Legal & compliance11 documents

Subprocessors

Last updated 28 July 2026

Every third party we use to deliver trellOS, what it does, what data reaches it, and whether it is covered by a business associate agreement.

Two entries say “no BAA”. They are on this list precisely because they are the interesting cases — a vendor that will not sign one is still safe to use if the architecture guarantees it never receives protected health information, and both of those guarantees are enforced in code rather than by policy. The reasoning is written out beside each.

Questions about anything on this page? compliance@trellos.org