Skip to main content
ComplicerAUDIT GRADE
MethodologyUse casesEU AI ActPricingBlogDocsSign inSTART FREE AUDIT
LEGAL — SUBPROCESSOR REGISTER

Every vendor that touches your data.

The third parties we rely on to run Complicer, what each one is used for, where your data is processed, and exactly what flows to them. Your application data lives in the EU. Vendors with US data flows are named below, not folded into a general disclosure.

DATA RESIDENCY
EU — Frankfurt
SUBPROCESSORS
9 named
LAST REVIEWED
18 July 2026
DPA
Under counsel review

Subprocessor register

Reconciled against our internal subprocessor inventory, last reviewed 18 July 2026. We notify customers before adding or changing a subprocessor.

VENDORPURPOSEDATA LOCATIONDATA CATEGORIESDPA / TRANSFER STATUS
Fly.ioApplication hosting, compute, and managed PostgreSQL database — our primary processorEuropean Union — Frankfurt, Germany (fra); data at rest in the EUAll application data: accounts, websites, audits, findings, and evidence. This is where your data lives.US entity operating an EU region. Standard Contractual Clauses / Data Privacy Framework — under counsel review.
CloudflareDNS, reverse proxy, WAF/DDoS protection (transit only), and R2 object storage for sealed evidenceEdge: global transit network. R2 evidence storage: EU jurisdiction (verified)Request metadata in transit (IP addresses, headers, URLs); sealed evidence bundles at rest in R2.Standard Contractual Clauses / Data Privacy Framework — under counsel review
AnthropicAI classification of cookie purposes and AI-assisted remediation textUnited StatesCookie names and domains, tracker signals, policy-text excerpts. No customer-site visitor data by design, and no account credentials or payment data. The AI never makes the final compliance decision — deterministic guardrails override it.Standard Contractual Clauses — under counsel review, including commercial-API retention terms
StripeSubscription billing and payment processingUnited States (Stripe Inc.); EU entity available (Stripe Payments Europe Ltd, Ireland)Billing contact and subscription tier. Payment card data is handled entirely by Stripe — Complicer never sees or stores card numbers.SCCs expected via the Stripe DPA — under counsel review; no executed record on file
ResendTransactional email delivery (audit notifications, invites, scheduled summaries)United StatesUser names and email addresses; notification content (audit titles, site names). Scheduled summaries carry compliance scores and result summaries. No sealed evidence files.Standard Contractual Clauses — under counsel review
InngestBackground-job orchestration — the event bus for the audit pipelineUnited StatesEvent payloads: organization/audit/user identifiers, audited website URLs, recipient email addresses on notification events. No evidence files and no credentials.Standard Contractual Clauses — under counsel review
PostHogProduct analytics — feature usage and funnel measurementUnited StatesEvents keyed by user/organization identifiers, including audited website URLs, audit identifiers, risk/scan scores, and finding counts; marketing funnel events can include a lead’s email address. No session recording.Standard Contractual Clauses — under counsel review
UpstashRedis-backed rate-limit counters (abuse protection on public and expensive endpoints)United StatesShort-lived rate-limit counters keyed by user/organization identifiers and client IP addresses, expiring within minutes. No audit content.Standard Contractual Clauses — under counsel review
SentryError monitoring for the application and background jobsUnited StatesError telemetry: stack traces and request metadata (URLs, IP addresses, user identifiers where available). No evidence files.Standard Contractual Clauses — under counsel review

Your application data lives in the EU (Fly.io, Frankfurt). Anthropic, Stripe, Resend, Inngest, PostHog, Upstash, and Sentry involve US data flows, each with exactly what it receives listed above. Transfer mechanisms for these vendors, including Standard Contractual Clauses, are under counsel review — none is an executed record yet; EU-region processing is our current operating posture. Read how our methodology keeps deterministic guardrails in control of every AI-assisted step.

01

Need the full procurement picture?

Our security & procurement page adds the Article 28 DPA, EU residency detail, retention and deletion policy, and our security controls in one place.

SECURITY & PROCUREMENT →
02

Questions about a specific vendor?

We are happy to walk your DPO or security team through this list, or to notify a named contact ahead of any subprocessor change.

[email protected] →
ComplicerAUDIT GRADE

We test whether Reject actually works on your site — and seal the evidence you can hand to a regulator.

GDPR-ALIGNED · SHA-256 · Ed25519 · EU-W1
PRODUCT
Free scanUse casesMethodologyEU AI ActPricingDocsBlog
COMPANY
ContactSecurityTrust
LEGAL
PrivacyTermsSubprocessorsComplaint
EVIDENCE CHAIN INTACT · SHA-256 · Ed25519 · RFC 3161-READY© 2026 COMPLICER