Sub-processors
The third parties that process data on our behalf, what each is for, and what each can see.
Current as of 2026-09-20. This is the list the data processing addendum attaches as its schedule, and it is generated from the same module the product calls — a provider added to the code and not to this page is a test failure rather than an omission a customer discovers.
| Sub-processor | Purpose | What it can see |
|---|---|---|
| Railway | Hosting, Postgres | Everything the application holds, at the infrastructure level |
| Cloudflare R2 | Object storage: HTML, DOM dumps, screenshots, bundles, PDFs | Stored objects |
| Stripe | Billing | Name, e-mail, billing address, payment instrument. We never see card data |
| Resend | Transactional e-mail | Recipient address and the body of our own e-mails |
| Sentry | Error monitoring | Stack traces and request metadata, allowlist-scrubbed |
| OpenAI | classifier, analyst and writer model roles | Redacted evidence slices only |
| Anthropic | Second adapter for the same roles, switchable per role by configuration | Redacted evidence slices only |
| mdtopdf | PDF rendering | The report Markdown we send it, for an account entitled to a PDF, from our API service only |
What the two model providers receive
Only the evidence slice for the dimension being analysed: extracted facts — titles, canonical URLs, header names, configuration paths, module ids, timings, accessibility rule ids, catalog counters — and the storefront text the evidence pack already carries, which is titles, meta descriptions, og: values, headings and category and item names. The pack holds no page body text and no item description. A redaction check runs on the rendered block before any call, and no account holder’s e-mail, name, address or billing detail can reach a slice: there is no code path that puts an account row into an evidence pack.
Both providers are configured for zero or minimum retention and no training on our traffic. That is a setting in each provider’s console rather than something our code can prove, so it is verified by a person before the first production call and re-verified at each security review.
Notice and objection
Customers are notified before a sub-processor is added. Enterprise customers may object. The data processing addendum that refers to this list is at /dpa, and what we hold and for how long is in the privacy notice.