Know which services may touch your product data.
A production deployment should maintain a current subprocessor and dependency register. The categories below are the ones to review during a project; the final provider names, locations, purposes, and transfer terms belong in the applicable agreement.
Infrastructure
Application hosting, databases, object storage, backups, content delivery, monitoring, logs, DNS, certificates, and email delivery may be provided by separate vendors.
AI and automation
AI providers may receive prompts or structured context when an approved feature uses them. Sensitive, regulated, confidential, or personal data should not be sent to an AI provider without an approved use case, contract, and data-handling review.
Payments and commerce
Payment providers may process payment credentials and transaction metadata. The app should keep card data outside the application when possible and rely on provider-hosted secure checkout.
Customer controls
The customer should receive the relevant vendor list, purpose, region, retention, security terms, change notice, and objection or alternative process required by the signed agreement.