01Current subprocessors
| Subprocessor | Purpose | Data it may process | Hosting region | Terms |
|---|---|---|---|---|
| Supabase | Primary database, authentication, and file storage | Account data, project and finding records, audit logs, encrypted OAuth tokens | United States | DPA |
| Cloudflare | Edge network, application runtime, DDoS protection | Request metadata, IP address, in-transit request payloads | Global edge | DPA |
| Vercel | Hosting for the API gateway and web analytics | Request metadata, IP address, aggregate page analytics | United States | DPA |
| Fly.io | Isolated static-analysis scanner and pentest runner containers | Transient repository content and scan targets during a run | United States | DPA |
| Stripe | Subscription billing and payment processing | Billing email, plan, subscription and payment records | United States | DPA |
| Resend | Transactional email (invitations, notifications, support replies) | Email address, name, message contents | United States | DPA |
| GitHub | Repository access for code monitoring and pull-request remediation | Repository metadata and file contents you grant access to | United States | DPA |
| PostHog | Product analytics (loaded only with your consent) | Pseudonymous usage events, page views, masked session replay | United States | DPA |
| Sentry | Error and performance monitoring (loaded only with your consent) | Redacted stack traces, browser metadata, user identifier | United States | DPA |
| Model providers (OpenAI, Anthropic, Google, Lovable AI Gateway) | LLM inference for finding triage and fix drafting | Redacted code excerpts, schema and configuration metadata, finding text | United States | DPA |
02Model providers and training
Sentrail sends redacted code excerpts, schema metadata, and finding text to a model provider to triage findings and draft fixes. We use enterprise or API endpoints configured so that submitted content is not used to train the provider's models.
Secrets, connection strings, and access tokens are stripped before any prompt is sent. If you would rather not use a hosted model at all, contact us about self-hosting the agent runtime.
03How we vet a subprocessor
- We review the vendor's security documentation and any available third-party audit report before onboarding.
- We execute a data processing agreement with equivalent obligations to the ones we owe you, including EU Standard Contractual Clauses where transfers require them.
- We grant the narrowest access that the integration needs and prefer vendors that support scoped, revocable credentials.
- We remove a vendor when it is no longer needed and revoke its credentials at that point.
04Notice of changes
We will give at least thirty (30) days' notice before a new subprocessor begins processing customer personal data, by updating this page and emailing account administrators who have subscribed to change notices. If you reasonably object on data protection grounds, contact privacy@sentrail.dev within that window and we will work with you or, failing a resolution, allow you to terminate the affected subscription and receive a pro-rata refund as described in our Data Processing Addendum.
Published to satisfy the subprocessor transparency and objection rights in GDPR Art. 28(2) and (4), and referenced by our DPA. Provided for information; it is not legal advice.