At Grivus, we believe transparency builds trust. This page outlines the infrastructure providers, subprocessors, and AI services that power our compliance platform. Every vendor is carefully vetted for security, compliance, and reliability.
We only use trusted providers that comply with industry standards such as SOC 2, ISO 27001, and GDPR.
Service | Purpose | Location | Compliance |
---|---|---|---|
Vercel | Frontend hosting & global edge delivery (React + Tailwind) | Global | SOC 2, ISO 27001, GDPR |
Railway | Backend hosting (Node.js APIs, task scheduling, certificate signing) | US/EU | SOC 2, ISO 27001 |
PostgreSQL (Managed) | Primary database (clients, tasks, compliance records, audit logs) | Canada / US | SOC 2, ISO 27001 |
pgvector / Pinecone | Vector database for large AI document processing & semantic search | US/EU | SOC 2, GDPR |
Service | Purpose | Data Handling | Compliance |
---|---|---|---|
OpenAI | Regulatory AI: impact analysis, task creation, classification | Text/documents processed transiently (no retention) | SOC 2, GDPR |
Anthropic | Summarization of long regulations & compliance insights | Text/documents processed transiently (no retention) | SOC 2, GDPR |
Perplexity AI | High reasoning & advanced analysis for compliance research | Text/documents processed transiently (no retention) | SOC 2, GDPR |
Service | Purpose | Compliance |
---|---|---|
X.509 Certificate Signing | Tamper-proof signing of audit log exports | RSA-2048, SHA-256 |
End-to-End Encryption | Protects sensitive client & regulatory documents | AES-256 standard |
Service | Purpose | Compliance |
---|---|---|
Postmark / SendGrid | Transactional emails (task alerts, compliance updates) | SOC 2, GDPR |
In-App Notifications | Real-time alerts & task reminders | Secure, hosted on Railway + PostgreSQL |
Wherever possible, data is stored in Canadian regions for regulatory alignment.
We only use what's necessary to deliver Grivus securely.
We never share or sell your data with advertisers.
Every provider we use meets enterprise compliance standards.
📌 Last Updated: October 2025
👉 For questions about data handling or subprocessors, please contact hello@grivus.com