Subprocessor List
a11 Accessibility uses the third-party subprocessors below to provide the a11 platform (AI video captioning, audio description, and document remediation). This list is updated as our subprocessors change.
Compliance certifications listed are those the provider publishes for its own services; a11 does not itself hold SOC 2 at this time. Certification entries marked "verify" or "see provider" should be confirmed against the provider's current trust documentation before contractual reliance.
AI Subprocessors (one-time inference; no training on submitted data)
These providers receive source media and/or derived data to generate accessibility outputs. Data is used for one-time inference only and is not used to train their models.
| Subprocessor | Purpose | Data categories | Location | Compliance | |---|---|---|---|---|| OpenAI | GPT-4o-mini text processing; text-to-speech | Transcripts/text, generated audio | US | SOC 2 Type 2; API data not used for training | | Google Vertex AI / Gemini | Video/visual description; OCR enrichment | Source video/images, derived descriptions/text | US (Google Cloud) | SOC 2, ISO 27001, ISO 27017/27018; Vertex AI does not train on submitted data [confirm Vertex backend] | | MathPix | Math and table OCR | Document images/regions, derived text | US / provider infrastructure | SOC 2; does not train on submitted data |
Speech-to-text (Whisper large-v3) transcription and speaker diarization run self-hosted on our Modal GPU compute — audio is not sent to any third-party transcription service.
Infrastructure & Operational Subprocessors
| Subprocessor | Purpose | Data categories | Location | Compliance |
|---|---|---|---|---|
| Amazon Web Services (AWS S3) | Source-media storage (AES-256) | Source media | US (us-west-2) |
SOC 2 Type 2, ISO 27001, PCI DSS |
| Supabase | Postgres database, auth, backups | Accounts, derived data, metadata | US | SOC 2 Type 2 |
| Vercel | Frontend application hosting | Account/session data, request metadata | US / global edge | SOC 2 Type 2 |
| Railway | API/backend hosting | Application data in transit/processing | US | SOC 2 (see provider) |
| Modal | GPU compute for inference pipelines (incl. self-hosted Whisper speech-to-text) | Source media/derived data during processing | US | SOC 2 Type 2 |
| Resend | Transactional email delivery | Name, email address | US | SOC 2 Type 2 |
| Kaltura | Pulls the institution's own source video | Source video | US / provider infrastructure | SOC 2, ISO 27001 (see provider) |
| Sentry | Error and performance monitoring | Diagnostic/error metadata | US | SOC 2 Type 2 |
| PostHog | Product analytics | Usage events, account identifiers | US (US cloud) | SOC 2 Type 2 |
| Namecheap | DNS management | Domain/DNS records (no customer content) | US | See provider |
| Stripe (planned/future) | Payment processing | Billing/payment details | US | SOC 2 Type 2, PCI DSS Level 1 |
Data Location Summary
All primary storage is in the United States: source media in AWS S3
(us-west-2, AES-256) and structured data in Supabase
Postgres (US, AES-256). Encryption is applied in transit (TLS) and at
rest (AES-256). Some subprocessors may process data in additional
regions per their own infrastructure.
Notification of Changes
We maintain this list as our current subprocessors. When we add or replace a subprocessor that processes institutional content, we update this list with a new Effective date and, for Enterprise and contracted customers, provide advance notice through the account contact where the applicable agreement requires it. Institutions may subscribe to updates or object to a new subprocessor as provided in their agreement.
Contact
a11 Accessibility — Owen Wayment, CEO Email: service@a11accessibility.com Provo, UT, USA
a11 Accessibility · Provo, UT, USA · service@a11accessibility.com