Skip to main content
FabWise

Trust

Subprocessors

Subprocessor List

Last updated: 2026-07-26

This is the list of third-party services FabWise uses to host, deliver, support, or protect the product. When a subprocessor is added, removed, or materially changes, we update this page and notify subscribed customers where feasible.

To subscribe to subprocessor change notices, email [email protected].


Active subprocessors

Vendor Role Data processed Region Security posture
Render Application hosting + PostgreSQL database Customer account data, users, time records, jobs, customers, operational records, audit logs, and sessions Oregon (US-West) SOC 2 Type II attested; Render's posture: https://render.com/security
Stripe Payment processing + subscription management Billing contact (name, email, address), payment method tokens (cards never stored on FabWise), subscription history, invoice records, webhook events US (Stripe Inc., Delaware) PCI DSS Level 1; SOC 1 + SOC 2 attested; Stripe's posture: https://stripe.com/docs/security
Postmark (ActiveCampaign) Email delivery (sending + inbound processing) Recipient email addresses and email content for transactional, account, billing, product, and marketing communications; inbound support/sales email US (ActiveCampaign LLC, Chicago) SOC 2 attested; Postmark's posture: https://postmarkapp.com/eu-data-protection
Google Cloud Platform Object storage for database backups Encrypted production database backups US SOC 1 + SOC 2 + ISO 27001/27017/27018 attested; GCP's posture: https://cloud.google.com/security
Cloudflare CDN / edge proxy + access controls for supporting infrastructure HTTP request metadata and traffic routed through Cloudflare services Global edge SOC 2 Type II + ISO 27001 attested; Cloudflare's posture: https://www.cloudflare.com/trust-hub/
Apple Push Notification Service iOS push notification delivery Notification payloads for supervisor mobile workflows US Apple's enterprise posture documented at https://www.apple.com/legal/privacy/
Sentry Application error tracking Error reports, stack traces, request paths, and diagnostic context needed to investigate production errors US (Sentry Inc., San Francisco) SOC 2 Type II attested; Sentry's posture: https://sentry.io/security/
Anthropic AI features inside the product (Foreman in-app assistant, support email auto-response, daily briefing generation, conversation summarization) + AI-assisted engineering workflows In-product: the content of messages you send to Foreman, account records the assistant reads to answer you (jobs, customers, shifts, users, settings), inbound support email content, and the operational data summarized into a daily briefing. Personal information is redacted before support conversations are sent. Engineering: limited customer context when manually provided for support or debugging. No direct production database access. US Anthropic's trust posture: https://trust.anthropic.com/
OpenAI Knowledge-base search embeddings; selectable alternative provider for the AI features above Support questions and help-article text converted to embeddings so the assistant can find the right help article. Personal information is redacted before embedding. If selected as the active AI provider in FabWise's configuration, also processes the in-product content described in the Anthropic row. US OpenAI's posture: https://openai.com/security-and-privacy/
xAI Selectable alternative provider for the AI features above Only when selected as the active AI provider in FabWise's configuration; then processes the in-product content described in the Anthropic row. US xAI's posture: https://x.ai/legal/privacy-policy

Marketing-website vendors (visitor data only, not customer data)

These vendors operate only on the public marketing website (fabwise.app) for traffic measurement and advertising. They process anonymous marketing-website visitor identifiers and cookie data — no Customer account data and no employee Personal Information, and they never run within the authenticated application or customer shop portals.

Vendor Role Data processed Region Security posture
Google (Analytics 4 + Google Ads) Marketing-website traffic analytics + advertising / remarketing Marketing-website visitor identifiers, cookie data, page-view events US Google's posture: https://safety.google/
Meta Platforms (Meta Pixel) Marketing-website advertising / remarketing Marketing-website visitor identifiers and cookie data US Meta's posture: https://www.facebook.com/privacy/policy/

Notification Policy

When a subprocessor is added, removed, or has its scope materially changed, FabWise notifies subscribed customers via email at least 30 days before the change takes effect, where feasible. Customers can subscribe by emailing [email protected].