This Subprocessor Register identifies third parties that Fintant Inc. (“Fintant”) may use to process Client Financial Data or other personal information on behalf of an accounting-firm client.
This draft intentionally distinguishes approved production subprocessors from providers under evaluation, test-only systems, and unselected capabilities. Being named in application code, a test configuration, a contract review, or this draft does not authorize a provider to receive live Client Financial Data.
1. Definitions
Client Financial Data means source records, personal information, financial information, workpapers, outputs, and related metadata submitted or created for an accounting firm under a Client Agreement.
Subprocessor means a third party appointed by Fintant to process Client Financial Data on behalf of an accounting-firm client.
Approved production means that the provider, contracting entity, data flow, security, region, transfer position, retention, deletion, incident duties, access, client authorization, and Fintant release evidence have been approved for the relevant live-data scope.
Under review means the provider is selected, configured, implemented, tested, or being evaluated but is not approved for live Client Financial Data.
Blocked external means the technical or organizational release remains blocked by provider, contract, region, security, ownership, operational, or legal evidence outside the code path.
2. Approved production subprocessors
As of July 30, 2026, no third-party production subprocessor is approved to receive live Client Financial Data.
Fintant must not activate live-data service until this section lists the actual approved production configuration and the matching Client Agreement and Data Processing and Security Addendum authorize it.
2. Approved production subprocessors table.
Approved subprocessor: None. Purpose: No provider is currently approved for live Client Financial Data. Client data: None authorized. Processing location: Not applicable. Transfer mechanism: Not applicable. Approval or change date: Not applicable.
3. Providers under evaluation or limited test
The providers below appear in the current application design or test paths. They are not approved production subprocessors unless and until moved to Section 2.
3. Providers under evaluation or limited test table.
Provider or service: WorkOS, Inc. / AuthKit; exact account entity and accepted agreement unverified. Proposed purpose: Managed identity, organization membership, invitations, WorkOS Magic Auth verified-email code authentication, and session-related events. Password, social OAuth, SSO, passkey, TOTP, and multi-factor authentication are not approved current paths. Proposed data: Name, work email, organization, role, invitation and authentication metadata; no financial-file content. Country or region: To be confirmed from the production account, contract, configuration, and provider evidence. Current status: Implemented in application paths; production account, contract acceptance, region, recovery, configuration, and organizational approval remain blocked external.
Provider or service: Plus Five Five, Inc., doing business as Resend; exact account and accepted agreement unverified. Proposed purpose: Transactional website authentication and one-time-code email only. Resend is not approved for prospect outreach, client workflow mail, or financial attachments. Proposed data: Recipient address, authentication event type, approved safe link or code, and delivery status; no attachments, financial content, or free-text work content. Country or region: To be confirmed from the production account, contract, configuration, and provider evidence. Current status: Adapter and signed callback path verified with synthetic isolated test data; account, domain, contract acceptance, region, retention, secrets, suppression, monitoring, and production approval remain blocked external.
Provider or service: Squarespace, Inc. or Squarespace Ireland Limited / Acuity Scheduling; exact account entity unverified. Proposed purpose: Public prospect scheduling and controlled appointment workflow. Proposed data: Business contact and scheduling information, approved appointment and calendar selectors, and opaque handoff reference; no Client Financial Data. Country or region: To be confirmed from the actual Acuity account, contract, configuration, and downstream-provider evidence. Current status: Application path implemented; provider account, plan, webhook, calendar, organizer, privacy, region, downstream providers, and production approval remain blocked external.
Provider or service: Google Workspace, Calendar, or Meet; provider and account not selected. Proposed purpose: Possible future Acuity calendar and Google Meet connection. Proposed data: Minimum meeting, calendar, organizer, and attendee information; no financial-file content. Country or region: Not applicable until an organization-owned tenant and account are selected and reviewed. Current status: Contemplated only; no organization-owned tenant, approved account, direct Google API integration, Acuity connection, contract acceptance, configuration, test, or production approval exists.
These systems may be approved for limited public-site or account-administration data before they are approved for Client Financial Data. The approved scope must be explicit in the production register and contract.
4. Current limited controller and business-contact systems
The following current or selected limited-purpose systems may handle public, prospect, business-contact, account-administration, or security data. They are not approved to receive Client Financial Data merely because they appear here.
4. Current limited controller and business-contact systems table.
System: GoDaddy email tenant; exact product and contracting entity unverified. Limited current role: Fintant mailbox hosting and routing for business correspondence. Current restriction: Exact product, upstream routing, account evidence, terms, retention, region, and sender authentication remain unverified. No Client Financial Data may be sent through ordinary email.
System: Microsoft Outlook client. Limited current role: Manual initiation and handling of approved direct business email through the GoDaddy tenant. Current restriction: Outlook is a client, not evidence of a Microsoft 365 tenant. No automated outreach and no Client Financial Data attachment are approved.
System: Cloudflare authoritative DNS. Limited current role: Domain and email-related DNS hosting. Current restriction: Current account ownership is user-reported; access, contract, logging, change, rollback, and retention evidence remain incomplete.
System: LinkedIn and Sales Navigator. Limited current role: Professional-source research and manually sent business messages. Current restriction: Source, lawful outreach basis, message approval, opt-out, suppression, and retention evidence are required for each controlled pilot contact.
System: Notion. Limited current role: Canonical Outreach Contact Register, Outreach Suppression Register, and separate Sales Outreach Runs campaign tracker. Current restriction: Each canonical register contains one reserved fictional control-test row and zero operating prospect or suppression rows. The tracker contains a fictional paused test and an unapproved Toronto draft. Complete ACL, operating-record, sender-integration, audit, retention, and deletion evidence remain incomplete. No Client Financial Data is approved.
System: Acuity Scheduling. Limited current role: Intended public prospect scheduling path. Current restriction: Exact account entity, plan, calendar connection, Google Meet configuration, data flow, contract, region, retention, and appointment-lifecycle tests remain incomplete.
System: WorkOS AuthKit. Limited current role: Implemented managed identity path using verified-email codes. Current restriction: No live Client Financial Data; production account, agreement, region, recovery, configuration, and approval evidence remain incomplete.
System: Resend / Plus Five Five, Inc. Limited current role: Website authentication and one-time-code email. Current restriction: Not approved for prospect outreach, general workflow email, attachments, or Client Financial Data. Account, agreement, region, retention, and production evidence remain incomplete.
Cronofy is not used by Fintant. Google Workspace, Calendar, or Meet is only being considered for a future Acuity connection and has not been selected. Mailchimp and HubSpot are future-only. An n8n Notion integration identity and LinkedIn engagement-layer schema footprint exist, but direct bot access, credentials and active workflow/runtime are not verified. n8n is not approved for outreach sending or automation and is not an approved production subprocessor.
5. Unselected production capabilities
The following required capabilities do not have an approved production provider as of this draft.
5. Unselected production capabilities table.
Capability: Production application and database hosting. Intended processing: Portal records, authorization state, work metadata, audit records, and database backups. Required before selection and approval: Contracting entity, hosting region, encryption, access, segmentation, backup, restore, retention, deletion, incident, monitoring, and approval evidence.
Capability: Private object storage and backup. Intended processing: Versioned source documents, deliverables, object metadata, and protected backups. Required before selection and approval: Private region and bucket, encryption, short-lived authorization, versioning, access logging, backup and restore, deletion and backup purge, DPA, and client approval.
Capability: File-security scanning. Intended processing: File version, content hash, scan result, signature or engine version, and quarantine state. Required before selection and approval: Fail-closed quarantine, provider and region, retention, timeouts, retries, update evidence, incident handling, and tested clean, malicious, unavailable, and stale-result cases.
Capability: Monitoring and on-call. Intended processing: Safe control state, correlation identifier, failure category, alert, and acknowledgement. Required before selection and approval: Provider or owned stack, privacy-safe allow-list, retention, destination region, on-call owner, escalation, acknowledgement, outage handling, and tested evidence.
Capability: Product analytics. Intended processing: Allow-listed product event and non-sensitive actor or object reference. Required before selection and approval: Business necessity, provider, destination, consent class, region, retention, event allow-list, durable delivery, deletion, opt-out, and proof that no financial content or free text is sent.
Capability: AI, OCR, extraction, or model processing. Intended processing: Minimized document or transaction input and generated extraction, classification, match, confidence, or exception output. Required before selection and approval: Approved provider and model, DPA, region, transfer mechanism, retention and training settings, security, client authorization, workflow version, source evidence, deterministic controls, human review, and deletion evidence.
Capability: Support and incident tooling. Intended processing: Support metadata, safe diagnostics, controlled evidence, and incident coordination. Required before selection and approval: Least privilege, time-limited access, audit, data minimization, region, retention, incident channel, confidentiality, and client-data restrictions.
No live Client Financial Data may be routed to an unselected or unapproved capability.
6. Excluded non-production infrastructure
Fintant may use separate systems for development and test with synthetic data. Those systems are not approved subprocessors for Client Financial Data.
6. Excluded non-production infrastructure table.
System: Contabo test infrastructure; contracting legal entity and region to be confirmed. Use: Non-production application testing and deployment evidence using synthetic fixtures. Live-data status: Not approved for live or identifiable Client Financial Data. Live-data processing is prohibited.
System: Local developer systems and CI or test runners. Use: Development, automated tests, builds, and synthetic verification. Live-data status: Not approved for live or identifiable Client Financial Data.
System: Stub or console provider adapters. Use: Simulated non-production behavior for unapproved providers. Live-data status: Fictional or synthetic behavior only; not evidence of a production service.
7. Fintant workforce and cross-border access
Fintant is a U.S. company and may use authorized personnel or contractors in the United States, Canada, and Bangladesh. Workforce members are not necessarily subprocessors, but their access creates cross-border, confidentiality, security, and client-authorization requirements.
Before any workforce member may access live Client Financial Data from a country:
the country and role must be approved in the Client Agreement or Work Authorization; required taxpayer or end-client authorization must be obtained; the person must have a signed confidentiality and data-protection agreement; background checks or screening required by policy must be complete; only named accounts, an approved strong-authentication method, approved devices, and least-privilege access may be used; local download, personal email, personal storage, and unapproved communications must be prohibited; access, training, monitoring, incident, and offboarding evidence must be current; and any client-specific restriction must be technically and operationally enforced.
8. Provider approval standard
Before a provider moves to Section 2, Fintant must record:
provider brand and exact contracting legal entity; service owner and approval owner; purpose and necessity; data categories and prohibited data; systems, users, and workflow boundaries; processing and storage countries or regions; transfer mechanism and required assessment; access model, encryption, secrets, and tenant controls; retention, deletion, de-identification, backup, and restore; incident notification and cooperation duties; subcontractors and material-change notice; data-processing, confidentiality, security, and audit terms; synthetic and production readiness tests; approval date, review date, evidence reference, and client-specific restrictions.
A mismatch between this Register, the deployed system, provider configuration, contract, or client approval fails closed.
9. Changes, notice, and objections
The applicable Client Agreement and Data Processing and Security Addendum control subprocessor authorization, notice, and objection rights.
Before appointing a new production subprocessor or making a material change, Fintant will:
update this Register with the provider, purpose, data, country or region, transfer position, and intended change date; provide the notice required by the applicable Client Agreement; make relevant security and data-protection information available under appropriate confidentiality; review a timely, reasonable objection; attempt in good faith to address the concern through configuration, restriction, an alternative provider, or another lawful solution; and not route the objecting client’s data to the provider before the contractual process is completed.
An objection does not require Fintant to use an unavailable or commercially unreasonable provider, but the Client Agreement must state the available remedy if the parties cannot resolve it.
10. Client-specific restrictions
This public Register describes Fintant’s general provider posture. A Client Agreement or Work Authorization may impose stricter restrictions, including:
approved or prohibited subprocessors; U.S.-only, Canada-only, or other regional processing; no offshore workforce access; no AI or OCR processing; specific retention and deletion requirements; specific encryption, audit, insurance, or incident terms; and prior specific authorization rather than general authorization.
The stricter approved client-specific restriction controls for that client.
11. Contact
Subprocessor and privacy questions: privacy@fintant.ai Security questions: security@fintant.ai Mail: Fintant Inc., 73-12 35th Avenue, Suite A45, Jackson Heights, NY 11372
Do not include credentials or Client Financial Data in ordinary email.