Current provider register
| Provider | Role and information | Location and boundary |
|---|---|---|
| Vercel | Website hosting, global edge delivery, server-side functions, scheduled jobs, and platform logs. Web requests and headers, content sent to application routes, deployment metadata, and operational logs. | Static content may be delivered globally. The current function and log regions are provider-account settings and are not asserted on this page. Boundary: Vercel operates the application layer. It is not authorized here to use form contents for Kaizen advertising. |
| Neon | Managed PostgreSQL database used by persisted website and operational workflows. Contact submissions, prior research records, moderated comments, consented first-party analytics, delivery state, and administrative records where a feature requires persistence. | The database region is an account configuration that must be confirmed for a specific procurement review. This page does not claim Canada-only storage. Boundary: Database access is server-side. Public pages do not receive database credentials. |
| Resend | Requested transactional email and delivery-event processing. Recipient and sender addresses, requested email content, message identifiers, and minimized delivery status. | Provider processing may occur outside British Columbia or Canada. Exact location commitments require contract-specific confirmation. Boundary: Kaizen does not intentionally store custom open-pixel events; opened and clicked webhook events are ignored by the current application. |
| Google Workspace | Operational mailboxes and correspondence with people who contact Kaizen. Email addresses, message contents, and attachments a sender chooses to provide. | Google-controlled processing may occur outside British Columbia or Canada. Do not email passwords, payment details, health records, or other sensitive records. Boundary: Google Workspace is an operational communication provider, not the website application database. |
| GitHub | Source control, automated code checks, dependency/security review, and private vulnerability reporting when that repository setting is enabled. Application source, change and CI metadata, and security-report content a reporter submits through GitHub. | GitHub is a global service. Website form and prior research records are not intentionally written to the source repository. Boundary: Personal or customer records must not be placed in source, issues, pull requests, or CI output. |