Updated: March 11, 2026
This page lists the primary third-party providers Bookify uses, or expects to use, to deliver hosted services, communications, payments, identity, and optional integrations. It is intended as a public summary, not a complete security questionnaire or contractual schedule.
Regulated-data support is conditional. Not every feature, integration, or deployment path on this page is approved for regulated data. Where a service is marked conditional or blocked, additional approvals, agreements, or infrastructure changes are required before regulated-data use.
Customer-configured third-party services connected independently by Subscribers may introduce additional subprocessors that are outside this public list until they are formally adopted or approved by Bookify.
| Vendor | Purpose | Status | Notes |
|---|---|---|---|
| Amazon Web Services (AWS) | Production runtime — compute (ECS Fargate), database (RDS PostgreSQL), storage (S3), encryption (KMS), secrets management, logging (CloudWatch/CloudTrail), firewall (WAF) | Active — regulated-data approved | HIPAA-eligible infrastructure. All production workloads run on AWS in us-east-2. Encryption at rest and in transit. BAA required and pending acceptance. |
| PostgreSQL (AWS RDS) | Primary application database | Active — regulated-data approved | Encrypted at rest (AES-256 via KMS), Multi-AZ, private subnet, 30-day automated backups with point-in-time recovery. |
| Cloudflare | DNS management only | Active — DNS only | DNS-only mode (proxy disabled). No application traffic or data transits Cloudflare. Used for DNS record management and CNAME flattening. |
| Vendor | Purpose | Status | Notes |
|---|---|---|---|
| Amazon SES | Transactional email delivery | Active — regulated-data approved | Regulated-mode email content uses generic portal-only prompts. Covered under AWS BAA. |
| Twilio | SMS delivery | Conditional | Used only for generic notifications in regulated mode unless additional approvals and agreements are in place. BAA required for regulated use. |
| Vendor | Purpose | Status | Notes |
|---|---|---|---|
| Stripe | Payment processing | Approved for payments scope | Sensitive service-record content is not permitted in metadata, descriptions, receipts, or mirrored logs. |
| Moneris | Payment processing | Approved for payments scope | Sensitive service-record content is not permitted in metadata, descriptions, receipts, or mirrored logs. |
| Vendor | Purpose | Status | Notes |
|---|---|---|---|
| Google OAuth | Identity federation and account sign-in | Conditional | Approved for identity use. This does not imply approval for all other Google-connected services. |
| Google Calendar | Calendar synchronization | Blocked by default for regulated data | Sensitive details are redacted or blocked unless the workspace and connection are explicitly approved. |
| OpenAI API | Primary generation for AI-powered document features | Conditional | Only selected extracted document passages are sent. Responses API calls disable response storage. Regulated or otherwise sensitive-data use still requires an explicitly approved workspace and vendor posture. |
| Whereby | Embedded video sessions | Conditional | Availability for regulated-data workflows depends on approved configuration and contractual review. |
| Google reCAPTCHA | Abuse prevention and bot detection | Approved for anti-abuse use | Used for challenge and verification flows, not as a subscriber data processor for service records. |
For vendor, agreement, or regulated-data questions, contact privacy@bookify.com.