Trust Center
Subprocessors and Service Providers
The provider categories used by Caseflow, the purposes they support, and the optional integrations customers may direct us to use.
Trust Center
Subprocessors and Service Providers
The provider categories used by Caseflow, the purposes they support, and the optional integrations customers may direct us to use.
Last updated: August 28, 2026
1. Core Subprocessors
- Google Cloud and Firebase (applicable Google contracting entity): hosting, authentication, Firestore database, file storage, Cloud Functions, App Check/reCAPTCHA, logging, security, and Google Cloud Vision OCR. Core functions are currently configured in us-central1; storage location follows the Firebase project configuration.
- OpenAI (applicable OpenAI contracting entity): AI generation, extraction, embeddings, document intelligence, transcription, and speech for user-invoked AI features. Processing location and retention depend on the approved API project configuration.
- Amazon Web Services (applicable AWS contracting entity): outbound email through SES and inbound email payload handling through S3. Current SES and inbound S3 defaults are eu-central-1.
- Stripe (applicable Stripe contracting entity): checkout, subscription management, payment processing, invoices, fraud prevention, and hosted billing portal.
2. Customer-Directed and Optional Providers
- Google Gmail / Google OAuth: connected mailbox access, message sending, and token management when a user connects Google email.
- Zoho Corporation and affiliates: Zoho Mail and Zoho Books OAuth integrations, email operations, accounting metadata, invoices, bills, and related synchronization.
- Meta Platforms / WhatsApp Cloud API: approved notification and support message delivery when configured.
- Sinch or Phaxio: fax transmission, receipt, status, telephone identifiers, and document delivery when the configured fax feature is used.
- Web-push endpoint providers: delivery of browser notifications to the push endpoint selected by the user’s browser or operating system.
3. Changes and Objections
Core providers may use their own subprocessors. Where a customer has a Data Processing Addendum with general authorization for subprocessors, Caseflow will provide notice of a new core subprocessor before it processes Customer Personal Data when reasonably practicable. A customer may object on reasonable data-protection grounds through support; the parties will work in good faith on a commercially reasonable solution.
4. Transfers and Due Diligence
Provider locations can change and some providers operate globally. Transfer safeguards, data residency, security documentation, and regulated-data eligibility must be confirmed for the customer’s actual deployment and enabled features. Inclusion on this list is not a certification that a provider is suitable for every category of regulated data.