Skip to content

Legal

Subprocessors

The list the Data Processing Addendum points at. It includes vendors we have not started using yet, marked as such, because a list that hides the distinction is not worth publishing.
2 in use7 planned30 days notice before changes

The list

Subprocessors
SubprocessorStatusPurposeWhat reaches themRegion
AnthropicPlannedPrimary model provider for review passes and verification.Diff content, file excerpts needed for context, and repository instruction files. Never credentials — secrets are redacted before a prompt is built.Zero-retention amendment targeted before beta. Until it is executed and named here, treat provider-side retention as the provider’s published default.United States
OpenAIPlannedSecondary model lane and the offline evaluation judge.Same class of content as the primary lane when the secondary lane is selected; benchmark datasets during evaluation runs.Zero-retention amendment targeted before beta.United States
Amazon Web ServicesIn useControl plane: application hosting, Postgres, object storage, key management.Review records, findings and their stored evidence snippets, repository and pull-request metadata, encrypted git bundles.eu-central-1 (primary)
HetznerIn useSandbox fleet — the isolated machines that check out code and run analysers.A working checkout of the repository under review, for the lifetime of the review only.Sandbox instances are destroyed after each review. Nodes hold no platform secrets — only the pass-through one-hour repository token.Germany / Finland
Temporal CloudPlannedDurable orchestration of review workflows.Workflow state: identifiers, commit SHAs, and stage status. No file contents.European Union
StripePlannedPayments and subscription management.Billing contact, organisation name, payment method held by Stripe.United States / Ireland
PostHogPlannedProduct analytics for the web application.Account identifiers and in-app events. No repository content, no diff content, no finding text.European Union
SentryPlannedError and performance monitoring.Stack traces and request metadata. Code content is scrubbed before an event is sent.European Union
VantaPlannedCompliance automation and continuous control monitoring.Employee and infrastructure metadata. No customer content.United States

How to read the status column

  • In use — this vendor processes customer data today. If you sign the DPA now, this is the set you are authorising in practice.
  • Planned — we intend to use them and have listed them in advance so that when they go live it is not a change you have to be notified about and object to under time pressure. Nothing reaches them yet.

Notice of changes

We give 30 days notice before adding or replacing a subprocessor that will process customer data, by email to your billing contact and in the changelog. Customers on a signed DPA may object on reasonable data protection grounds within that window; if we cannot offer an alternative, you may terminate the affected part of the service with a pro-rata refund.

To be added to the notification list without being a billing contact, write to privacy@superdiffs.com.

What never leaves

  • Credentials. Detected secrets are redacted before a prompt is constructed, so they are not in what goes to a model provider.
  • Code, to the analytics and monitoring vendors. Product analytics receives account identifiers and in-app events. Error monitoring receives stack traces with code content scrubbed.
  • Anything, to an advertising network. There are none on this list, and there will not be.
  • Platform credentials, into the sandbox fleet. Those machines hold a one-hour, single-repository, read-only token and nothing else.

Full data-flow detail is on the trust centre; the processor terms are in the DPA.