Sub-processors
Last updated: 2026-10-09
This page is the canonical, current list of sub-processors that Trial Commander (iHOST LABS, LLC) engages to process Customer Data on your behalf. It is the list referenced by § 7 of our Data Processing Agreement. We keep it here so changes are public and verifiable.
A sub-processor is a third party that processes Customer Data on our behalf. We engage our sub-processors under written data-protection terms — for most, the provider's own data processing addendum, which forms part of the terms we accepted when we opened the account — and we remain liable for their compliance. Three providers on this list do not process Customer Data on our behalf in that way, and the notes below explain each: Intuit (QuickBooks Online) and Google (Google Calendar) act as independent controllers of the information a firm or user exchanges with them, under their own terms; and Free Law Project is engaged only under its public API terms.
Current authorized sub-processors
| Sub-processor | Purpose | Data Category | Location | Certifications |
|---|---|---|---|---|
| Clerk Inc. | Authentication | User identity, session | USA | SOC 2 Type II |
| Stripe Inc. | Payment processing | Billing info | USA | PCI-DSS Level 1, SOC 2 |
| Anthropic PBC | AI processing (no model training on customer data; retention per the AI Disclosure) | Matter content for AI features | USA | SOC 2 Type II |
| Postmark (AC PM LLC) | Transactional email | Recipient info | USA | SOC 2 Type II |
| Sentry (Functional Software, Inc.) | Error monitoring | Stack traces (PII scrubbed) | USA | SOC 2 Type II |
| Cloudflare, Inc. (R2) | File storage and backup storage | Uploaded documents; and the Service's daily per-firm database backups, which contain all Customer Data | USA | SOC 2 Type II |
| Upstash Inc. | Rate limiting / Redis | IP, hashed user IDs | USA | — |
| Intuit Inc. (QuickBooks Online) | Accounting sync — only for firms that connect QuickBooks | Client name, client billing email, invoice and payment amounts and dates, matter reference | USA | — |
| Microsoft Corporation (Azure, Microsoft Graph) | Application hosting and database; document sync and email filing (OneDrive/SharePoint, Outlook) for firms that connect them; calendar sync for users who connect their own Microsoft 365 / Outlook calendar (push, and reading that user's own events back to show them in the Service); speech-to-text transcription of deposition audio (Azure AI Speech) in Crucible, for firms that use transcription on our servers — from the effective date in the change note of 2026-10-09 below | All Customer Data; where a firm connects document sync or email filing, also matter documents and the client email bodies and attachments it files; where a user connects their Outlook calendar, the deadlines and consultations pushed to it (the same fields as the Google Calendar row below); for deposition transcription, the recorded audio and, as recognition hints, the deponent's and the matter's names (the audio is not stored by us) | USA (East US 2 — Virginia) | SOC 2 Type II, ISO 27001, HITRUST |
| OpenAI, L.L.C. | Voice-memo transcription (model whisper-1) — only once it is set up on the Service | When set up: the audio of voice memos users record; the transcript is returned to Trial Commander | USA | — |
| Free Law Project (CourtListener) | Case-law research search, citation check and federal docket tracking (docket tracking not yet available) | The case citations found in a draft or a Word selection (never the draft or the selection itself); the search terms users type into Legal Research; once docket tracking is available, the case numbers and courts a firm asks to track | USA | — |
| Google LLC (Google Calendar) | Calendar sync — only for users who connect their own Google Calendar, and only once connecting is set up on the Service: push, and reading that user's own events back to show them in the Service | For each deadline pushed: its title, date, priority, rule and trigger, the matter number and name, and the client's name; for each consultation pushed: the time and location, and the prospective client's name, email, phone and stated reason | USA | — |
Notes on key processors
- Anthropic (AI). Your matter content is never used to train models, in either retention mode. Trial Commander currently operates on Anthropic's standard API retention: Anthropic may hold API inputs and outputs for a limited operational period — approximately 30 days — for abuse and safety monitoring, after which they are deleted. We have requested Zero-Data-Retention on our Anthropic account and will operate under it once Anthropic confirms activation; the mode that is live is always shown in the app at Settings → AI Limits → Data retention, and stated in the AI Disclosure. A firm that requires zero retention before using cloud AI may switch on "Require zero retention" in Settings (which pauses that firm's cloud AI until ZDR is live), connect its own Anthropic API key, or use per-matter local AI. AI processing is disclosed per Florida Bar Rule 4-5.3.
- Intuit (QuickBooks Online). Engaged only when a firm connects its own QuickBooks company. When connected, we push invoices, recorded payments and (if the firm maps trust accounts) trust movements, which carries the client's name and billing email, the amounts and dates, and a matter reference in the invoice memo. No documents, notes or matter content are sent. A firm can disconnect QuickBooks at any time in Settings → QuickBooks Sync, which stops all further transmission. Under Intuit's developer terms, Intuit and Trial Commander are independent controllers of that information, not processor and sub-processor: Intuit holds what we push under the firm's own agreement with Intuit, and does not process it on our behalf.
- Microsoft Azure / Cloudflare R2. Customer Data and uploaded documents are encrypted in transit (TLS 1.3) and at rest (AES-256); sensitive fields receive additional application-level field encryption.
- Microsoft Graph (document sync, email filing and calendar push). Engaged only when a firm connects OneDrive/SharePoint or an Outlook mailbox, or a user connects their own Microsoft 365 / Outlook calendar. Document sync copies matter documents between Trial Commander and the firm's own Microsoft tenant; email filing reads messages from the connected mailbox and files them — including bodies and attachments — to the matter. Calendar push writes into the connecting user's own Outlook calendar the deadlines and consultations the Google Calendar row above lists, field for field; calendar sync also reads that user's own events back, exactly as described for Google Calendar below. Document sync and email filing are per-firm and can be disconnected in Settings → Document Sync and Settings → Email; calendar push is per-user and can be disconnected in Settings → Calendar Sync.
- Search by meaning — not yet connected. Search in Trial Commander matches words: the firm-wide search and the Brief Bank find the words you type, and similar-matter matching compares matter fields. No text is sent to an outside provider to be searched by meaning. If a provider for search by meaning is connected later, it will be added to this list, with notice, before any text is sent to it.
- OpenAI (voice-memo transcription). OpenAI is a new sub-processor as of 2026-09-27; the change note of 2026-09-29 below says when it may be used. Transcription runs only once it is set up on the Service, and the voice-memo page says whether it is. Until then voice memos can be recorded but are not transcribed, and nothing is sent to OpenAI. When it runs, only the recorded audio of a voice memo is sent, and only when a user records one. OpenAI's published API data controls (developers.openai.com/api/docs/guides/your-data, read 2026-09-27) state that data sent to the OpenAI API is not used to train its models unless the customer opts in — we have not (our organization's data-sharing settings were checked on 2026-09-29: sharing inputs and outputs with OpenAI is off) — and list the audio-transcription endpoint with no abuse-monitoring retention and no application-state retention. Those are OpenAI's own published terms; we have no separate agreement with OpenAI on retention.
- Free Law Project (CourtListener). Free Law Project is a nonprofit that publishes the CourtListener API under its own public terms. We have no data-processing agreement with it beyond those terms, which is why only the items in the table are sent: citation check extracts the case citations locally — only text that names a known case reporter, such as "760 So. 2d 126" — and sends only those citation strings, never the surrounding text, and it sends nothing until its CourtListener API token is set; Legal Research sends the words the user types as the search; docket tracking, once it is available, will send the case number and court. A user should not type client-confidential facts into the Legal Research search box. Statute check works the same way without CourtListener: it finds the statute and regulation sections cited in a draft locally and requests only the public page for each section from Cornell's Legal Information Institute (U.S. Code, C.F.R.) or the Florida Senate (Florida Statutes). Those public law sites receive a request for that page, as any visitor's browser sends, and never the draft; they are not listed as sub-processors for that reason.
- Google Calendar. Google is a new sub-processor as of 2026-09-27; the change note of 2026-09-29 below says when it may be used. Connecting runs only once it is set up on the Service, and Settings → Calendar Sync says whether it is. Until then no user can connect a Google account and nothing is sent to Google. When it is set up, Google is engaged only when a user connects their own Google account in Settings → Calendar Sync. Events are written into, and read back from, that user's own calendar, where Google holds them under the user's own agreement with Google; Trial Commander's connection is governed by Google's API terms. Google acts as an independent controller of that calendar, not as our processor. The read-back takes each event's title, start and end time, all-day flag and link for a date range, to show the user's events beside matter deadlines (the Deadlines page shows the next 60 days) and to keep a booking page from offering a time the user is busy; it is not stored, except when the user imports a day's events into Chronicle as time blocks, which keeps their title, times and link with each block. For per-matter calendar routing, Trial Commander also reads the names and ids of the calendars the user can add events to, when the routing card is opened; only the id of the calendar the user picks for a matter is stored. How Trial Commander handles Google user data, including the Limited Use statement, is set out in the Privacy Policy under "Google user data". A user can disconnect at any time in Settings → Calendar Sync, which stops all further pushes.
- Microsoft Azure AI Speech (deposition transcription). A new purpose for an existing sub-processor, used only from the effective date in the change note of 2026-10-09 below. Then it is engaged only when a firm uses transcription on our servers for audio an attorney records in Crucible, and never for a matter set to keep all AI features on the attorney's computer. The recorded audio (in parts of a few minutes) is sent to Azure AI Speech in East US 2 with the deponent's and the matter's names as recognition hints, and the transcript comes back; Trial Commander keeps only the transcript and does not store the audio. Microsoft's published documentation (learn.microsoft.com, "Data, privacy, and security for Speech to text", read 2026-10-09) states that for fast transcription, the kind we use, "Microsoft does not retain or store the data provided by customers", and that the voice signals used to tell speakers apart are discarded when the transcription is complete. Microsoft processes this data under the Microsoft Products and Services Data Protection Addendum.
- Twilio and RingCentral — not sub-processors. A firm can connect its own Twilio or RingCentral account (Settings → VoIP) so that text messages its clients send to the firm's Twilio number, and records of the firm's phone calls, reach Trial Commander (see the Privacy Policy § 2.1). Those messages and calls are carried by the firm's own account, under the firm's own agreement with that provider, and we receive the records through the credentials the firm gives us. We do not engage Twilio or RingCentral, or send them Customer Data on our behalf, so they are not listed as Trial Commander sub-processors — in the same way that a browser's own speech-recognition service is not (Privacy Policy § 4.2). Trial Commander cannot yet send text messages to clients; when it can, they will go out through the firm's own Twilio account.
- HIPAA. Trial Commander does not currently offer a Business Associate Agreement on any plan. Of the sub-processors that would handle PHI, the BAAs with Anthropic, Postmark and Cloudflare are not executed, and there is no BAA with OpenAI or Google. See the HIPAA Addendum.
Change note (2026-10-09, Microsoft). A new purpose for an existing sub-processor: the Microsoft entry now includes speech-to-text transcription of Crucible deposition audio through Azure AI Speech, a new purpose and a new data category (deposition audio, with the deponent's and the matter's names as recognition hints). Notice of this change is emailed to customer Controllers, and Trial Commander does not use Azure AI Speech for transcription before the effective date that notice states, thirty days after it was sent. A Controller may object within 14 days of that notice, as described under "Notice of changes".
Change note (2026-10-09). Deepgram, Inc. (transcription of deposition audio) is listed below under "Proposed sub-processor — not yet in use". It is not an authorized sub-processor, it is not in the table above, and Trial Commander sends it nothing: the Service's code refuses to use it. It will be added to the table only after notice to customer Controllers as described under "Notice of changes", and no sooner than 30 days after that notice; no notice has been sent. On the same day we corrected the description of how the providers on this list are engaged (top of this page): Intuit and Google act as independent controllers under their own terms, not as our processors. Sentry's data processing addendum (version 5.1.0), which Sentry has customers accept separately from its terms of service, was accepted on 2026-10-09. We also added a note explaining why Twilio and RingCentral, which a firm connects with its own account, are not sub-processors. No sub-processor was added or removed, and, apart from the Microsoft change in the note above, no data goes anywhere it did not go before.
Change note (2026-09-29). Notice of the 2026-09-27 changes was emailed to customer Controllers on 2026-09-29, and it gave a date 30 days later before OpenAI and Google would be used. On 2026-09-29 we decided not to wait for that date: OpenAI (voice-memo transcription) and Google (Google Calendar push) may be used from 2026-09-29, sooner than the 30 days' advance notice described under "Notice of changes". Each is used only once its feature is set up on the Service, and only when a user records a voice memo or connects their own Google Calendar. A Controller may still object to either within 14 days of that notice, as described under "Notice of changes". A later new sub-processor gets the full 30 days' advance notice.
Change note (2026-09-27). This list was updated on 2026-09-27. Two new sub-processors: OpenAI, L.L.C. (voice-memo transcription) and Google LLC (Google Calendar push, for users who connect it). When this note was written, Trial Commander was not to use either until at least 30 days after notice of this change was sent to customer Controllers; that wait was later waived (change note of 2026-09-29). Two disclosures of processing that already happens. First, Free Law Project (CourtListener: research search, citation check, docket tracking) is listed because Legal Research's case-law search has sent the words a user types to CourtListener since that feature shipped, without an API token, and that was not disclosed until now; citation check sends nothing to CourtListener until its API token is set, and docket tracking is not yet available. Second, the Microsoft entry did not mention calendar push: a user who connects their own Outlook calendar has had deadlines and consultations written into it through Microsoft Graph, and the entry now says so. Both should have been listed, with the 30 days' advance notice described under "Notice of changes", before that processing began; they were not. We are giving customer Controllers notice of all four changes by email, and a Controller may object to any of them within 14 days of that notice, as described under "Notice of changes". Search by meaning is not connected, and no provider for it is listed.
Change note (2026-09-15). Correction to the Cloudflare (R2) entry. This list described the data Cloudflare holds as "Uploaded documents". That understated it: R2 also stores the Service's daily per-firm database backups, which contain all Customer Data, not only uploaded files. No new sub-processor was added and nothing about where the data actually goes has changed — Cloudflare has held those backups for as long as the backup job has run. Only the disclosure was wrong, and it is corrected above. Because correcting a sub-processor's stated data categories is itself a material change under "Notice of changes" below, this note records it: on this date the only firm with an account on the Service was the law firm of the owner of iHOST LABS, LLC, so no customer Controller other than the operator's own firm existed to receive 30 days' advance notice.
Change note (2026-09-14). Notice of the 2026-09-13 changes. On 2026-09-13 this list added Intuit Inc. (QuickBooks Online) and expanded the Microsoft entry to name Microsoft Graph document sync and email filing. The 30 days' advance notice described under "Notice of changes" was not given before those changes were published. On that date the only firm with an account on the Service was the law firm of the owner of iHOST LABS, LLC, which had connected Microsoft document sync and had not connected QuickBooks; no customer Controller other than the operator's own firm existed to receive notice. Separately, the HIPAA note above was corrected on 2026-09-14: Trial Commander does not currently offer a Business Associate Agreement.
Change note (2026-09-13). Two corrections and one addition. (a) The Anthropic entry previously stated that AI features run on a Zero-Data-Retention tier. That is not the configuration in production: the platform runs Anthropic's standard API retention, and the entry now says so. Training on customer data is not permitted in either mode. (b) Intuit Inc. (QuickBooks Online) has been added, and the Microsoft entry now also names Microsoft Graph document sync and email filing; both are per-firm integrations a firm must connect itself.
Change note (2026-08-19). Database hosting moved from Supabase, Inc. to Microsoft Azure, consolidating application and database hosting with a single sub-processor. This reduced the number of sub-processors from nine to eight; no sub-processor was added, and no new category of data was disclosed to any party. The change was made before general availability, so no Customer Data was ever held by Supabase.
Proposed sub-processor — not yet in use
A provider listed here is one we propose to engage. It is not an authorized sub-processor, and Trial Commander sends it nothing. It will be moved into the table above only after notice to customer Controllers as described under "Notice of changes" below, and no sooner than 30 days after that notice. Until then the Service's code refuses to use it, whatever the Service's settings say.
- Deepgram, Inc. (San Francisco, California)
- Purpose: speech-to-text transcription of deposition audio in Crucible, Trial Commander's deposition workspace — once server transcription is set up on the Service, as an alternative to the browser's own speech recognition or typed and pasted capture.
- Data category: the audio a user captures during a deposition session in Crucible, sent in parts of at most 5 MB as it is captured; the transcript (text, speaker labels, timing and detected language) is returned to Trial Commander.
- Location: not yet stated. Deepgram's published documentation names no country for its default (global) endpoint, which is the one Trial Commander's code calls; it guarantees a location only for its regional endpoints (European Union, Australia, India). We will state the location here, from Deepgram's own written terms, before any notice is sent.
- Retention and training: by default Deepgram retains request audio and transcripts to improve its models (its "Model Improvement Program"). Every request Trial Commander's code sends opts out of that program (Deepgram's
mip_opt_outsetting); Deepgram's published documentation (developers.deepgram.com/trust-security/your-data, read 2026-10-09) states that for opted-out requests the audio and transcript are retained only for the duration needed to process the request. We have no separate agreement with Deepgram yet. - Status: proposed. No notice has been sent, and Trial Commander does not use Deepgram.
Notice of changes
We maintain this list at https://www.trialcommander.com/sub-processors. Material changes (adding a new sub-processor or materially changing the data a processor handles) require 30 days' advance notice to active Controllers. Controllers may object within 14 days of notice; we will work to address the concern or offer cancellation with a pro-rated refund of prepaid, unused fees.
Change notices are emailed to every active administrator of your firm, at the email address they sign in with; keep your firm's administrators current in Settings → Team Members. Questions: privacy@trialcommander.com.
This list is operational and kept current as vendors change. The governing terms are in the Data Processing Agreement and Privacy Policy.