Sub-processors

Referenced by the Privacy Policy and the DPA, and part of both.

Last updated: 28 September 2026


How to read this list

A sub-processor is a third party that processes customer data on our behalf. Every one is engaged under a written contract imposing confidentiality and security obligations no weaker than our own.

This list is conditional on configuration. Every integration below is driven by an environment variable, and an unset variable means the sub-processor is not used at all. A self-hosted deployment with no Stripe key, no SMTP host and no AI key sends data to none of them.

The authoritative answer is therefore what is set in the running deployment's backend/.env, not what is written here — the settings are defined in backend/app/core/config.py. This list was last checked against production on 8 September 2026.

Active sub-processors

All four are United States entities processing in the United States. The transfer mechanism is the same for all of them and is stated once in § Transfers out below, rather than repeated per row — it depends on where we are established, not on which vendor is in the table.

Sub-processorPurposeData it receivesEnabled byLocation
Stripe, Inc.Payment processing, subscriptionsYour email, billing details you enter directly with Stripe, subscription state. Card data goes browser→Stripe and never transits our serversSTRIPE_SECRET_KEYUnited States
Anthropic PBCAI explanations of findings, and the written plan accompanying a prioritised listPer finding: algorithm name, file path and line, severity, quantum status, standard recommendation, detected hosting platform, our replacement recommendation, and a production / non-production / sensitive classification of the path. A prioritised plan sends up to 40 findings — and so up to 40 file paths — in one request. Not your source code — the evidence excerpt is excluded structurally, not filtered. Exception — "Fix it for me" (Pro), only when you start it: the full contents of the files the fix changes (at most eight) and the fix our rules produced, so the model can place the fix in your codeAI_API_KEYUnited States
Resend, Inc.Transactional email — password resets, key expiry, scan reports, supportRecipient email address, message contentSMTP_HOSTUnited States
DigitalOcean, LLCCompute, network, and managed PostgreSQLAll data in transit and at restAlways (compute); DATABASE_URL (database)United States — New York (NYC1)

Redis is not a sub-processor. It runs as a container on our own DigitalOcean compute, published on no host port and reachable only from the application. No third party receives that data, so it is covered by the DigitalOcean row rather than a row of its own. If a managed cache is adopted later — which happens the day a second server is added, not before — it becomes a sub-processor and this list must change first.

Transfers out

None required. We are established in the United States, we host in the United States, and all four sub-processors above are US entities processing in the United States. There is no transfer out of a jurisdiction whose law requires a mechanism, so there is nothing to rely on and nothing to name.

This is true because of where we sell, not by accident. Selling into the UK or EEA changes it, and this section is the first thing that must be rewritten if that happens.

Conditional — only if you enable them

Sub-processorPurposeDataEnabled by
SlackInternal operational alertsAlert content, which may include account identifiersSLACK_WEBHOOK_URL
HashiCorp VaultEnvelope encryption of keysKey material for wrap/unwrapVAULT_ADDR
AWS KMSEnvelope encryptionSameAWS_KMS_KEY_ID
GCP KMSEnvelope encryptionSameGCP_KMS_KEY_NAME
Azure Key VaultEnvelope encryptionSameAZURE_KEY_VAULT_URL
ServicePurposeDataWhen
Google LLC (Google Analytics 4)How visitors use qopanza.com's public pagesPages visited, referrer, approximate location, device and browser, and the events in the Privacy Policy 3.8 (counts and choices only) — never a scanned site's address, findings, an email, or anything from the signed-in dashboardOnly after a visitor accepts the consent barUnited States

This is data about visitors to our own website, which we control; no customer data you give us reaches Google. It is listed here so that everything that receives anything from us is in one place.

Not sub-processors, though they look like it

  • Your identity provider (OIDC_ISSUER). If you use SSO, that is your provider under your contract. We receive a subject identifier and email from it; we send it nothing about you.
  • Your git host (GitHub, GitLab, Bitbucket). When we clone a repository you connected, we are acting as a client of your account using your token. We disclose nothing to them beyond what any git clone reveals.
  • Your cloud provider, when scanning a cloud account you connected. Same reasoning.
  • Your hosting provider (Netlify). When you connect it for "Fix it for me", we act as a client of your Netlify account, with the access you granted on Netlify's own sign-in page, and publish only a change you approved.
  • Webhook endpoints you configure. Data goes to a destination you chose and control. You are the controller of what happens next.

Changes

We will publish changes here before a new sub-processor starts processing customer data, and give at least 30 days' notice by email to the billing contact on the account so that DPA customers can object under section 5 of the DPA.

To be notified, email support@qopanza.com asking to be added to the sub-processor notice list. Customers on a signed DPA are added automatically.

30 days is a commitment, not a description. It is the market standard and enterprise buyers expect it, but it means no new sub-processor can go live inside a month — including an emergency switch of email or hosting provider. That is the trade you are making for it, and it is the right one.