Legal
Third parties that process personal data to help us operate AtRisk. This list mirrors Privacy Policy §8.1 and constitutes Annex III to our Data Processing Addendum.
Last updated: September 9, 2026 · Effective: September 9, 2026
These providers are authorized to process data only as needed to perform services for us. We do not use Microsoft Clarity or other marketing-site session-replay tools.
| Provider | Purpose | Data categories | Location | Transfer |
|---|---|---|---|---|
Neon Neon, Inc. | Authentication and database hosting | Account identifiers, profile fields, session metadata, Customer Content stored in the app database | United States / EU (provider regions) | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
Polar Polar Software Inc. | Payment processing, subscriptions, and customer billing portal (may act as merchant of record) | Billing email, plan/subscription status, customer identifiers, country/tax metadata; card data handled by Polar | United States / EU | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
GitHub GitHub, Inc. (Microsoft) | Repository connection via GitHub App or OAuth when you connect a repo | Repository metadata and contents you authorize, installation/OAuth identifiers, agent run context | United States / EU | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
Anthropic Anthropic PBC | In-app AI generation (fix prompts, optional finding judgments) | Finding text, evidence snippets, and prompts needed to return the requested Output | United States | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
OpenRouter OpenRouter, Inc. | Free-tool AI on the marketing site (routes to underlying model providers) | Free-tool inputs and prompts submitted on atrisk.dev | United States (plus underlying model-provider regions) | SCCs / provider terms (where applicable) |
Cloudflare Cloudflare, Inc. | Hosting, CDN, Workers, Browser Rendering, Containers, KV (including free-tool leads and rate limits), and related infrastructure | IP addresses, request metadata, TLS metadata, Worker logs, KV lead records, scan-related edge processing | United States (global edge) | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
OSV Google LLC (api.osv.dev) / public vulnerability sources | Public vulnerability lookups using package metadata | Package names and versions derived from lockfiles/manifests you authorize | United States | Public-data lookup; no account personal data shared by design |
Resend Resend, Inc. | Transactional and tool-related email delivery | Email address, message content, delivery metadata | United States | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
Sentry Functional Software, Inc. (Sentry) | Error monitoring and performance traces (session replay off by default) | Error stacks, request metadata, account identifiers when attached | United States / EU | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
PostHog PostHog Inc. | Product analytics and usage insights (no session recording in current configuration) | Event metadata, account identifiers, page/feature paths | United States / EU | SCCs / EU-U.S. Data Privacy Framework (where applicable) |
Questions or objections on reasonable data-protection grounds: contact@atrisk.dev. See also our DPA, Privacy Policy, and Trust Center.