Trust Centre
Subprocessor register
This register identifies service providers that may process personal information or customer content for SR&ED Copilot. A provider receives customer content only when necessary for the stated service or when the customer activates the relevant feature.
Effective: July 14, 2026
Appointed service providers
| Provider | Purpose | Data involved | When used | Location note |
|---|---|---|---|---|
| Render | Application, API, and managed database hosting | Account data, customer content, integration tokens in encrypted form, logs, and service metadata | Core service | Core production hosting is currently in the United States on Render; Canada-only residency is not available |
| Cohere | Hosted AI narrative generation | The generation prompt and evidence text selected for the request | When a customer uses the default hosted Cohere model | Provider-controlled processing; do not assume Canada-only processing |
| Anthropic | Optional AI narrative generation | The generation prompt and evidence text selected for the request | Only when an Anthropic model is selected and available through hosted or customer-supplied credentials | Provider-controlled processing; may include the United States |
| OpenAI | Optional AI narrative generation | The generation prompt and evidence text selected for the request | Only when an OpenAI model is selected and available through hosted or customer-supplied credentials | Provider-controlled processing; may include the United States |
| Stripe | Subscription checkout, invoicing, and payment processing | Billing contact, organization and transaction metadata; card data is entered into Stripe and is not stored by SR&ED Copilot | When billing or checkout is used | Provider-controlled processing, including the United States and other locations described by Stripe |
| Resend | Transactional email delivery | Recipient email address and the content of account, security, billing, or support-related messages | When the service sends transactional email | Provider-controlled processing; may include the United States |
| Google Ads | Public-site campaign attribution and completed-sign-up conversion measurement | Public page URL and title, browser/device/network metadata, consent state, permitted ad-click identifiers, and a completed-sign-up event; no registration form fields or SR&ED customer content | Only on designated public marketing and registration routes; advertising storage is denied by default and the tag is excluded from dashboard, welcome, invitation, and password-reset routes | Provider-controlled global processing, including the United States; do not assume Canada-only processing |
Customer-directed connections
The following services are not activated by default. If an account owner connects one, that provider remains subject to the customer's own agreement with it, and SR&ED Copilot exchanges the scopes and records the customer authorizes:
- GitHub
- GitLab
- Atlassian Jira
- Slack
- Microsoft Teams
- Microsoft Azure DevOps
- Bitbucket
Browser measurement status
Google Ads is limited to designated public marketing and registration routes and receives a completed sign-up event only after the registration API succeeds. Consent mode denies advertising and analytics storage by default and presents an allow/decline control. Declining keeps advertising storage denied and uses redacted, cookieless signals. Google Ads is not loaded on authenticated dashboard, welcome, invitation, or password-reset routes. Product and evidence identifiers, claim content, registration form fields, account email addresses, and authenticated page URLs are not sent by this measurement code. Plausible and PostHog remain disabled.
AI-specific controls
- Only the project context, evidence selected for a generation request, and generation instructions are sent to the selected AI provider.
- An organization owner can disable AI processing, require customer-supplied provider keys, or allow only selected providers.
- Data minimization limits the request to project name, description, fiscal year, and technology stack; selected evidence IDs, sources, titles, summaries, dates, and tags; instructions; and draft narrative text when improving a draft. Evidence links and raw integration payloads are excluded.
- Hosted and customer-supplied-key requests still send content to the selected provider; supplying a key changes credentials, not the data path.
- Customer-supplied API keys are used for the request and are not intentionally persisted by SR&ED Copilot.
- SR&ED Copilot does not use customer content to train its own models and relies on applicable provider API terms for provider training restrictions.
- Customers should redact secrets, personal data, and technical detail that is not needed for the draft.
Changes and objections
We will update this page before or promptly after a material provider change. Where a signed agreement requires advance notice or an objection period, that agreement controls. Self-service customers who object to a new material subprocessor may stop using the affected feature, export available records, and request deletion before the provider is used for their future requests. We cannot promise that every core provider can be replaced for an individual self-service account.
Need a vendor document?
Review the DPA framework and Security & Data Handling, then email legal@sredcopilot.ca with any required contractual terms.
Return to the Trust Centre.