01 — SERVICE PROVIDERS

Who else touches your data.

These are the service providers that process data on our behalf. This page names every one, says what it receives and where it runs, and is referenced by the privacy policy and the security page. Every entry was traced to the code that sends it data.

List as of 2026-09-20

02 — THE LIST

Provider
Location
Purpose and data received
Amazon Web Services
United States (us-east-1); CloudFront edge locations worldwide
Hosting, storage, database, cache and CDN for this site and the signed-in application, and the identity provider behind sign-in. Receives: Everything the application stores: account details, intake submissions, uploads, generated reports, and server logs.
Stripe
United States
Payment processing, subscription billing and the customer billing portal. Receives: Name, email address, billing address and payment card details. Card numbers go to Stripe directly and never reach us.
Resend
United States
Transactional email — sign-in links, email-address confirmations, report delivery and account notices. Receives: Email address and the contents of the message sent to it.
Anthropic
United States
Generates the written sections of a readiness report. Receives: The company intake you submit, sent as the prompt for that generation.
PostHog
United States
Product analytics inside the signed-in application. No analytics tag loads on this marketing site — a build gate enforces that. Receives: Account ID, page views, and the named product events listed in the analytics section of our privacy policy.
Cloudflare
Global edge network
Turnstile bot protection on the intake form. Receives: Visitor IP address and a challenge token.
Brave Software
United States
Web search used to enrich a company profile during report generation. Receives: Your company name, sent as the search query.
Google
Global edge network
Google Fonts serves two typefaces used across this marketing site. We run no Google Analytics. Receives: Visitor IP address and browser user-agent, on every page load of this site.

03 — WHAT THIS LIST CLAIMS

It claims exactly one thing: these companies receive this data. Every entry was traced to the code that sends it, or to the credential that code uses, rather than assembled from memory.

We have not executed a data processing agreement with any of the providers listed here, and nothing on this page should be read as saying we have. Each is used under its publicly posted terms of service. This list records who receives your data, which we can verify; it does not record what any of them has contractually agreed about it, which we cannot yet.

We publish the gap rather than the appearance of no gap. That is the same standard the security page applies to our own controls, and the same one we apply to every vendor we score: a company's own claim and a verified record are not the same thing and are never rendered as if they were.

04 — THE STANDARD WE WILL HOLD THEM TO

Written in the future tense on purpose. This is what a data processing agreement with each provider will have to say before we describe any of them as bound by it — not a description of terms in force today.

  • It may process customer data only to perform its service for us, and for no purpose of its own.
  • It may not use customer data to train, fine-tune, evaluate, or benchmark any model — the same commitment we make on the privacy policy and in the terms, passed through.
  • It must protect the data with measures appropriate to it, and tell us promptly if it fails to.
  • It may not engage a service provider of its own for our data without the same terms applying down the chain.
  • It must delete or return the data when the service ends.

Our own no-training commitment does not depend on any of this. It binds GovExpress directly, today, and is in the terms.

05 — THIRD PARTIES THIS WEBSITE TALKS TO

Separate from the above, and a shorter list: loading this marketing site causes your browser to contact the following. This site holds no customer data at all, so nothing here is a subprocessor — but you can verify every entry by reading the page source, which is more than can be said for most disclosures of this kind.

Party
Location
What it receives
Amazon Web Services (S3 + CloudFront)
United States (us-east-1)
Serves this static site. Receives your IP address and request metadata in server logs.
Google Fonts
Global CDN
Serves two webfonts from fonts.googleapis.com and fonts.gstatic.com. Your browser requests them directly, so Google receives your IP address and user agent. We set no Google cookie and run no Google analytics tag on this site.

06 — CHANGES TO THIS LIST

We give notice before adding a subprocessor that will handle customer data, so you can object before it starts. The date at the top of this page moves when the list does — it is the day somebody last reviewed the list, not the day the site was last built, because the second one would advertise a freshness this page has not earned.

Questions, or a request for the current status of any row: privacy@govexpress.ai. You will get a straight answer, including "not signed yet" where that is the answer.

We publish the gaps. That is the product argument too.

Read the security page