AI processing
The application supports an AI provider configuration, including OpenRouter. Confirm the provider and model actually enabled, the information sent, retention settings and contractual terms. Do not publish a blanket no-training promise without verifying the configured providers.
Billing and communication
The code includes Stripe billing and Resend email integrations. Confirm which services are enabled in production, their processing purpose, entity, location and agreement before adding them to an approved register.
Hosting, storage and background work
Confirm the actual hosting provider, PostgreSQL service, object storage, background-job infrastructure and monitoring services. A code dependency is evidence of a possible integration, not proof of production use.
Customer-selected integrations
CRMs, scheduling providers, Slack and commerce connections are enabled by workspace administrators. Review each connection’s permissions and data flow and determine the appropriate contractual treatment.
Required register fields
The final register should identify each approved provider, service purpose, information processed, processing location, safeguards and change-notification process.