Who else touches your records
Providers marked in use are in the path for every deployment of JobSite. Conditional providers stay off for a tenant until the feature is enabled and its contract, security, deletion, incident and data-location review is recorded.
Published
| Provider | Capability | Data boundary | Processing location | Status |
|---|---|---|---|---|
| Vercel | Hosting and delivery for the JobSite web application | Requests to the web application, edge routing metadata and deployment artefacts | Provider network locations, potentially outside Canada | On track: In use — hosts this application |
| Supabase | Identity and sessions, the PostgreSQL database, and private object storage for documents | Account identifiers, authentication factors, session and security metadata, and the tenant records and files themselves | Deployment-specific project region and provider support locations | On track: In use — shared project, isolated by schema and row-level security |
| Amazon Web Services | Infrastructure for the jobsite-platform service that this application calls server-to-server | Tenant-scoped service records, encrypted files and minimized operational telemetry | Canadian primary region where configured; limited global support and security processing may apply | On track: In use — platform service |
| PostHog | Optional product analytics | Consented, minimized interaction events without project content | Configured service region and support locations | Informational: Conditional — analytics consent defaults off |
| OpenAI or Anthropic, through the governed AI gateway | Specifically enabled AI assistance | Redacted, permission-filtered context for the approved capability only | Provider locations, potentially outside Canada | Needs attention: Conditional — no provider key is present in this environment |
| Stripe | Payment processing, were a paid plan to exist | None. No billing relationship exists and no payment method is collected | Not applicable while unused | Inactive: Not in use — no paid plan is published |
| Twilio | Tenant-enabled SMS and voice | Contact number, disclosure and consent state, message or call routing, minimized delivery evidence | Provider network locations, potentially outside Canada | Inactive: Conditional — off until tenant provisioning and review |
| Mapbox | Tenant-enabled routing and travel-time estimates | Purpose-limited route coordinates; not an unrestricted worker trail | Provider locations, potentially outside Canada | Inactive: Conditional — off without tenant policy; no token in this environment |
| DocuSign | Tenant-enabled electronic signatures | Signer identity, document reference, consent and completion evidence | Configured account region and provider support locations | Inactive: Conditional — off until professional and provider review |
What this page does and does not mean
A tenant's active provider set depends on the capabilities it has enabled, so this page does not mean every conditional provider receives your information. Material provider changes are versioned and communicated through the applicable contract or tenant notice.
Publishing this inventory is not a claim that every provider's formal review is complete. Conditional activation stays blocked until its recorded review passes.
Stripe and the AI gateway
Stripe is listed as not in use. An earlier version of this page described it as “core for paid subscriptions”. There is no paid plan, no published price and no verified JobSite provisioning with Stripe, so the row would have implied a billing relationship that does not exist.
The AI gateway has no provider key in this environment. An AI run is enqueued as a governed job whether or not a model answers it, so the row stays in the inventory — but nothing is currently being sent to a model provider from this deployment.