Sub-processors
Every third party that can touch customer data, what each one can actually see, and why it is there. This is the list the data processing addendum refers to, and the only copy of it we maintain.
Last updated .
| Provider | What it does | What it can see | Where |
|---|---|---|---|
| DigitalOcean | Hosting: the API, the database, the queue, and the machines that render pages. | Everything, in the sense that it operates the hardware the data sits on. Data at rest lives on their volumes; they have no application-level access. | EU (Amsterdam / Frankfurt) |
| Cloudflare | DNS, TLS termination and the CDN in front of the website and API. | Request metadata and traffic in transit: URLs, headers, IP addresses. It does not hold scan results or account records. | Global edge; UK/EU entity |
| Resend | Sends transactional email: verification links, password resets, alerts. | The recipient's email address and the content of those messages. Nothing else. | US |
| Stripe | Payments, when paid plans open. | Billing email, and the card details you give it directly. Card numbers never reach our servers — the payment form is Stripe's, on Stripe's domain. | US / EU |
| GitHub | Only if you use the GitHub Action: it runs inside your own workflow. | Whatever your workflow logs, which includes scan findings for the pages it checked. This one is your relationship, not ours — we list it because the data path is real. | US |
Transfers outside the UK and EEA
Resend, Stripe and GitHub are US companies. Where personal data is transferred to them, we rely on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, as incorporated into each provider's data processing terms.
Hosting and the database are in the EU. Scan results and account records do not leave the EU except through Cloudflare's edge in transit.
What is deliberately not on this list
No analytics provider, no error-tracking service that receives customer content, no advertising network, no data enrichment, no AI or machine-learning service. Scan content is never sent to a third party for processing.
We do use Sentry for our own error reporting. It is configured to receive stack traces and request paths, not request bodies or scan content, and it is disabled entirely unless a DSN is configured. If that ever changes so that it could receive customer content, it goes on the table above and customers get notice first.
Changes
We will give at least 30 days' notice by email before adding a sub-processor that can access customer personal data, so you have time to object as the addendum allows. Removing one needs no notice.