| Fly.io | Application hosting, compute, and managed PostgreSQL database — our primary processor | European Union — Frankfurt, Germany (fra); data at rest in the EU | All application data: accounts, websites, audits, findings, and evidence. This is where your data lives. | US entity operating an EU region. Standard Contractual Clauses / Data Privacy Framework — under counsel review. |
| Cloudflare | DNS, reverse proxy, WAF/DDoS protection (transit only), and R2 object storage for sealed evidence | Edge: global transit network. R2 evidence storage: EU jurisdiction (verified) | Request metadata in transit (IP addresses, headers, URLs); sealed evidence bundles at rest in R2. | Standard Contractual Clauses / Data Privacy Framework — under counsel review |
| Anthropic | AI classification of cookie purposes and AI-assisted remediation text | United States | Cookie names and domains, tracker signals, policy-text excerpts. No customer-site visitor data by design, and no account credentials or payment data. The AI never makes the final compliance decision — deterministic guardrails override it. | Standard Contractual Clauses — under counsel review, including commercial-API retention terms |
| Stripe | Subscription billing and payment processing | United States (Stripe Inc.); EU entity available (Stripe Payments Europe Ltd, Ireland) | Billing contact and subscription tier. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers. | SCCs expected via the Stripe DPA — under counsel review; no executed record on file |
| Resend | Transactional email delivery (audit notifications, invites, scheduled summaries) | United States | User names and email addresses; notification content (audit titles, site names). Scheduled summaries carry compliance scores and result summaries. No sealed evidence files. | Standard Contractual Clauses — under counsel review |
| Inngest | Background-job orchestration — the event bus for the audit pipeline | United States | Event payloads: organization/audit/user identifiers, audited website URLs, recipient email addresses on notification events. No evidence files and no credentials. | Standard Contractual Clauses — under counsel review |
| PostHog | Product analytics — feature usage and funnel measurement | United States | Events keyed by user/organization identifiers, including audited website URLs, audit identifiers, risk/scan scores, and finding counts; marketing funnel events can include a lead’s email address. No session recording. | Standard Contractual Clauses — under counsel review |
| Upstash | Redis-backed rate-limit counters (abuse protection on public and expensive endpoints) | United States | Short-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content. | Standard Contractual Clauses — under counsel review |
| Sentry | Error monitoring for the application and background jobs | United States | Error telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files. | Standard Contractual Clauses — under counsel review |