Skiplink

Sub-processors

Every third party that can touch customer data, what each one can actually see, and why it is there. This is the list the data processing addendum refers to, and the only copy of it we maintain.

Last updated .

Sub-processors, their purpose, what they can access, location and transfer mechanism
ProviderWhat it doesWhat it can seeWhere
DigitalOcean Hosting: the API, the database, the queue, and the machines that render pages. Everything, in the sense that it operates the hardware the data sits on. Data at rest lives on their volumes; they have no application-level access. EU (Amsterdam / Frankfurt)
Cloudflare DNS, TLS termination and the CDN in front of the website and API. Request metadata and traffic in transit: URLs, headers, IP addresses. It does not hold scan results or account records. Global edge; UK/EU entity
Resend Sends transactional email: verification links, password resets, alerts. The recipient's email address and the content of those messages. Nothing else. US
Stripe Payments, when paid plans open. Billing email, and the card details you give it directly. Card numbers never reach our servers — the payment form is Stripe's, on Stripe's domain. US / EU
GitHub Only if you use the GitHub Action: it runs inside your own workflow. Whatever your workflow logs, which includes scan findings for the pages it checked. This one is your relationship, not ours — we list it because the data path is real. US

Transfers outside the UK and EEA

Resend, Stripe and GitHub are US companies. Where personal data is transferred to them, we rely on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, as incorporated into each provider's data processing terms.

Hosting and the database are in the EU. Scan results and account records do not leave the EU except through Cloudflare's edge in transit.

What is deliberately not on this list

No analytics provider, no error-tracking service that receives customer content, no advertising network, no data enrichment, no AI or machine-learning service. Scan content is never sent to a third party for processing.

We do use Sentry for our own error reporting. It is configured to receive stack traces and request paths, not request bodies or scan content, and it is disabled entirely unless a DSN is configured. If that ever changes so that it could receive customer content, it goes on the table above and customers get notice first.

Changes

We will give at least 30 days' notice by email before adding a sub-processor that can access customer personal data, so you have time to object as the addendum allows. Removing one needs no notice.