Providers & subprocessors
A point-in-time register of provider paths present in the application and the production facts that remain unconfirmed.
How to read this register
A provider named here has an architecture or code path in the reviewed application. That does not by itself prove the integration is enabled in production or settle whether the provider is legally a processor or subprocessor for every customer context.
This is not yet a contractual subprocessor schedule. Legal entities, account owners, plans, regions, contracts, retention, backups, deletion, incident contacts, and change-notice methods remain pending operator confirmation and t16 approval.
Current architecture and integrated paths
- Vercel — application hosting and scheduled jobs; production plan, regions, logs, backups, and contract details are pending.
- Postgres hosting — application data storage; the current production provider, legal entity, regions, backup or PITR behavior, and contract details require confirmation.
- LiveKit — realtime audio and screen-share transport, participant identity, rooms, tokens, and service telemetry; production activation and provider settings require confirmation.
- Microsoft identity platform / Entra — conditional interactive sign-in under openid, profile, email, and User.Read; production registration and provider facts require confirmation.
Conditional or optional integrations
Live production enablement, exact providers and models, customer authorization, data-use terms, regions, retention, contracts, and deletion or export behavior are not approved public facts.
- Google OAuth for interactive identity and profile data
- Postmark or a configured SMTP provider for authentication email
- Sentry for exceptions and deliberately attached diagnostic context
- Microsoft Teams / Power Automate for optional notification payloads and outcomes
- An OpenAI-compatible organizer provider when a project explicitly enables and configures it
- GitHub or an internal Git / Forgejo-compatible provider for selected repository reads and evidence
Point-in-time negative findings
These are implementation findings from the August 3, 2026 review, not promises that Mosaic will never add a provider or feature. Any addition requires provider, policy, consent, retention, deletion, and contract review before release.
- No payment-processor dependency or configuration was found in the reviewed tree.
- No advertising network or general behavioral-analytics SDK was found in the reviewed tree.
- No LiveKit Egress, media recording, transcription, or media-storage destination was found in the reviewed application code.
Provider changes
A customer-notice period, subscription method, provider activation dates, and contractual change process have not yet been approved. This page will record a new version and dated summary when confirmed provider facts change.
Change history
- Draft 0.1 ·
Initial fact-checked publication draft. It is not effective and has not been approved as a legal or contractual commitment.