Referenced by the Privacy Policy and the DPA, and part of both.
Last updated: 28 September 2026
How to read this list
A sub-processor is a third party that processes customer data on our behalf. Every one is engaged under a written contract imposing confidentiality and security obligations no weaker than our own.
This list is conditional on configuration. Every integration below is driven by an environment variable, and an unset variable means the sub-processor is not used at all. A self-hosted deployment with no Stripe key, no SMTP host and no AI key sends data to none of them.
The authoritative answer is therefore what is set in the running deployment's backend/.env, not what is written here — the settings are defined in backend/app/core/config.py. This list was last checked against production on 8 September 2026.
Active sub-processors
All four are United States entities processing in the United States. The transfer mechanism is the same for all of them and is stated once in § Transfers out below, rather than repeated per row — it depends on where we are established, not on which vendor is in the table.
| Sub-processor | Purpose | Data it receives | Enabled by | Location |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing, subscriptions | Your email, billing details you enter directly with Stripe, subscription state. Card data goes browser→Stripe and never transits our servers | STRIPE_SECRET_KEY | United States |
| Anthropic PBC | AI explanations of findings, and the written plan accompanying a prioritised list | Per finding: algorithm name, file path and line, severity, quantum status, standard recommendation, detected hosting platform, our replacement recommendation, and a production / non-production / sensitive classification of the path. A prioritised plan sends up to 40 findings — and so up to 40 file paths — in one request. Not your source code — the evidence excerpt is excluded structurally, not filtered. Exception — "Fix it for me" (Pro), only when you start it: the full contents of the files the fix changes (at most eight) and the fix our rules produced, so the model can place the fix in your code | AI_API_KEY | United States |
| Resend, Inc. | Transactional email — password resets, key expiry, scan reports, support | Recipient email address, message content | SMTP_HOST | United States |
| DigitalOcean, LLC | Compute, network, and managed PostgreSQL | All data in transit and at rest | Always (compute); DATABASE_URL (database) | United States — New York (NYC1) |
Redis is not a sub-processor. It runs as a container on our own DigitalOcean compute, published on no host port and reachable only from the application. No third party receives that data, so it is covered by the DigitalOcean row rather than a row of its own. If a managed cache is adopted later — which happens the day a second server is added, not before — it becomes a sub-processor and this list must change first.
Transfers out
None required. We are established in the United States, we host in the United States, and all four sub-processors above are US entities processing in the United States. There is no transfer out of a jurisdiction whose law requires a mechanism, so there is nothing to rely on and nothing to name.
This is true because of where we sell, not by accident. Selling into the UK or EEA changes it, and this section is the first thing that must be rewritten if that happens.
Conditional — only if you enable them
| Sub-processor | Purpose | Data | Enabled by |
|---|---|---|---|
| Slack | Internal operational alerts | Alert content, which may include account identifiers | SLACK_WEBHOOK_URL |
| HashiCorp Vault | Envelope encryption of keys | Key material for wrap/unwrap | VAULT_ADDR |
| AWS KMS | Envelope encryption | Same | AWS_KMS_KEY_ID |
| GCP KMS | Envelope encryption | Same | GCP_KMS_KEY_NAME |
| Azure Key Vault | Envelope encryption | Same | AZURE_KEY_VAULT_URL |
Visitor analytics — our data, only with consent
| Service | Purpose | Data | When | |
|---|---|---|---|---|
| Google LLC (Google Analytics 4) | How visitors use qopanza.com's public pages | Pages visited, referrer, approximate location, device and browser, and the events in the Privacy Policy 3.8 (counts and choices only) — never a scanned site's address, findings, an email, or anything from the signed-in dashboard | Only after a visitor accepts the consent bar | United States |
This is data about visitors to our own website, which we control; no customer data you give us reaches Google. It is listed here so that everything that receives anything from us is in one place.
Not sub-processors, though they look like it
- Your identity provider (
OIDC_ISSUER). If you use SSO, that is your provider under your contract. We receive a subject identifier and email from it; we send it nothing about you. - Your git host (GitHub, GitLab, Bitbucket). When we clone a repository you connected, we are acting as a client of your account using your token. We disclose nothing to them beyond what any git clone reveals.
- Your cloud provider, when scanning a cloud account you connected. Same reasoning.
- Your hosting provider (Netlify). When you connect it for "Fix it for me", we act as a client of your Netlify account, with the access you granted on Netlify's own sign-in page, and publish only a change you approved.
- Webhook endpoints you configure. Data goes to a destination you chose and control. You are the controller of what happens next.
Changes
We will publish changes here before a new sub-processor starts processing customer data, and give at least 30 days' notice by email to the billing contact on the account so that DPA customers can object under section 5 of the DPA.
To be notified, email support@qopanza.com asking to be added to the sub-processor notice list. Customers on a signed DPA are added automatically.
30 days is a commitment, not a description. It is the market standard and enterprise buyers expect it, but it means no new sub-processor can go live inside a month — including an emergency switch of email or hosting provider. That is the trade you are making for it, and it is the right one.