TRANSPARENCY · SUBPROCESSORS
Subprocessors
Every audit draws independent engines from a vetted pool. Each one, and everyone else who touches your data, runs on US infrastructure. Model provenance is listed openly below; nothing is hidden.
| PROVIDER | ROLE | LOCATION | TRAINING COMMITMENT |
|---|---|---|---|
| Google Cloud / Firebase | Hosting, storage, functions | US | n/a (infrastructure; no model access) |
| Stripe | Payment processing | US | n/a (never sees your code) |
| Resend | Transactional email (report delivery) | US | n/a (sees report summary and recipient address, never your code) |
| Google (Gemini API) | Scanner engine | US | No training on inputs (paid API tier) |
| OpenAI (API) | Scanner engine | US | No training on inputs (business API terms) |
| DeepSeek V4 Pro (served via Fireworks AI) | Scanner engine | US (Fireworks) | No training on inputs (Fireworks commercial terms) |
| Anthropic (API) | Consensus judge | US | No training on inputs (commercial terms) |
| Fireworks AI (GLM, DeepSeek, Kimi) | Standby scanner understudies and backup judge | US | No training on inputs (Fireworks commercial terms) |
Every model that processes your code runs on US infrastructure. Model provenance is listed for full transparency; the data path never leaves the United States.
Each report records the exact engines that produced it. If a primary engine is briefly unavailable, an understudy from the pool above stands in so your audit completes; the substitution is recorded in your report.
This list updates before any provider is added or replaced. Questions: see the Privacy Policy.