Legal
Subprocessors
The list the Data Processing Addendum points at. It includes vendors we have not started using yet, marked as such, because a list that hides the distinction is not worth publishing.
2 in use7 planned30 days notice before changes
The list
| Subprocessor | Status | Purpose | What reaches them | Region |
|---|---|---|---|---|
| Anthropic | Planned | Primary model provider for review passes and verification. | Diff content, file excerpts needed for context, and repository instruction files. Never credentials — secrets are redacted before a prompt is built.Zero-retention amendment targeted before beta. Until it is executed and named here, treat provider-side retention as the provider’s published default. | United States |
| OpenAI | Planned | Secondary model lane and the offline evaluation judge. | Same class of content as the primary lane when the secondary lane is selected; benchmark datasets during evaluation runs.Zero-retention amendment targeted before beta. | United States |
| Amazon Web Services | In use | Control plane: application hosting, Postgres, object storage, key management. | Review records, findings and their stored evidence snippets, repository and pull-request metadata, encrypted git bundles. | eu-central-1 (primary) |
| Hetzner | In use | Sandbox fleet — the isolated machines that check out code and run analysers. | A working checkout of the repository under review, for the lifetime of the review only.Sandbox instances are destroyed after each review. Nodes hold no platform secrets — only the pass-through one-hour repository token. | Germany / Finland |
| Temporal Cloud | Planned | Durable orchestration of review workflows. | Workflow state: identifiers, commit SHAs, and stage status. No file contents. | European Union |
| Stripe | Planned | Payments and subscription management. | Billing contact, organisation name, payment method held by Stripe. | United States / Ireland |
| PostHog | Planned | Product analytics for the web application. | Account identifiers and in-app events. No repository content, no diff content, no finding text. | European Union |
| Sentry | Planned | Error and performance monitoring. | Stack traces and request metadata. Code content is scrubbed before an event is sent. | European Union |
| Vanta | Planned | Compliance automation and continuous control monitoring. | Employee and infrastructure metadata. No customer content. | United States |
How to read the status column
- In use — this vendor processes customer data today. If you sign the DPA now, this is the set you are authorising in practice.
- Planned — we intend to use them and have listed them in advance so that when they go live it is not a change you have to be notified about and object to under time pressure. Nothing reaches them yet.
Notice of changes
We give 30 days notice before adding or replacing a subprocessor that will process customer data, by email to your billing contact and in the changelog. Customers on a signed DPA may object on reasonable data protection grounds within that window; if we cannot offer an alternative, you may terminate the affected part of the service with a pro-rata refund.
To be added to the notification list without being a billing contact, write to privacy@superdiffs.com.
What never leaves
- Credentials. Detected secrets are redacted before a prompt is constructed, so they are not in what goes to a model provider.
- Code, to the analytics and monitoring vendors. Product analytics receives account identifiers and in-app events. Error monitoring receives stack traces with code content scrubbed.
- Anything, to an advertising network. There are none on this list, and there will not be.
- Platform credentials, into the sandbox fleet. Those machines hold a one-hour, single-repository, read-only token and nothing else.
Full data-flow detail is on the trust centre; the processor terms are in the DPA.