Legal
Subprocessors
The list the Data Processing Addendum points at. It includes vendors we have not started using yet, marked as such, because a list that hides the distinction is not worth publishing.
6 in use6 planned30 days notice before changes
The list
| Subprocessor | Status | Purpose | What reaches them | Region |
|---|---|---|---|---|
| Anthropic | Planned | Alternative model lane, not currently on the live review path. | Diff content, file excerpts needed for context, and repository instruction files. Never credentials — secrets are redacted before a prompt is built.Zero-retention amendment targeted before beta. Until it is executed and named here, treat provider-side retention as the provider’s published default. | United States |
| OpenAI | In use | Model provider for review, verification and judge passes. | Diff content, file excerpts needed for context, and repository instruction files. Never credentials — secrets are redacted before a prompt is built.Reviews run across several model lanes (cheap, frontier, thorough and a verification judge) so that a cheap pass does not have to carry a hard one. Each lane receives the same redacted diff and context. | United States |
| Amazon Web Services | In use | Underlying infrastructure for the E2B sandbox fleet. Our own application hosting is Railway, listed separately. | A working checkout of the repository under review, held in a disposable sandbox for the lifetime of that review only.Sandbox instances are destroyed after each review. They carry a pass-through repository token scoped to that one review. | United States, Europe and Japan (sandbox regions) |
| Hetzner | Planned | Contested alternative for the sandbox fleet. Not in use. | A working checkout of the repository under review, for the lifetime of the review only.If adopted, sandbox instances would be destroyed after each review and would hold no platform secrets — only a pass-through repository token. | Germany / Finland |
| E2B | In use | Sandbox provider: the disposable machines that check out code and let verification read and search it. | A working checkout of the repository under review, plus the file and search results a verification pass asks for. Held for the lifetime of the review only.Sandboxes are destroyed when the review finishes, before any posting-capable credential is minted. Nodes hold no platform secrets — only the pass-through repository token. | United States (region selectable per review) |
| Temporal Cloud | Planned | Under consideration for durable review orchestration. Not in use; the review queue is Redis-backed today. | Workflow state: identifiers, commit SHAs, and stage status. No file contents. | European Union |
| Paddle | In use | Merchant of record: payments, subscriptions, invoicing and sales tax. | Billing contact, organisation name, and the billing country used to charge tax. The payment method is held by Paddle and never reaches us. | United Kingdom / United States |
| PostHog | Planned | Product analytics for the web application. | Account identifiers and in-app events. No repository content, no diff content, no finding text. | European Union |
| Sentry | Planned | Error and performance monitoring. The integration is in the code but no DSN is configured, so nothing is transmitted today. | If enabled: stack traces and request metadata only. Code content, request and response bodies, and user identifiers are explicitly disabled. | European Union |
| Railway | In use | Application hosting for the api and web services, and the managed Postgres and Redis instances. | Review records, findings and their stored evidence snippets, repository and pull-request metadata, billing records, account email addresses and notification preferences, and the email outbox.Backups are retained on the owner-configured schedule. Deletion requests are executed through an audited erasure process and completed within 30 days. | United States and Europe (region selectable) |
| Resend | In use | Transactional email: the welcome message, plan and usage notices, and trial reminders. | The recipient email address, the organisation name, and the rendered message body. Message bodies contain no source code, no diff content and no finding text.Every message carries a signed one-click unsubscribe link. Suppressed and unsubscribed addresses are never sent again. | United States |
| Vanta | Planned | Compliance automation and continuous control monitoring. | Employee and infrastructure metadata. No customer content. | United States |
How to read the status column
- In use — this vendor processes customer data today. If you sign the DPA now, this is the set you are authorising in practice.
- Planned — we intend to use them and have listed them in advance so that when they go live it is not a change you have to be notified about and object to under time pressure. Nothing reaches them yet.
Notice of changes
We give 30 days notice before adding or replacing a subprocessor that will process customer data, by email to your billing contact and in the changelog. Customers on a signed DPA may object on reasonable data protection grounds within that window; if we cannot offer an alternative, you may terminate the affected part of the service with a pro-rata refund.
To be added to the notification list without being a billing contact, write to privacy@superdiffs.com.
What never leaves
- Credentials. Detected secrets are redacted before a prompt is constructed, so they are not in what goes to a model provider.
- Code, to the analytics and monitoring vendors. Product analytics receives account identifiers and in-app events. Error monitoring receives stack traces with code content scrubbed.
- Anything, to an advertising network. There are none on this list, and there will not be.
- Platform credentials, into the sandbox fleet. Those machines hold a one-hour, single-repository, read-only token and nothing else.
Full data-flow detail is on the trust centre; the processor terms are in the DPA.