Skip to main content

Subprocessors

Provider and Subprocessor Transparency

MARCUS relies on service providers for hosting, model processing, storage, email, billing, monitoring, and optional integrations. Provider use varies by deployment and enabled feature.

MARCUS's supported product scope is limited to individual and approved institutional non-PHI workspaces. Individual signup is available only when surgicAI explicitly enables it after launch-readiness review. Do not upload, type, paste, connect, or transmit protected health information, patient identifiers, patient-specific clinical facts, credentials, secrets, or other prohibited data. PHI use is not available in this lane. Any future PHI program would require a separate legal, privacy, security, provider, deployment, and institutional approval process.

Last updated: August 5, 2026

This page describes the current engineering posture and explicit limitations. It is not a certification, service commitment, data-processing agreement, authorization for PHI use, or confirmation that customer signup is active. Customer use requires explicit launch activation and compliance with the applicable published policies. Institution-controlled or restricted use may also require a separately approved trust packet and written agreement.

1. Documented Core Providers

Core provider categories
Provider or categoryRoleCurrent evidence limit
VercelFrontend hostingPlan, region, contract, and log retention require account evidence
RailwayAPI, worker, PostgreSQL, and Redis hostingRegion, backup, log, and contract settings require account evidence
OpenAIAnswer generation, search indexing, and configured enrichmentRetention, training-sharing, residency, and account settings require account evidence
S3-compatible storageUploaded originalsActive provider, region, encryption, versioning, lifecycle, and deletion require account evidence

2. Conditional Providers

Conditional integrations can include error monitoring, email, billing, Google Workspace, Microsoft Graph, Dropbox, image tagging, OAuth, and a malware scanner. Code support does not prove that a provider is active in a particular deployment.

3. Deployment-Specific Review

Before institutional use, the approved trust packet must identify active providers, purpose, data categories, region, account controls, contract scope, notice process, retention, and deletion behavior. Public provider documentation does not prove the MARCUS account configuration.

Contact