Skip to content

Sub-processors

The third parties that process data on our behalf, what each is for, and what each can see.

Current as of 2026-09-20. This is the list the data processing addendum attaches as its schedule, and it is generated from the same module the product calls — a provider added to the code and not to this page is a test failure rather than an omission a customer discovers.

Customers are notified before a sub-processor is added. Enterprise customers may object.
Sub-processorPurposeWhat it can see
RailwayHosting, PostgresEverything the application holds, at the infrastructure level
Cloudflare R2Object storage: HTML, DOM dumps, screenshots, bundles, PDFsStored objects
StripeBillingName, e-mail, billing address, payment instrument. We never see card data
ResendTransactional e-mailRecipient address and the body of our own e-mails
SentryError monitoringStack traces and request metadata, allowlist-scrubbed
OpenAIclassifier, analyst and writer model rolesRedacted evidence slices only
AnthropicSecond adapter for the same roles, switchable per role by configurationRedacted evidence slices only
mdtopdfPDF renderingThe report Markdown we send it, for an account entitled to a PDF, from our API service only

What the two model providers receive

Only the evidence slice for the dimension being analysed: extracted facts — titles, canonical URLs, header names, configuration paths, module ids, timings, accessibility rule ids, catalog counters — and the storefront text the evidence pack already carries, which is titles, meta descriptions, og: values, headings and category and item names. The pack holds no page body text and no item description. A redaction check runs on the rendered block before any call, and no account holder’s e-mail, name, address or billing detail can reach a slice: there is no code path that puts an account row into an evidence pack.

Both providers are configured for zero or minimum retention and no training on our traffic. That is a setting in each provider’s console rather than something our code can prove, so it is verified by a person before the first production call and re-verified at each security review.

Notice and objection

Customers are notified before a sub-processor is added. Enterprise customers may object. The data processing addendum that refers to this list is at /dpa, and what we hold and for how long is in the privacy notice.