AfriScore Trust

Subprocessors

Every third party that may process data on behalf of AfriScore.

A subprocessor is any third party that AfriScore engages to process data on its behalf. Institutions reviewing AfriScore for regulatory or security reasons require visibility into every subprocessor — what it does, where it operates, and what categories of data it handles.

This page is the authoritative list. It is updated whenever a new subprocessor is engaged or an existing one is removed.

Current subprocessors

SubprocessorPurposeData categoriesLocation
Vercel Inc.Application hosting and edge networkSite traffic, form submissions, uploaded files (careers page only)United States (global edge)
Neon Inc.Managed PostgreSQL databasePilot application data, account dataUnited States (us-east-1)
Cloudflare, Inc.DNS, SSL, email routing, DDoS protectionDNS queries, email metadataGlobal
Resend Inc.Transactional email deliveryRecipient email addresses, message metadataUnited States
Formspree Inc.Form submission processing (pilot application)Pilot application submissionsUnited States
Google LLCGoogle Workspace (email and calendar)Email correspondence with partners and institutionsUnited States
GitHub Inc.Source code hostingSource code and public repositoriesUnited States

What is not a subprocessor

AfriScore does not engage subprocessors for core scoring. The credit decisioning engine runs either on AfriScore's own infrastructure (cloud deployment) or entirely on the institution's own infrastructure (on-premise deployment). No third-party service is involved in producing a credit decision.

Data flow by deployment model

Cloud deployment

When an institution uses the default cloud deployment model:

  1. The institution sends an application to the AfriScore API
  2. The API processes the request on Vercel's edge network
  3. The model produces a score and SHAP explanation
  4. The result is returned to the institution
  5. The application is logged in Neon for audit

No data is shared with any subprocessor beyond what is listed above.

On-premise deployment

When an institution uses on-premise deployment:

  1. The institution sends an application to the engine running on its own servers
  2. The engine produces a score and SHAP explanation locally
  3. The result is returned to the institution's internal systems
  4. No data leaves the institution's environment

In this deployment model, none of the subprocessors listed above process borrower data. The only subprocessors engaged are those supporting AfriScore's own operations (email, code hosting, DNS).

How we select subprocessors

AfriScore evaluates each subprocessor against the following criteria:

  • Security posture — Independent audits, encryption standards, access controls
  • Data protection commitments — Contractual obligations for data handling and breach notification
  • Regional data residency — Where the subprocessor stores and processes data
  • Business continuity — Financial stability and service reliability
  • Exit strategy — Ability to migrate away without data loss

Updates and notification

This page is updated whenever the subprocessor list changes. Institutional partners under pilot or commercial agreement will receive advance notice of any material change.

Last updated: September 2026

Objections and inquiries

If you have questions about any subprocessor, or if an institution's regulatory obligations prevent the use of a specific subprocessor, please contact security@afriscore.africa.

We are prepared to discuss alternative subprocessors for institutions with specific requirements.