Effective September 15, 2026 · Version v1.33
Version v1.33 · Effective September 15, 2026 · Published September 15, 2026
OCTICASE, INC. ("Octicase", "Provider", "we," "us," or "our") engages third-party service providers ("subprocessors") to process Personal Data and Protected Health Information (PHI) on behalf of our Customers. This list identifies all current subprocessors, and the planned engagements disclosed in advance, as of the effective date and is available from Provider on request and, from the date the Beta opens, at https://trust.octicase.com/subprocessors. Customers remain Data Controllers and, where applicable, Covered Entities under HIPAA.
| Provider | Service | PHI? | Region | BAA Status |
|---|---|---|---|---|
| Amazon Web Services | Hosting (us-east-1), S3, RDS, ElastiCache, CloudWatch, GuardDuty malware scanning, KMS, Bedrock (Claude) as AI failover for critical real-time surfaces, Connect (SIP bridge for inbound voice); Planned, not yet engaged: Simple Email Service (SES), to take over transactional and inbound email from the third-party email provider listed below | Yes | us-east-1 | BAA executed. AWS applies it automatically to the HIPAA-eligible services listed in it. Provider is confirming with AWS that Bedrock and Connect are among them under the current version of that agreement, and does not process Protected Health Information through either service until that confirmation is on file. |
| Google Cloud / Vertex AI | All AI features (primary processor), Gemini 2.5-flash | Yes | us-multi-region | BAA + CDPA executed March 16, 2026 |
| Twilio SendGrid | Transactional email and inbound email parsing | Possible on the inbound route. Email is not an approved channel for PHI and nothing the platform sends carries it, but a person can send clinical content to a case address, and the message reaches the provider before it reaches Octicase (see Critical Notes) | us-multi-region | No BAA today. Octicase transmits no PHI by email, but the inbound parsing route can deliver clinical content that a person sends to a case address, and the domain's mail exchange records deliver to the provider first, which retains the message while it retries delivery to Octicase. A Business Associate Agreement is therefore required for the inbound route unless the filtering control described in the Critical Notes is built and verified first. Open and click tracking is being disabled on every message except marketing email to a business; the feature flag is on by default in the codebase and the shutdown is pending engineering confirmation. |
| SRFax | Inbound and outbound fax, including medical records retrieval | Yes | US / Canada | BAA executed |
| Retell AI | Conversational voice agent: speech recognition, dialogue model and speech synthesis for inbound and outbound calls; SMS delivery | Yes for voice - call audio and transcripts. SMS notifications are content-minimal by design and carry no clinical content or matter detail | US | BAA executed. Retell engages downstream voice-synthesis vendors; see Critical Notes |
| Twilio | 2FA SMS codes, magic-link delivery | No (codes only) | US | No BAA required today: this channel carries verification codes and links only, never PHI. An account upgrade to a BAA-eligible tier is in progress as a precondition to routing any case-related SMS content through Twilio in the future; until a BAA is executed, no such content moves to this channel |
| DocuSeal (self-hosted) | Electronic signature. Deployed self-hosted inside the Octicase AWS HIPAA perimeter; no signature content is transmitted to a third-party e-signature vendor | Yes (within our own perimeter) | us-east-1 | No separate BAA required because no third party processes the data; covered by the AWS BAA. Replaced BoldSign, which replaced Dropbox Sign / HelloSign. |
| Vimeo | Video library (training/marketing only) | No | Global | N/A (no PHI) |
| Google LLC (Google Analytics) | Website analytics on marketing and campaign landing pages only; not loaded on the pages listed in Section 7 of the Cookie Policy | No | Global | No BAA required (no PHI); IP anonymization enabled; data retention set to the shortest available period |
| Cobalt (NeoPayment / MetroBank gateway) | Subscription, add-on and prepaid-credit processing (Section 5 of the Terms of Service); claiming a listing is free and involves no payment. Replaced by Stripe, Inc. for subscription, add-on and prepaid-credit processing. Remains the configured rail for payouts to sellers, which cannot occur until Provider enables Platform Engagements | No | Panama / US | DPA status: no data processing agreement is on file today. Cobalt no longer processes subscription, add-on or prepaid-credit payments, and no payout has been made through it. Execution of a data processing agreement on the terms Section 4.3 of the Data Processing Addendum requires is a condition of the first payout, and no payout will be made through Cobalt until it is executed. No BAA required (no PHI). No case type, injury type, matter identifier or outcome appears in payment descriptions or metadata. Subscription, add-on and prepaid-credit processing has moved to Stripe, Inc.; Cobalt remains the configured rail for payouts to experts and other sellers, and would carry them until Stripe Connect is engaged. No payout has been made through it, because Platform Engagements are not enabled |
| Gmail / Outlook OAuth | Customer-controlled email integration | Customer-controlled | Global | Customer's own contract with Google/Microsoft |
| Sentry | Error tracking and cron-failure alerting | Possible. Scrubbing is not enforced at the point of capture and the browser software development kit loads inside authenticated areas (see Critical Notes) | us | BAA executed with Octicase. The Confidentiality of Medical Information Act has no equivalent of the business associate; the basis for medical information is stated in the Critical Notes |
| Apify | Public-data scraping (Phase 1 directory enrichment) | No (public data only) | Multi-region | N/A (no PHI) |
| Apollo.io | Cold-outreach contact discovery (Phase 1, NOT YET ACTIVE) | No | us | N/A (no PHI) |
| Google Places | Firm domain discovery (Phase 1, NOT YET ACTIVE) | No | Multi-region | N/A (no PHI) |
| Stripe, Inc. | (1) Subscription, add-on and prepaid-credit processing, replacing Cobalt; (2) Planned, not yet engaged: Stripe Connect: payout accounts connected to the platform for experts, consultants and partners that sell Platform Engagements through the Services, including verification of their identity, beneficial owners, tax information and bank account (performed by Stripe as an independent controller for its own compliance), payment of Service Amounts (Section 4.16 of the Agreement, meaning the Terms of Service) by Customers, payouts to sellers, refund and recovery debits, ACH debit authorizations, and the information returns Octicase or Stripe files for payments settled through the platform | No. Payment descriptions and metadata never contain case type, injury type, matter identifiers or outcomes; engagement records stay on the platform | United States | Engaged for subscription, add-on and prepaid-credit processing, replacing Cobalt. Stripe Connect remains not yet engaged: neither the payout accounts nor the identity, tax and bank verification they require have begun. Both the migration and the plan for Connect were disclosed in this list before either occurred, and Octicase was pre-launch throughout, with no Customer to whom the notice and objection process of Sections 2 and 3 was owed; that process governs the next change. For Connect, Stripe will act as an independent controller of the identity, tax and bank information of sellers, under its own privacy notice, as Section 5.2 of the Privacy Policy describes; that information will be the seller's own, not Customer Data. Until Connect is engaged, the processor configured for the purposes of Section 6.1 of the Expert and Consultant Services Agreement and Section 7.1 of the Partner Agreement is Cobalt, and no payout has been made through it because Platform Engagements are not enabled. No BAA is required (no PHI) |
| Microsoft Azure (Blob Storage) | Second-cloud disaster-recovery backup of the production database (incremental) | Yes, once the replication is in operation: the disaster-recovery backup would carry the full production dataset, including PHI. No copy exists today. | Not applicable. No storage account holds a copy of the production dataset today | BAA executed with Microsoft. Octicase is confirming with Microsoft that Azure Blob Storage is an in-scope service under it |
| Speech and voice vendors engaged by Retell AI | Retell's published documentation lists ElevenLabs, Cartesia and MiniMax for text-to-speech, and Azure, Deepgram and Soniox for speech recognition. These are Retell's subcontractors; Octicase does not contract with them directly. The provider actually used depends on the voice configured on each agent. | Possible. The text sent for synthesis is whatever the agent says out loud, and the audio sent for recognition is whatever the caller says. Both can contain PHI where case-assist features are enabled. | Varies by vendor - not published by Retell | Retell does not publish a subprocessor list. Provider has requested from Retell, and does not yet hold, written confirmation of the speech and voice providers permitted on a HIPAA-enabled account and of the Business Associate Agreements Retell holds with each, which 45 CFR 164.308(b)(2) requires of a business associate engaging subcontractors. Until Provider holds that confirmation, the voice configured on each agent is restricted to a provider Retell has confirmed in writing is covered, and the case-assist features that read matter information aloud remain disabled. This row will be revised, with the date, when the confirmation is received. |
| CourtListener (Free Law Project), Caselaw Access Project, OpenStates, GovInfo, California Leginfo | Public legal corpus ingestion and citation verification. Outbound queries only; citation strings are transmitted for verification | No - no Customer Data, PHI or personal information is transmitted | US | N/A (no PHI). Attribution obligations of each source apply |
| Google Cloud Speech-to-Text (not enabled) | Dedicated speech recognition with speaker diarisation for voice transcription. A distinct service from Vertex AI. Disabled by default; the default transcriber remains Gemini via Vertex AI | Yes, if enabled - call audio can contain PHI | us-multi-region | Covered in principle by the executed Google Cloud BAA; Octicase will confirm that Speech-to-Text is a HIPAA-covered product under that BAA before the feature is enabled. Disclosed here while disabled so that the thirty-day notice and objection process of Sections 2 and 3 can run before the change, not after |
| Integrated video-conferencing tool (provider to be named; planned, not live) | Video consultations between Customers and experts or consultants inside the platform, where both choose to use it; call content may include case discussion | Possible, where a consultation discusses a patient's condition; a BAA is a condition of engagement (see the BAA Status column). Whether calls are recorded or transcribed, by which vendor, and where any recording is stored will be stated here before the feature goes live | To be a United States region, stated here before the feature goes live | Not yet engaged. Disclosed in advance so the notice and objection process runs before enablement; a BAA and a no-training clause are conditions of engagement. This advance row does not start the notice period of Section 2; a notice naming the provider will be issued before enablement. |
If Octicase engages a new subprocessor or materially changes the scope or services of an existing subprocessor, we will:
If a Customer objects to the appointment or change of a subprocessor, the Customer must email privacy@octicase.com with a description of the objection within thirty (30) days of the notice. The subject line should read: "Subprocessor Objection -- [Organization Name]."
Upon timely objection, Octicase will work with the Customer in good faith to resolve the concern. If resolution is not feasible and the Customer remains objecting, the Customer may terminate the affected Services without penalty, and Octicase will refund the pro-rata portion of any prepaid fees covering the period after the effective date of that termination, as Section 4.3 of the Data Processing Addendum and Section 5 of the Business Associate Agreement provide.
For questions about this list or to submit an objection: privacy@octicase.com