Sub-Processor List
Last Updated: May 11, 2026
URL: www.keivos.com/subprocessors
Overview
This document lists all third-party service providers ("sub-processors") that may have access to student personally identifiable information (PII) in the course of providing the Keivos Services on behalf of Keivos LLC. This list is maintained in accordance with our Data Processing Agreement (DPA) obligations and FERPA compliance requirements.
Per our DPA, we will notify university partners at least 30 days prior to engaging any new sub-processor that will have access to Student Data, both by updating this document and by emailing the Institution's designated contact.
Current Sub-Processors
| Provider | Service | Data Accessed | Location | Certifications |
|---|---|---|---|---|
| Supabase, Inc. | Primary backend — PostgreSQL database, authentication, file storage, Edge Functions | All Student Data | United States | SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA-eligible |
| Base44, Inc. | Web application hosting — Keivos Hub, Advisor Dashboard, Student Web app, and public website | All Student Data | United States | SOC 2 Type II, ISO 27001 |
| Resend, Inc. | Transactional email delivery — account, trial, license, and notification emails | Name, email address | United States | SOC 2 Type 2 |
| Apple Inc. | iOS app distribution and in-app purchase processing | Apple ID and purchase transaction data only — no academic Student Data | United States | ISO 27001 |
| Google LLC (Firebase Cloud Messaging) | Android push notification delivery | Device tokens and notification content | United States | SOC 2, ISO 27001, ISO 27017, ISO 27018 |
| Anthropic, PBC | AI inference for optional in-app chat assistant ("Ask Keivos") — only when student uses the feature | Student query text and limited context window (when feature is used) | United States | SOC 2 Type 2. Per Commercial Terms, data not used to train models. |
| Stripe, Inc. | Web and Android payment processing | Payment transaction data only — no academic Student Data | United States | PCI DSS Level 1 |
Categories of Service Provider NOT Used
Keivos does NOT use the following categories of providers, which are commonly associated with student data privacy concerns:
- Marketing automation platforms or advertising networks
- Data brokers or data aggregators
- AI/machine learning platforms for model training on Student Data
- Direct-to-consumer or student analytics services unrelated to educational guidance
- Social media platforms or tracking services
- Commercial data enrichment services
Service Providers That Do Not Receive Student Data
The following providers support Keivos's business operations but do not process Student Data and are not considered sub-processors for FERPA purposes:
Google Workspace
Keivos corporate email and document collaboration for employees only. No Student Data is stored or transmitted through Google Workspace.
Mercury
Keivos business banking. No Student Data; only Keivos's own financial information.
Cloudflare
DNS and DDoS protection for keivos.com and subdomains. Traffic is encrypted end-to-end with TLS; Cloudflare does not have access to decrypted Student Data.
Change Notification
If Keivos intends to engage a new sub-processor that will have access to Student Data, we will:
- Update this document and republish at www.keivos.com/subprocessors
- Notify all university partners with active DPAs at least 30 days in advance via their designated contact email
- Provide the university with an opportunity to object within 15 days of notice
Contact
For questions about our sub-processors or to request additional information:
