Trust Center
Sub-processors
Current register for enterprise review. Last updated 2026-06-21. We notify customers 30 days before adding a new sub-processor.
| Provider | Purpose | Data | Region | DPA |
|---|---|---|---|---|
| Railway | Application hosting | Scan metadata, configs | US | SOC 2 Type II (NDA); HIPAA BAA (Enterprise); DPA |
| Vercel | Web frontend CDN | Static assets, analytics cookies | Global | DPA available |
| WorkOS | Dashboard authentication | User email, name, org membership, SSO/session metadata | US | DPA available |
| Postgres (managed) | Primary database | Tenant scans, remediation, audit | US (EU by agreement) | DPA available |
| Redis (managed) | Job queue | Job payloads (ephemeral) | Contractual | DPA available |
| Stripe | Billing | Billing contact, subscription metadata | Global | Stripe DPA |
| Resend | Transactional email | Alert addresses, report delivery | US | DPA available |
| PostHog (optional) | Product analytics | Anonymized usage events if enabled | US/EU | DPA available |
| OpenAI (optional) | Copilot explanations | Finding text only if tenant enables | US | Enterprise DPA |
Primary hosting provider maintains SOC 2 Type II; report available under NDA on document request. Request artifacts via Contact sales. See also Data residency. ← Trust Center