Schedule D — For Buyers, Procurement & InfoSec
For procurement,
compliance, and InfoSec.
Everything an evaluation team needs to clear DocumentBoost through a firm review, on one page.
Article I — Security Posture
The full posture table — encryption, residency, sub-processors, consent gate, audit immutability, SOC 2 readiness — lives on the security page and is what we hand to procurement teams during evaluation.
Review the security & compliance postureArticle II — Sub-Processors
Current sub-processor list. The full DPA detailing data handling for each is available on request.
| Vendor | Purpose |
|---|---|
| Supabase | Database, auth, storage |
| Vercel | Application hosting, edge runtime |
| Anthropic | AI inference (consent-gated) |
| OpenAI | AI inference (consent-gated, optional) |
| Resend | Transactional email |
Article III — Sample DPA
A sample Data Processing Agreement, with executable signature blocks and our standard sub-processor schedule, is available on request to qualified firms.
Request the sample DPAArticle IV — Customer References
The undersigned represents that
Customer references are made available on request after a first discovery call. Design partners under NDA during the v1 window require explicit authorization before disclosure; we route requests through the relationship lead.
Article V — Recent Architecture Decisions
For technical reviewers: a curated set of public-relevant decisions from the architecture decision record.
- ADR-012Prompt cache & third-party AI consent gate
External AI is fail-closed by default; firms opt in with explicit acknowledgment.
- ADR-018Retrieval architecture — pgvector + provenance citations
Every AI answer cites the source document; retrieval is per-org scoped.
- ADR-026Immutable, WORM-enforced audit log
Audit rows are append-only at the database layer, not the application.
- ADR-031Trust posture — confidence signals, stop button, undo
AI surfaces expose confidence; advisors retain a hard stop and selective undo.
- ADR-035MCP server with bearer-token distribution
Claude and ChatGPT connect via per-firm MCP tokens with audit lineage.
- ADR-036Workflow engine — declarative trigger → conditions → actions
Automation under the workflow creator's identity, cross-org rejection at three layers.
For the full procurement bundle — security brief, DPA, sub-processor agreements, and references — we'd be glad to connect.
Authorized Signature