Полный текст этого руководства на английском языке; краткое изложение выше — на вашем языке. Изложения законов и английский текст остаются источником записи.
Все поставщики
The authorized subprocessors are the providers that are always on, and those a firm or account holder connects. Dormant providers are wired into the code but carry no configuration and receive no data. This list is the one the data processing addendum refers to.
“Built” means TrusteeClear's software can work with the provider. “Set up” means this deployment holds the credentials the provider needs. Neither means that a firm has connected an account, or that a connection is working: that is recorded for each firm, and shown to that firm and to TrusteeClear's support.
| Provider | Purpose | Status | On this deployment |
|---|---|---|---|
| Supabase | Database, sign-in and private file storage | Always on | In use |
| Vercel | Hosting, content delivery, server functions and privacy-preserving web analytics | Always on | In use; nothing to set up |
| Anthropic | Model provider for firm-staff generative features and for structured extraction | Always on | In use |
| Square | Payments: checkout, subscriptions and payment events | Always on | In use |
| Resend | Outbound transactional email; mail forwarded to a matter's address, once email filing is switched on | Always on | In use |
| ImprovMX | Forwarding of mail sent to TrusteeClear's published addresses | Always on | In use; nothing to set up |
| Plaid | Bank-account connections for ledger feeds | Used only for the firms and account holders who choose it | Built, not set up: no one can connect it on this deployment |
| Clio | Practice-management sync for firms that connect it | Used only for the firms and account holders who choose it | Built, not set up: no one can connect it on this deployment |
| Google Calendar | Calendar sync for people who connect it | Used only for the firms and account holders who choose it | Built, not set up: no one can connect it on this deployment |
| Microsoft calendar (Graph) | Calendar sync for people who connect it | Used only for the firms and account holders who choose it | Built, not set up: no one can connect it on this deployment |
| DocuSign | Electronic-signature provider for firms that connect it | Used only for the firms and account holders who choose it | Built, not set up: no one can connect it on this deployment |
| Microsoft Office add-in platform | Hosts the Word and Outlook add-ins inside Office | Used only for the firms and account holders who choose it | Available: nothing to connect or set up |
| EstateDraftFL (sister platform) | Membership codes issued with an EstateDraftFL purchase | Dormant | Built, not in use |
| Stripe | Former payment rail, kept dormant | Dormant | Built, not in use |
| OpenAI | Retained code path for a second model provider | Dormant | Built, not in use |
| Twilio | Text-message reminders | Dormant | Built, not in use |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Carry a notification to a browser a person turned push notifications on for | Used only for the firms and account holders who choose it | Built, not set up: no one can connect it on this deployment |
| Postmark | Alternative outbound email sender | Dormant | Built, not in use |
Supabase
- Purpose
- Database, sign-in and private file storage
- Data
- Account identities (email address)
- Matter records, ledgers and audit records
- Uploaded documents
- Region
- United States
- Status
- Always on
- On this deployment
- In use
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Row-level security on every table
- Private storage with signed, matter-scoped access
- Privileged credentials used only on the server
Vercel
- Purpose
- Hosting, content delivery, server functions and privacy-preserving web analytics
- Data
- Request metadata such as IP address and browser
- Operational logs that carry markers and codes, not document text
- Anonymous page-view and speed measurements
- Region
- United States
- Status
- Always on
- On this deployment
- In use; nothing to set up
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Security headers and a content-security policy on every response
- Production variables held in the platform, never in source
Anthropic
- Purpose
- Model provider for firm-staff generative features and for structured extraction
- Data
- Document text and matter facts sent for the requested operation
- Region
- United States
- Status
- Always on
- On this deployment
- In use
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- The provider's terms prohibit training on this data; retention follows its API terms
- Generative use only behind a firm-staff session
- A monthly spend ceiling that fails closed
Square
- Purpose
- Payments: checkout, subscriptions and payment events
- Data
- Payer name and email address
- Order amounts
- Card data is entered with Square and never reaches TrusteeClear
- Region
- United States
- Status
- Always on
- On this deployment
- In use
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Payment events accepted only with a valid signature
- Hourly reconciliation of provider events
Resend
- Purpose
- Outbound transactional email; mail forwarded to a matter's address, once email filing is switched on
- Data
- Recipient email address
- Notification content
- Mail forwarded to a matter's or a firm's address, with its attachments (once email filing is switched on)
- Region
- United States
- Status
- Always on
- On this deployment
- In use
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Sent from an authenticated domain (SPF and DKIM)
- Forwarded mail is read by its identifier from a signed webhook; its attachments enter the upload quarantine and scanner
ImprovMX
- Purpose
- Forwarding of mail sent to TrusteeClear's published addresses
- Data
- Messages sent to the published addresses, such as working-session requests and accessibility feedback
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Always on
- On this deployment
- In use; nothing to set up
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- The domain's mail policy quarantines unauthenticated mail that claims to come from it
Plaid
- Purpose
- Bank-account connections for ledger feeds
- Data
- Account and transaction data the account holder chooses to connect
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Used only for the firms and account holders who choose it
- On this deployment
- Built, not set up: no one can connect it on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected only by the account holder, and disconnectable at any time
Clio
- Purpose
- Practice-management sync for firms that connect it
- Data
- Matter summaries the firm chooses to sync
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Used only for the firms and account holders who choose it
- On this deployment
- Built, not set up: no one can connect it on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected by the firm, and disconnectable at any time
Google Calendar
- Purpose
- Calendar sync for people who connect it
- Data
- Deadline titles and dates
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Used only for the firms and account holders who choose it
- On this deployment
- Built, not set up: no one can connect it on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected by the account holder, and disconnectable at any time
Microsoft calendar (Graph)
- Purpose
- Calendar sync for people who connect it
- Data
- Deadline titles and dates
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Used only for the firms and account holders who choose it
- On this deployment
- Built, not set up: no one can connect it on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Connected by the account holder, and disconnectable at any time
DocuSign
- Purpose
- Electronic-signature provider for firms that connect it
- Data
- Documents sent for signature
- Signer names and email addresses
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Used only for the firms and account holders who choose it
- On this deployment
- Built, not set up: no one can connect it on this deployment
- Contract basis
- The provider's standard terms and data-processing terms
- Controls
- Provider callbacks accepted only with a valid signature
- Only a clean document can be sent
Microsoft Office add-in platform
- Purpose
- Hosts the Word and Outlook add-ins inside Office
- Data
- None sent by TrusteeClear; the add-in runs inside the user's own Office host
- Region
- The user's Office host
- Status
- Used only for the firms and account holders who choose it
- On this deployment
- Available: nothing to connect or set up
- Contract basis
- The Office add-in platform terms that apply to the firm's own Office subscription
- Controls
- Only the add-in pages may be framed, and only by Office hosts
EstateDraftFL (sister platform)
- Purpose
- Membership codes issued with an EstateDraftFL purchase
- Data
- Membership codes and their redemption status
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Dormant
- On this deployment
- Built, not in use
- Contract basis
- Common ownership; the partner door refuses every call until it is configured
- Controls
- Partner calls accepted only with the partner secret
Stripe
- Purpose
- Former payment rail, kept dormant
- Data
- None while dormant
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Dormant
- On this deployment
- Built, not in use
- Contract basis
- None in force while dormant
- Controls
- Events accepted only with a valid signature
OpenAI
- Purpose
- Retained code path for a second model provider
- Data
- None while dormant
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Dormant
- On this deployment
- Built, not in use
- Contract basis
- None in force while dormant
- Controls
- Unused unless configured; the same gateway limits would apply
Twilio
- Purpose
- Text-message reminders
- Data
- None while dormant
- Region
- United States
- Status
- Dormant
- On this deployment
- Built, not in use
- Contract basis
- None in force while dormant
- Controls
- Unused unless configured
Browser push services (Google, Mozilla, Apple, Microsoft)
- Purpose
- Carry a notification to a browser a person turned push notifications on for
- Data
- A fixed sentence that something is waiting or new, encrypted for the one browser so the service cannot read it
- The browser's push address and when a notification was sent
- Region
- Not stated in TrusteeClear's records; see the provider's published terms
- Status
- Used only for the firms and account holders who choose it
- On this deployment
- Built, not set up: no one can connect it on this deployment
- Contract basis
- None: the service is the one the person's own browser uses, and receives only what it cannot read
- Controls
- Nothing is sent until push is set up and a person turns it on for a browser; they turn it off there or from any of their browsers
- Encrypted for the one browser (RFC 8291) and signed as TrusteeClear (RFC 8292)
- Never a name, a trust, a document, a date or an amount; the page a notification opens is on TrusteeClear
- Sent only to a known push service's address, checked before each send
Postmark
- Purpose
- Alternative outbound email sender
- Data
- None while dormant
- Region
- United States
- Status
- Dormant
- On this deployment
- Built, not in use
- Contract basis
- None in force while dormant
- Controls
- Unused unless configured
Подключения браузера
Every outside origin the site's content-security policy can allow, and the provider it belongs to. An origin is allowed only where its provider is set up; the browser refuses anything else.
| Origin | Provider | Allowed for |
|---|---|---|
This deployment's database origin | Supabase | Data requests from the browser |
https://va.vercel-scripts.com | Vercel | Scripts, data requests or frames the policy allows |
https://vitals.vercel-insights.com | Vercel | Scripts, data requests or frames the policy allows |
https://cdn.plaid.com | Plaid | Not allowed on this deployment: allowed only once it is set up |
https://*.plaid.com | Plaid | Not allowed on this deployment: allowed only once it is set up |
https://appsforoffice.microsoft.com | Microsoft Office add-in platform | Scripts, data requests or frames the policy allows |
https://*.officeapps.live.com | Microsoft Office add-in platform | May frame the add-in pages only |
https://*.office.com | Microsoft Office add-in platform | May frame the add-in pages only |
https://outlook.office.com | Microsoft Office add-in platform | May frame the add-in pages only |
https://outlook.office365.com | Microsoft Office add-in platform | May frame the add-in pages only |