EnrollPilot uses the third-party providers below to deliver the Service. Each one processes Customer Data only as needed for the purpose described, under contract with us. This page is referenced by Section 8 of the EnrollPilot Terms of Service and is updated whenever a subprocessor is added or replaced.
| Subprocessor | Purpose of processing | Data processed |
|---|---|---|
| Neon, Inc. | Managed PostgreSQL hosting for all application data | All Customer Data stored in the application, including provider demographics and enrollment records |
| Amazon Web Services, Inc. | Object storage for uploaded documents and files, encrypted at rest | Credentialing documents and any file content uploaded by customers |
| Vercel Inc. | Application hosting, content delivery, and serverless execution | Customer Data in transit during request processing, and application logs |
| Mailgun Technologies, Inc. | Outbound and inbound email delivery and correspondence threading | Email addresses, message content, and attachments sent through the Service |
| Ably Real-time Ltd. | Real-time internal messaging delivery, presence, and typing indicators | Message content and sender identity for in-app messaging |
| OpenRouter, Inc. | Routing of AI requests for document extraction, classification, and drafting assistance | Document text and record fields submitted to AI features |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact and subscription data. Card details are collected and stored by Stripe and never stored in our systems |
| Mapbox, Inc. | Geocoding addresses to coordinates for map display | Practice and provider addresses |
AI requests are routed through OpenRouter to the model provider selected for a given feature. OpenRouter is our direct subprocessor; the model providers it routes to act as its subprocessors.
The Service queries the CMS NPPES registry to retrieve publicly available provider information by NPI. NPPES is a government registry of public data, not a subprocessor of Customer Data.
We may add or replace subprocessors as the Service evolves, and we will update this page when we do. Section 8 of the Terms of Service describes how we select providers and what we are responsible for.
If you have questions about this list, or need it for a vendor review: