1. Register status
The organizations and infrastructure categories below are approved for planning only. None is represented here as an active CXRove subprocessor, integration, partner, endorsement, data location, or production dependency.
Before any row is changed to active, the public register must match executed contracts, runtime configuration, safe provider readback, and the production data-flow map.
2. Planned and authorized register
Every row remains pending activation evidence. A product name may cover more than one contracting entity or service; an active register must name the exact entity and service actually used.
| Provider or category | Planned purpose and data | Status and region |
|---|---|---|
| Stripe / Stripe TaxPayments and tax technology | Purpose Planned payment processing, billing references, tax calculation support, fraud controls, and transaction reconciliation. DataAccount, billing, transaction, tax-location, and provider-reference data; card data should remain on Stripe-hosted surfaces. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| TwilioCommunications carrier and platform | Purpose Planned primary telephony transport, phone-number, routing, and communications metadata processing for approved routes. DataContact and communications metadata and, only when separately enabled, approved call artifacts. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| Telnyx (when enabled)Secondary communications carrier and platform | Purpose Planned controlled secondary telephony path only after equivalent identity, route, reconciliation, and legal gates pass. DataContact and communications metadata and, only when separately enabled, approved call artifacts. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| OpenAIAI model services | Purpose Planned model processing for approved agent and communications functions behind CXRove provider contracts. DataPrompts, approved customer content, generated output, and service metadata limited by the activated feature. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| Google (Gemini)AI model and cloud services | Purpose Planned alternate model processing for approved functions behind CXRove provider contracts. DataPrompts, approved customer content, generated output, and service metadata limited by the activated feature. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| BunnyObject storage and content delivery | Purpose Planned storage and delivery of eligible generated artifacts and public content under cache and privacy boundaries. DataEligible artifacts, object metadata, delivery requests, and technical logs approved for the activated path. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| Amazon Web Services (SES)Transactional email | Purpose Planned delivery of account, security, billing, and service messages after template, consent, and secret gates pass. DataRecipient and sender address, message content, delivery metadata, and suppression status for approved transactional messages. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| CloudflareDNS, edge security, and public delivery | Purpose Planned public DNS, proxy, security, and cache-layer processing before the Bunny and origin path. DataPublic request, network, security, device, and edge-delivery metadata for the approved hostnames. | Planned / authorized; activation not verified Pending activation evidence; no processing region represented. |
| Cyber Infrastructure LLC-operated self-hosted infrastructureOperator infrastructure | Purpose Planned hosting for public, application, API, database, cache, realtime communications, observability, backup, and recovery components under separate service identities. DataCustomer, account, communications, content, security, usage, audit, and service data limited to the activated component and purpose. | Planned operator infrastructure; activation not verified Pending activation and host evidence; no processing location represented. |
3. Required fields before activation
- Exact provider legal entity, contracted service, agreement or DPA version, and activation date.
- Specific purpose, personal-data categories, data-subject categories, controller or processor role, and service owner.
- Storage and processing countries or regions, transfer mechanism where required, and downstream subprocessor reference.
- Retention and deletion behavior, security evidence reference, incident path, and current vendor-change subscription or review date.
- Signed manifest identity and deployed readback proving the provider is enabled for the exact environment and feature.
4. Changes and objections
The executed DPA and final register must define how customers receive notice of a new or replacement subprocessor and how they may raise a reasonable data-protection objection.
This public register does not create a notice period or objection remedy. Those terms depend on the executed DPA and customer agreement.
Change record
Published the approved planning set with explicit non-activation and exact live-evidence requirements.
This is the first published version; no prior operative version exists.