Legal

Subprocessors

Third parties that process personal data to help us operate AtRisk. This list mirrors Privacy Policy §8.1 and constitutes Annex III to our Data Processing Addendum.

Last updated: September 9, 2026 · Effective: September 9, 2026

Current subprocessors

These providers are authorized to process data only as needed to perform services for us. We do not use Microsoft Clarity or other marketing-site session-replay tools.

ProviderPurposeData categoriesLocationTransfer
Neon
Neon, Inc.
Authentication and database hostingAccount identifiers, profile fields, session metadata, Customer Content stored in the app databaseUnited States / EU (provider regions)SCCs / EU-U.S. Data Privacy Framework (where applicable)
Polar
Polar Software Inc.
Payment processing, subscriptions, and customer billing portal (may act as merchant of record)Billing email, plan/subscription status, customer identifiers, country/tax metadata; card data handled by PolarUnited States / EUSCCs / EU-U.S. Data Privacy Framework (where applicable)
GitHub
GitHub, Inc. (Microsoft)
Repository connection via GitHub App or OAuth when you connect a repoRepository metadata and contents you authorize, installation/OAuth identifiers, agent run contextUnited States / EUSCCs / EU-U.S. Data Privacy Framework (where applicable)
Anthropic
Anthropic PBC
In-app AI generation (fix prompts, optional finding judgments)Finding text, evidence snippets, and prompts needed to return the requested OutputUnited StatesSCCs / EU-U.S. Data Privacy Framework (where applicable)
OpenRouter
OpenRouter, Inc.
Free-tool AI on the marketing site (routes to underlying model providers)Free-tool inputs and prompts submitted on atrisk.devUnited States (plus underlying model-provider regions)SCCs / provider terms (where applicable)
Cloudflare
Cloudflare, Inc.
Hosting, CDN, Workers, Browser Rendering, Containers, KV (including free-tool leads and rate limits), and related infrastructureIP addresses, request metadata, TLS metadata, Worker logs, KV lead records, scan-related edge processingUnited States (global edge)SCCs / EU-U.S. Data Privacy Framework (where applicable)
OSV
Google LLC (api.osv.dev) / public vulnerability sources
Public vulnerability lookups using package metadataPackage names and versions derived from lockfiles/manifests you authorizeUnited StatesPublic-data lookup; no account personal data shared by design
Resend
Resend, Inc.
Transactional and tool-related email deliveryEmail address, message content, delivery metadataUnited StatesSCCs / EU-U.S. Data Privacy Framework (where applicable)
Sentry
Functional Software, Inc. (Sentry)
Error monitoring and performance traces (session replay off by default)Error stacks, request metadata, account identifiers when attachedUnited States / EUSCCs / EU-U.S. Data Privacy Framework (where applicable)
PostHog
PostHog Inc.
Product analytics and usage insights (no session recording in current configuration)Event metadata, account identifiers, page/feature pathsUnited States / EUSCCs / EU-U.S. Data Privacy Framework (where applicable)

Questions or objections on reasonable data-protection grounds: contact@atrisk.dev. See also our DPA, Privacy Policy, and Trust Center.

Last reviewed September 9, 2026. Material additions are generally announced with reasonable prior notice (typically at least 30 days) via contact@atrisk.dev / product notice unless urgent for security or legal reasons.