Bookify Subprocessors

Updated: March 11, 2026

This page lists the primary third-party providers Bookify uses, or expects to use, to deliver hosted services, communications, payments, identity, and optional integrations. It is intended as a public summary, not a complete security questionnaire or contractual schedule.

Regulated-data support is conditional. Not every feature, integration, or deployment path on this page is approved for regulated data. Where a service is marked conditional or blocked, additional approvals, agreements, or infrastructure changes are required before regulated-data use.

Customer-configured third-party services connected independently by Subscribers may introduce additional subprocessors that are outside this public list until they are formally adopted or approved by Bookify.

Infrastructure

VendorPurposeStatusNotes
Amazon Web Services (AWS)Production runtime — compute (ECS Fargate), database (RDS PostgreSQL), storage (S3), encryption (KMS), secrets management, logging (CloudWatch/CloudTrail), firewall (WAF)Active — regulated-data approvedHIPAA-eligible infrastructure. All production workloads run on AWS in us-east-2. Encryption at rest and in transit. BAA required and pending acceptance.
PostgreSQL (AWS RDS)Primary application databaseActive — regulated-data approvedEncrypted at rest (AES-256 via KMS), Multi-AZ, private subnet, 30-day automated backups with point-in-time recovery.
CloudflareDNS management onlyActive — DNS onlyDNS-only mode (proxy disabled). No application traffic or data transits Cloudflare. Used for DNS record management and CNAME flattening.

Communications and Messaging

VendorPurposeStatusNotes
Amazon SESTransactional email deliveryActive — regulated-data approvedRegulated-mode email content uses generic portal-only prompts. Covered under AWS BAA.
TwilioSMS deliveryConditionalUsed only for generic notifications in regulated mode unless additional approvals and agreements are in place. BAA required for regulated use.

Payments

VendorPurposeStatusNotes
StripePayment processingApproved for payments scopeSensitive service-record content is not permitted in metadata, descriptions, receipts, or mirrored logs.
MonerisPayment processingApproved for payments scopeSensitive service-record content is not permitted in metadata, descriptions, receipts, or mirrored logs.

Identity, Integrations, and Optional Services

VendorPurposeStatusNotes
Google OAuthIdentity federation and account sign-inConditionalApproved for identity use. This does not imply approval for all other Google-connected services.
Google CalendarCalendar synchronizationBlocked by default for regulated dataSensitive details are redacted or blocked unless the workspace and connection are explicitly approved.
OpenAI APIPrimary generation for AI-powered document featuresConditionalOnly selected extracted document passages are sent. Responses API calls disable response storage. Regulated or otherwise sensitive-data use still requires an explicitly approved workspace and vendor posture.
WherebyEmbedded video sessionsConditionalAvailability for regulated-data workflows depends on approved configuration and contractual review.
Google reCAPTCHAAbuse prevention and bot detectionApproved for anti-abuse useUsed for challenge and verification flows, not as a subscriber data processor for service records.

Questions

For vendor, agreement, or regulated-data questions, contact privacy@bookify.com.

Bookify
© Copyright Bookify Software Inc. 2026. All rights reserved.