Sub-processor list
Third-party providers that process customer data on our behalf.
Sub-processor list
Last updated: 2026-07-12 Notification window: we publish updates to this page at least 30 days before a new sub-processor begins processing customer data, unless the change is required for security or legal reasons.
NoDowntimeShield uses the following sub-processors to deliver the platform. Each is bound by a Data Processing Agreement that meets or exceeds the protections in our customer DPA. If you would like a copy of the relevant agreement, email [email protected].
Core infrastructure
| Sub-processor | Purpose | Region | | ------------- | -------------------------------------------------------- | -------------- | | Supabase | PostgreSQL + Auth + Object Storage | Single region (see Trust Centre for residency status) | | Cloudflare | Edge/CDN + DDoS protection in front of our application, plus WAF-ruleset automation for customer domains (product feature) | Global edge |
Our application and worker processes run on infrastructure we operate directly (not a third-party PaaS such as Vercel or Fly.io); Redis (queue + cache + rate-limit counters) runs on that same infrastructure rather than a hosted Redis provider.
Payments
| Sub-processor | Purpose | Region | | ------------- | -------------------------------------------------------- | -------------- | | Stripe | Subscription billing + Stripe Tax + checkout (incl. PayPal flow) | US/EU |
Communications
| Sub-processor | Purpose | Region | | ------------- | -------------------------------------------------------- | -------------- | | Brevo | Transactional email delivery | EU | | Kapso.ai | WhatsApp Business message routing | US |
Identity
| Sub-processor | Purpose | Region | | ------------- | -------------------------------------------------------- | -------------- | | WorkOS | Enterprise SSO (SAML/OIDC) + SCIM provisioning (only where contractually enabled; not currently offered for sale) | US |
Threat intelligence + AI
| Sub-processor | Purpose | Region | | ------------- | -------------------------------------------------------- | -------------- | | OpenAI | LLM — primary provider (finding triage, plain-language rewrite, chat) | US | | Anthropic | LLM — fallback provider | US | | OpenRouter | LLM router — catch-all fallback + cost optimisation | US | | MiniMax | LLM — APAC-region fallback provider | APAC | | HIBP | Have I Been Pwned — breach + credential-leak data | US | | Google Safe Browsing | URL reputation classification | US | | VirusTotal | URL + file reputation enrichment | US | | MXToolbox | Email blacklist lookup | US | | URLScan.io | Phishing-page sandbox + screenshot | EU | | OSV.dev | Open-source vulnerability database | US | | NVD | National Vulnerability Database (CVSS metadata) | US | | EPSS | Exploit Prediction Scoring System | US | | GitHub | GitHub App — repo manifest reads, PR diffs, PR/Checks comments (customers who install our GitHub App only) | US |
Observability
| Sub-processor | Purpose | Region | | ------------- | -------------------------------------------------------- | -------------- | | Sentry | Application error tracking + performance monitoring | US |
Domain intelligence
| Sub-processor | Purpose | Region | | ------------- | -------------------------------------------------------- | -------------- | | Namecheap | Domain availability lookup (brand-protection scanner) | US |
What customer data each sub-processor receives
| Data category | Sub-processors that receive it | | -------------------------------------------- | ---------------------------------------------------------------------------- | | Account profile (email, name) | Supabase, Brevo, Stripe, WorkOS (SSO customers only) | | Billing details (last-4 PAN, address) | Stripe | | Scan findings + scan history | Supabase, Sentry (via error breadcrumbs only) | | Findings sent to LLM for plain-English rewrite | OpenAI, Anthropic, OpenRouter, MiniMax (per provider routing) | | Findings sent to alert channels | Brevo (email), Kapso (WhatsApp), customer-configured Slack / Teams / Jira | | Domain + DNS lookups | Google Safe Browsing, VirusTotal, MXToolbox, URLScan.io, Namecheap, OSV.dev | | Repository contents (GitHub App installs only) | GitHub |
Data-residency option
Regional data-residency pinning (EU / US / APAC) is architected in our codebase (Organization.region) but not yet available in production — today every organisation's data is stored in the same single-region Supabase project regardless of plan. We will update this section and notify affected customers before offering a residency guarantee. If regional storage is a requirement for your organisation, email [email protected] to discuss options.
Removing a sub-processor
If a sub-processor materially changes its terms or jurisdiction, customers may object in writing within 30 days; we will work in good faith to provide a comparable alternative or pro-rate the remainder of the subscription term.