# RILLA Shield — Sub-processors

Last updated: 2026-06-23.

RILLA engages the following sub-processors to deliver the Service. Material changes are notified to customers with 30 days' notice.

| Sub-processor | Purpose | Data location |
|---|---|---|
| Supabase (managed PostgreSQL, Auth, Storage) | Primary application database, user authentication, file storage | AU (ap-southeast-2) |
| Cloudflare | Edge delivery, DNS, DDoS protection | Global edge; AU termination |
| Stripe | Subscription billing | US / global; PCI DSS Level 1 |
| Resend | Transactional email delivery | US / EU |
| OpenAI via Lovable AI Gateway | Risk reasoning on de-identified invoice features | US |
| Basiq | Bank account verification (Australia) | AU |
| Xero | Read-only accounting sync (customer-authorised only) | AU |
| ElevenLabs | Voice scam analysis (opt-in) | US |

No customer data is sold or used to train third-party models. All sub-processors operate under written DPAs.
