TC 11Vaethra reference

Subprocessors

Every third party that stores or processes data on Vaethra's behalf, what they hold, where, and their own attestations.

Count
4
Personal data
minimal
Notice of change
30 days
Reviewed
7 September 2026
01The list

Four, and no others

SubprocessorPurposeDataRegionAttestations
Cloudflare, Inc.
United States
Edge compute, CDN, DNS, web application firewall, object storage, key-value store, access control, model inference Request metadata, cached API responses, bulk extracts, cached satellite imagery, public-source text sent for extraction and embedding Global edge SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS
Supabase, Inc.
United States
Managed PostgreSQL — the durable record — and database functions The event and entity record, API key digests, alert rules AWS us-east-2, or an EU region on enterprise agreements SOC 2 Type II
Amazon Web Services, Inc.
United States
Underlying infrastructure for Supabase. Named explicitly rather than left behind our direct vendor. As Supabase — they host it us-east-2, Ohio SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS
GitHub, Inc.
United States
Source control and continuous integration Source code only. No production data, no customer data, no secrets. United States SOC 1/2 Type II, ISO 27001

Data providers are not subprocessors. The 55 public feeds we read receive nothing from us but an HTTP request and a user-agent string. They are listed separately under coverage, with the licence of each.

Web fonts are self-hosted, so no font service receives any visitor's IP address.

02What none of them receives

There is very little customer personal data to pass on

Vaethra has no user accounts, so no name, email or profile is attached to use of the Terminal or Atropos, and nothing about a session reaches a subprocessor beyond the request metadata any web service necessarily sees.

Two exceptions, stated precisely:

  • Webhook alert rules. The destination URL you register is stored in the database so the rule can be evaluated while your browser is closed. It is owned by an anonymous token your browser generates, not by an identity.
  • API key records. The digest, the owner and the usage are stored for billing and abuse handling. This is the only place a customer is identifiable, and it lives in Supabase on AWS.

No advertising network. No analytics broker. No data broker. No sale or sharing of any data with anyone outside the table above.

03How a subprocessor is added

Assessed before engagement, reviewed after

  1. Necessity. Whether the requirement can be met without adding a third party. The list is four long because the answer is usually yes.
  2. Security assessment. Their attestations, security documentation, incident history and their own subprocessors.
  3. Privacy assessment. What personal data they would process, the transfer mechanism, and their retention and deletion terms.
  4. Contract. A data processing agreement incorporating the Standard Contractual Clauses where a transfer requires them, with terms no weaker than those we give you.
  5. Annual review, and immediate review after any incident of theirs that affects us.
04Changes

30 days' notice, with a right to terminate

We give 30 days' notice by email to enterprise customers before adding or replacing a subprocessor, and this page carries the current list with the date it was last reviewed.

If a change is unacceptable to you, that is grounds to terminate without penalty for the remainder of the term, with a full export of anything you supplied. That right is in the DPA.

To join the notification list, write to support@vaethra.com.

↑↓ to move · Enter opens the highlighted result