Sub-processors
Effective 2026-09-16 (subject to change on legal review) · Version subprocessors-draft-2026-09-16
This document does two jobs. Sections 1 to 3 are the public sub-processor register for breachr.ai/subprocessors, written for customers and their DPOs. Section 4 onward is the internal coverage note explaining how each tool is handled and where the residual risks sit. Publish sections 1 to 3; keep section 4 onward internal, for you and Lex Law.
1. What a sub-processor is
To run breachr we use a small set of trusted service providers. Some of them process personal data on our behalf. GDPR calls these sub-processors. We list them here, tell you what they do, and tell you where they process data. We keep this list current and give notice of changes as set out in our Data Processing Agreement.
2. Current sub-processors
Sub-processor
Purpose
Data processed
Location
Transfer safeguard
Amazon Web Services (Frankfurt)
Core cloud infrastructure and storage
Account data, scan targets, findings, reports
EU (Frankfurt)
None needed (EU); see note 4.9
Supabase (EU)
Database, authentication and storage
Account data, and scan data held in the database
EU region (on AWS)
SCCs (US parent); see note 4.9
Vercel
Application hosting, edge and serverless functions
Request data, IP addresses, logs (pass-through, not scan storage)
EU region
SCCs (US parent); see note 4.9
OpenRouter
Routing layer for the AI reasoning model
Minimised finding data for analysis
EU endpoint where available; otherwise routed to model provider
SCCs; migrating to EU in-region
Anthropic
AI language model used to analyse findings
Minimised finding data for analysis
United States
Standard Contractual Clauses + Schrems II safeguards
Stripe Europe
Payment processing
Billing and payment data
EU / global
SCCs where applicable
Resend (EU)
Transactional and service email
Name, email, message content
EU
None needed (EU)
Umami Cloud
Cookieless website analytics
Aggregated, non-identifying site metrics
[CONFIRM EU HOSTING]
See note 4.6
PostHog (EU)
Product analytics inside the portal
Product usage and journey data (no scan data, no credentials, no findings)
EU
None needed (EU)
3. Two commitments about your data
We never sell your data, and we never use your scan data for our own purposes beyond delivering the service to you.
The AI reasoning layer involves one transfer outside the EU, and we will not hide it. Where our model provider's infrastructure sits outside the EU, a limited transfer occurs, covered by Standard Contractual Clauses, using only the minimum data needed to analyse a finding. We are migrating this layer to EU in-region routing, after which the transfer falls away.