Полный текст этого руководства на английском языке; краткое изложение выше — на вашем языке. Изложения законов и английский текст остаются источником записи.
Все поставщики
The authorized subprocessors are the providers that are always on, and those a firm or account holder connects. Dormant providers are wired into the code but carry no configuration and receive no data. This list is the one the data processing addendum refers to.
| Provider | Purpose | Status | On this deployment |
|---|---|---|---|
| Supabase | Database, sign-in and private file storage | Always on | Configured |
| Vercel | Hosting, content delivery, server functions and privacy-preserving web analytics | Always on | No configuration needed |
| Anthropic | Model provider for firm-staff generative features and for structured extraction | Always on | Configured |
| Square | Payments: checkout, subscriptions and payment events | Always on | Configured |
| Resend | Outbound transactional email | Always on | Configured |
| ImprovMX | Forwarding of mail sent to TrusteeClear's published addresses | Always on | No configuration needed |
| Plaid | Bank-account connections for ledger feeds | Enabled when a firm or account holder connects it | Not configured |
| Clio | Practice-management sync for firms that connect it | Enabled when a firm or account holder connects it | Not configured |
| Google Calendar | Calendar sync for people who connect it | Enabled when a firm or account holder connects it | Not configured |
| Microsoft calendar (Graph) | Calendar sync for people who connect it | Enabled when a firm or account holder connects it | Not configured |
| DocuSign | Electronic-signature provider for firms that connect it | Enabled when a firm or account holder connects it | Not configured |
| Microsoft Office add-in platform | Hosts the Word and Outlook add-ins inside Office | Enabled when a firm or account holder connects it | No configuration needed |
| EstateDraftFL (sister platform) | Membership codes issued with an EstateDraftFL purchase | Dormant | Not configured |
| Stripe | Former payment rail, kept dormant | Dormant | Not configured |
| OpenAI | Retained code path for a second model provider | Dormant | Not configured |
| Twilio | Text-message reminders | Dormant | Not configured |
| Postmark | Alternative outbound email sender | Dormant | Not configured |
Supabase
- Purpose
- Database, sign-in and private file storage
- Data
- Account identities (email address)
- Matter records, ledgers and audit records
- Uploaded documents
- Region
- United States
- Status
- Always on; configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Row-level security on every table
- Private storage with signed, matter-scoped access
- Privileged credentials used only on the server
Vercel
- Purpose
- Hosting, content delivery, server functions and privacy-preserving web analytics
- Data
- Request metadata such as IP address and browser
- Operational logs that carry markers and codes, not document text
- Anonymous page-view and speed measurements
- Region
- United States
- Status
- Always on
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Security headers and a content-security policy on every response
- Production variables held in the platform, never in source
Anthropic
- Purpose
- Model provider for firm-staff generative features and for structured extraction
- Data
- Document text and matter facts sent for the requested operation
- Region
- United States
- Status
- Always on; configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- The provider's terms prohibit training on this data; retention follows its API terms
- Generative use only behind a firm-staff session
- A monthly spend ceiling that fails closed
Square
- Purpose
- Payments: checkout, subscriptions and payment events
- Data
- Payer name and email address
- Order amounts
- Card data is entered with Square and never reaches TrusteeClear
- Region
- United States
- Status
- Always on; configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Payment events accepted only with a valid signature
- Hourly reconciliation of provider events
Resend
- Purpose
- Outbound transactional email
- Data
- Recipient email address
- Notification content
- Region
- United States
- Status
- Always on; configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Sent from an authenticated domain (SPF and DKIM)
ImprovMX
- Purpose
- Forwarding of mail sent to TrusteeClear's published addresses
- Data
- Messages sent to the published addresses, such as working-session requests and accessibility feedback
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Always on
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- The domain's mail policy quarantines unauthenticated mail that claims to come from it
Plaid
- Purpose
- Bank-account connections for ledger feeds
- Data
- Account and transaction data the account holder chooses to connect
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Enabled when a firm or account holder connects it; not configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected only by the account holder, and disconnectable at any time
Clio
- Purpose
- Practice-management sync for firms that connect it
- Data
- Matter summaries the firm chooses to sync
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Enabled when a firm or account holder connects it; not configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected by the firm, and disconnectable at any time
Google Calendar
- Purpose
- Calendar sync for people who connect it
- Data
- Deadline titles and dates
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Enabled when a firm or account holder connects it; not configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected by the account holder, and disconnectable at any time
Microsoft calendar (Graph)
- Purpose
- Calendar sync for people who connect it
- Data
- Deadline titles and dates
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Enabled when a firm or account holder connects it; not configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected by the account holder, and disconnectable at any time
DocuSign
- Purpose
- Electronic-signature provider for firms that connect it
- Data
- Documents sent for signature
- Signer names and email addresses
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Enabled when a firm or account holder connects it; not configured on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Provider callbacks accepted only with a valid signature
- Only a clean document can be sent
Microsoft Office add-in platform
- Purpose
- Hosts the Word and Outlook add-ins inside Office
- Data
- None sent by TrusteeClear; the add-in runs inside the user's own Office host
- Region
- The user's Office host
- Status
- Enabled when a firm or account holder connects it
- Contract basis
- The Office add-in platform terms that apply to the firm's own Office subscription
- Controls
- Only the add-in pages may be framed, and only by Office hosts
EstateDraftFL (sister platform)
- Purpose
- Membership codes issued with an EstateDraftFL purchase
- Data
- Membership codes and their redemption status
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Dormant; not configured on this deployment
- Contract basis
- Common ownership; the partner door refuses every call until it is configured
- Controls
- Partner calls accepted only with the partner secret
Stripe
- Purpose
- Former payment rail, kept dormant
- Data
- None while dormant
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Dormant; not configured on this deployment
- Contract basis
- None in force while dormant
- Controls
- Events accepted only with a valid signature
OpenAI
- Purpose
- Retained code path for a second model provider
- Data
- None while dormant
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Dormant; not configured on this deployment
- Contract basis
- None in force while dormant
- Controls
- Unused unless configured; the same gateway limits would apply
Twilio
- Purpose
- Text-message reminders
- Data
- None while dormant
- Region
- United States
- Status
- Dormant; not configured on this deployment
- Contract basis
- None in force while dormant
- Controls
- Unused unless configured
Postmark
- Purpose
- Alternative outbound email sender
- Data
- None while dormant
- Region
- United States
- Status
- Dormant; not configured on this deployment
- Contract basis
- None in force while dormant
- Controls
- Unused unless configured
Подключения браузера
Every outside origin the site's content-security policy allows, and the provider it belongs to. The browser refuses anything else.
| Origin | Provider | Allowed for |
|---|---|---|
This deployment's database origin | Supabase | Data requests from the browser |
https://va.vercel-scripts.com | Vercel | Scripts, data requests or frames the policy allows |
https://vitals.vercel-insights.com | Vercel | Scripts, data requests or frames the policy allows |
https://cdn.plaid.com | Plaid | Scripts, data requests or frames the policy allows |
https://*.plaid.com | Plaid | Scripts, data requests or frames the policy allows |
https://appsforoffice.microsoft.com | Microsoft Office add-in platform | Scripts, data requests or frames the policy allows |
https://*.officeapps.live.com | Microsoft Office add-in platform | May frame the add-in pages only |
https://*.office.com | Microsoft Office add-in platform | May frame the add-in pages only |
https://outlook.office.com | Microsoft Office add-in platform | May frame the add-in pages only |
https://outlook.office365.com | Microsoft Office add-in platform | May frame the add-in pages only |