Sub-Processor List

Last Updated: May 11, 2026

URL: www.keivos.com/subprocessors

Overview

This document lists all third-party service providers ("sub-processors") that may have access to student personally identifiable information (PII) in the course of providing the Keivos Services on behalf of Keivos LLC. This list is maintained in accordance with our Data Processing Agreement (DPA) obligations and FERPA compliance requirements.

Per our DPA, we will notify university partners at least 30 days prior to engaging any new sub-processor that will have access to Student Data, both by updating this document and by emailing the Institution's designated contact.

Current Sub-Processors

ProviderServiceData AccessedLocationCertifications
Supabase, Inc.Primary backend — PostgreSQL database, authentication, file storage, Edge FunctionsAll Student DataUnited StatesSOC 2 Type 2, ISO/IEC 27001:2022, HIPAA-eligible
Base44, Inc.Web application hosting — Keivos Hub, Advisor Dashboard, Student Web app, and public websiteAll Student DataUnited StatesSOC 2 Type II, ISO 27001
Resend, Inc.Transactional email delivery — account, trial, license, and notification emailsName, email addressUnited StatesSOC 2 Type 2
Apple Inc.iOS app distribution and in-app purchase processingApple ID and purchase transaction data only — no academic Student DataUnited StatesISO 27001
Google LLC (Firebase Cloud Messaging)Android push notification deliveryDevice tokens and notification contentUnited StatesSOC 2, ISO 27001, ISO 27017, ISO 27018
Anthropic, PBCAI inference for optional in-app chat assistant ("Ask Keivos") — only when student uses the featureStudent query text and limited context window (when feature is used)United StatesSOC 2 Type 2. Per Commercial Terms, data not used to train models.
Stripe, Inc.Web and Android payment processingPayment transaction data only — no academic Student DataUnited StatesPCI DSS Level 1

Categories of Service Provider NOT Used

Keivos does NOT use the following categories of providers, which are commonly associated with student data privacy concerns:

  • Marketing automation platforms or advertising networks
  • Data brokers or data aggregators
  • AI/machine learning platforms for model training on Student Data
  • Direct-to-consumer or student analytics services unrelated to educational guidance
  • Social media platforms or tracking services
  • Commercial data enrichment services

Service Providers That Do Not Receive Student Data

The following providers support Keivos's business operations but do not process Student Data and are not considered sub-processors for FERPA purposes:

Google Workspace

Keivos corporate email and document collaboration for employees only. No Student Data is stored or transmitted through Google Workspace.

Mercury

Keivos business banking. No Student Data; only Keivos's own financial information.

Cloudflare

DNS and DDoS protection for keivos.com and subdomains. Traffic is encrypted end-to-end with TLS; Cloudflare does not have access to decrypted Student Data.

Change Notification

If Keivos intends to engage a new sub-processor that will have access to Student Data, we will:

  1. Update this document and republish at www.keivos.com/subprocessors
  2. Notify all university partners with active DPAs at least 30 days in advance via their designated contact email
  3. Provide the university with an opportunity to object within 15 days of notice

Contact

For questions about our sub-processors or to request additional information:

Keivos LLC

336 East University Pkwy #1095, Orem, Utah 84058

Email: privacy@keivos.com