Subprocessors
Every third party that stores or processes data on Vaethra's behalf, what they hold, where, and their own attestations.
Four, and no others
| Subprocessor | Purpose | Data | Region | Attestations |
|---|---|---|---|---|
| Cloudflare, Inc. United States |
Edge compute, CDN, DNS, web application firewall, object storage, key-value store, access control, model inference | Request metadata, cached API responses, bulk extracts, cached satellite imagery, public-source text sent for extraction and embedding | Global edge | SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS |
| Supabase, Inc. United States |
Managed PostgreSQL — the durable record — and database functions | The event and entity record, API key digests, alert rules | AWS us-east-2, or an EU region on enterprise
agreements |
SOC 2 Type II |
| Amazon Web Services, Inc. United States |
Underlying infrastructure for Supabase. Named explicitly rather than left behind our direct vendor. | As Supabase — they host it | us-east-2, Ohio |
SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS |
| GitHub, Inc. United States |
Source control and continuous integration | Source code only. No production data, no customer data, no secrets. | United States | SOC 1/2 Type II, ISO 27001 |
Data providers are not subprocessors. The 55 public feeds we read receive nothing from us but an HTTP request and a user-agent string. They are listed separately under coverage, with the licence of each.
Web fonts are self-hosted, so no font service receives any visitor's IP address.
There is very little customer personal data to pass on
Vaethra has no user accounts, so no name, email or profile is attached to use of the Terminal or Atropos, and nothing about a session reaches a subprocessor beyond the request metadata any web service necessarily sees.
Two exceptions, stated precisely:
- Webhook alert rules. The destination URL you register is stored in the database so the rule can be evaluated while your browser is closed. It is owned by an anonymous token your browser generates, not by an identity.
- API key records. The digest, the owner and the usage are stored for billing and abuse handling. This is the only place a customer is identifiable, and it lives in Supabase on AWS.
No advertising network. No analytics broker. No data broker. No sale or sharing of any data with anyone outside the table above.
Assessed before engagement, reviewed after
- Necessity. Whether the requirement can be met without adding a third party. The list is four long because the answer is usually yes.
- Security assessment. Their attestations, security documentation, incident history and their own subprocessors.
- Privacy assessment. What personal data they would process, the transfer mechanism, and their retention and deletion terms.
- Contract. A data processing agreement incorporating the Standard Contractual Clauses where a transfer requires them, with terms no weaker than those we give you.
- Annual review, and immediate review after any incident of theirs that affects us.
30 days' notice, with a right to terminate
We give 30 days' notice by email to enterprise customers before adding or replacing a subprocessor, and this page carries the current list with the date it was last reviewed.
If a change is unacceptable to you, that is grounds to terminate without penalty for the remainder of the term, with a full export of anything you supplied. That right is in the DPA.
To join the notification list, write to support@vaethra.com.