WiBizTrust Center
Service-provider transparency

Providers, roles, and data locations

This organisation-level register identifies provider categories in the current estate and the limits of the available public evidence. It is not a promise that every provider processes every client's data. The signed build-specific schedule controls for an assessed service.

Neon

Purpose

Managed PostgreSQL database service when selected for a build

Data

Application and operational records defined by the build

Location evidence

Verified for the referenced Pulse production project: AWS Asia Pacific Singapore

Boundary

Project-specific. Other builds require separate verification.

Vercel

Purpose

Web application hosting and delivery when selected for a build

Data

Web requests, application content, deployment and service logs as configured

Location evidence

Build-specific and provider-managed. Exact processing and log locations must be confirmed in the build annex.

Boundary

Active provider review and build-specific role assessment required.

Railway

Purpose

Application and worker workloads when selected for a build

Data

Service traffic, application records, configuration metadata, and logs as configured

Location evidence

Build-specific. Exact service region and transfer paths must be confirmed in the build annex.

Boundary

Active provider review and build-specific role assessment required.

SiteGround

Purpose

Corporate website and email services

Data

Website, contact, account, and email data associated with the selected service

Location evidence

Provider-managed. Exact mailbox and service locations are not yet confirmed for a universal public claim.

Boundary

Corporate service. A current authentication limitation for business email remains recorded as an open exception.

Dropbox

Purpose

Controlled business document storage and collaboration

Data

Business and engagement records placed in the service

Location evidence

Provider-managed. Exact storage and support-access geography is not yet confirmed for a universal public claim.

Boundary

Applicability and disclosed data depend on the engagement.

Meta

Purpose

Messaging and channel services when selected by a client

Data

Channel identifiers, messages, media, and interaction metadata as configured

Location evidence

Provider-managed and service-dependent

Boundary

Exact product, role, purpose, transfer, and retention require build-specific confirmation.

Payment service providers

Purpose

Payment collection and payment-service administration when selected

Data

Payment, account, transaction, and anti-fraud data determined by the payment flow

Location evidence

Provider and merchant arrangement dependent

Boundary

The provider may act as an independent controller rather than a subprocessor. The role is assessed per flow and contract.

Specialised processing providers

Purpose

Media, language, automation, or other advanced functions only when included in a build

Data

Only the data categories and instructions approved for the specific function

Location evidence

Provider, account, and feature dependent

Boundary

The exact provider, data use, retention, training setting, and transfer path must be disclosed in the build-specific schedule.

Role and contract status matter

A provider is not automatically a subprocessor. Payment providers and other services may act as independent controllers. Each production schedule records the legal role, service, data, purpose, location, safeguards, review status, and open evidence before client approval.