inc.
Privacy policy
Authentication, account management, session management, multi-factor authentication, organization membershipEmail, name, hashed password, MFA credentials, session tokens, organization membershipUnited States
Neon, Inc. (on AWS)
Privacy policy
Database hosting (PostgreSQL)All Platform data stored in the databaseAWS US-West-2 (Oregon, USA)
Vercel Inc.
Privacy policy
Application hosting, content delivery, preview deploymentsIP address, request logs, application code and assets, security/bot-protection cookiesUnited States (global edge network)
Anthropic, PBC
Privacy policy
AI-assisted PDF extraction and CSV/XLSX column mappingContents of uploaded financial documents (PDF) and structured-data column headers / sample rows submitted to the extraction APIUnited States
Stripe, Inc.
Privacy policy
Payment processing, subscription management, invoicingName, email, billing address, payment method details (held by Stripe), transaction history, subscription stateUnited States
Resend, Inc.
Privacy policy
Transactional email delivery (outbound) and inbound email parsing (per-broker marketplace-inquiry forwarding addresses and per-buyer pipeline-capture forwarding addresses, ADR 0008)Outbound: recipient email address, email subject and content, delivery metadata. Inbound: sender address, subject, body, headers, and any attachments of emails forwarded to platform-minted forwarding addresses (retained on Resend only during webhook delivery; body bytes streamed via the Receiving API and stored in the platform's own Vercel Blob private store)United States
Sentry (Functional Software, Inc.)
Privacy policy
Error tracking and application monitoringIP address (anonymized), browser/OS info, error stack traces, scrubbed application state, user ID for error attributionUnited States
PostHog, Inc.
Privacy policy
Product analytics (cookieless mode)Anonymized usage events, page views, feature interactions, device / browser typeUnited States
Cloudflare, Inc.
Privacy policy
DNS management, DDoS protection, edge security, Turnstile bot detectionDNS query data, IP address for security filtering, Turnstile challenge metadataGlobal edge network
Upstash, Inc.
Privacy policy
Distributed rate limitingIP address, action identifier, timestampUnited States / global
Better Stack
Privacy policy
Uptime monitoring and status pageMonitoring endpoint URLs, response metadata; no User data is transmittedUnited States
Dropbox Sign (HelloSign, Dropbox, Inc.)
Privacy policy
E-signature for click-through NDAs, LOIs, and purchase agreements (Evenhand-managed and BYO modes)Signer name, email, IP address at signature time, document content for signing, signed PDFUnited States
DocuSign, Inc.
Privacy policy
E-signature (BYO mode)Same as Dropbox SignUnited States / region per Brokerage's DocuSign account

User-authorized integrations.

These providers process information only when you (or your Brokerage) expressly connect them. They operate under your direct relationship with them. Evenhand acts as the bridge; the third party's own privacy policy and terms govern their use of your data.

ProviderPurposeWhen activated
Google LLC (Calendar API)Calendar event creation and read for closing-timeline integrationUser connects Google Calendar in profile settings
Microsoft Corporation (Microsoft Graph)Calendar event creation and readUser connects Microsoft 365 Calendar
Intuit Inc. (QuickBooks Online)Read-only accounting snapshots for QoESeller authorizes QBO connection for a Deal
Xero LimitedRead-only accounting snapshots for QoESeller authorizes Xero connection for a Deal
Oracle NetSuiteRead-only accounting snapshots for QoESeller authorizes NetSuite connection for a Deal
Firmex Inc.Virtual data room document storageBrokerage configures Firmex as the document-storage adapter
iDeals Solutions GroupVirtual data room document storageBrokerage configures iDeals as the document-storage adapter
Google LLC (Drive API)Document storage in your Google DriveBrokerage or Deal owner configures Google Drive
Dropbox, Inc. (Dropbox Business)Document storage in your Dropbox Business accountBrokerage or Deal owner configures Dropbox Business
DocuSign / Dropbox Sign (BYO)E-signature using your own accountBrokerage connects its own e-signature account

Customer-configured webhook recipients.

If a Brokerage configures an outbound webhook endpoint, Evenhand transmits event payloads to that endpoint at the Brokerage's direction. The operator of the endpoint is not an Evenhand sub-processor; the Brokerage is responsible for the security and data-protection posture of any endpoint it configures.