Compliance

Sub-processors.

Solus uses a small number of third-party service providers to operate the platform. Each has a specific role, a defined data scope, and a data-processing agreement with X Point. Sub-processors are subject to the same confidentiality and security obligations that apply to us under our own Privacy Policy and any customer Data Processing Agreement (DPA).

Last reviewed: August 2026 · Questions or DPA-review requests: soluseditor@gmail.com

Notice: This list may change as the platform evolves. We will notify institutional customers with executed DPAs at least 30 days in advance of any material change to this sub-processor list. Individual users can subscribe to changes by watching this page.
Sub-processor Purpose & data scope Region Category
Supabase
privacy policy →
Managed Postgres database, authentication, storage, and Edge Functions. Stores user accounts, class rosters, assignment metadata, submission records, encrypted .solus files, and system audit data. Encrypted submission content is stored encrypted-at-rest and only readable by the recipient's private key. Supabase staff do not have access to plaintext document content. us-west-2 (AWS) Essential Handles student data
Netlify
privacy policy →
Static-site hosting, CDN, and edge network for every Solus web surface (marketing site, web editor, teacher dashboard, institution portal, admin dashboard, public verifier). Also manages the DNS zone for soluseditor.com. Global (Anycast) Essential
Cloudflare Turnstile
privacy policy →
Bot-detection challenge on the account-signup and password-recovery flows. Turnstile does not use tracking cookies and does not identify individuals. Global Essential
Resend
privacy policy →
Transactional email delivery. Sends account-confirmation emails, password-recovery emails, submission notifications, grade notifications, and institution-approval emails. Recipients' email addresses and message content are transmitted to Resend for delivery only. us-east-1 (AWS) Essential
Stripe
privacy policy →
Payment processing and subscription billing for institutional customers. Handles all card data; Solus does not receive or store card numbers. Institution billing metadata (organization name, contact email, plan) is shared with Stripe. us-west-2 (AWS) Institutional only
GitHub
privacy policy →
Source-code hosting for the Solus repository and the release binary distribution for the desktop app. Does not touch student data. Only source code, application binaries, and Solus staff account information. Global (Azure) Solus staff only

Sub-processors we deliberately don't use

This list is as important as the one above. Solus does not use:

How to be notified of changes

Institutional customers with executed DPAs receive advance notice by email for any sub-processor addition or role change with at least 30 days lead time. Individual users can watch this page and check the last-reviewed date at the top.

Questions

Data Processing Agreement requests, sub-processor evaluations, and security questions: soluseditor@gmail.com. We aim to respond to institutional inquiries within 3 business days.