This document is written for Skaith’s current U.S. business service. It does not turn an audit result into legal advice or guarantee a supplier credit.
Cloudflare, Inc.
Purpose: authoritative DNS, secure tunnel connectivity, edge security, and Turnstile abuse prevention for authentication. Data can include IP address, device and request signals, hostname, and encrypted traffic transiting Cloudflare’s network. Primary processing is in the United States and Cloudflare’s global network.
Amazon Web Services, Inc.
Purpose: Amazon Cognito account authentication and managed login. Data can include name, verified email address, authentication events, device and network information, and identity-provider identifiers. The configured user pool is in the United States (Northern Virginia). Core invoice and agreement processing is not moved to AWS merely because optional AWS adapters exist.
Resend, Inc.
Purpose: transactional email, invoice-email receipt, raw message retrieval, and delivery status. Data can include sender and recipient addresses, message headers, message bodies, attachments, delivery events, and customer-authorized recovery communications. Processing can occur in the United States.
Operator-controlled infrastructure
Skaith’s current web application, PostgreSQL database, private object storage, malware scanner, worker, and local optical-character-recognition tools run on infrastructure controlled by the Skaith operator. This is not a separate third-party subprocessor. Access remains limited to operational need.
Changes and questions
We will update this list before a provider materially expands processing of Customer Content. A customer may object on reasonable data-protection grounds as described in the Data Processing Addendum. Questions may be sent to [email protected].
