Last updated: July 16, 2026
These third-party service providers (“sub-processors”) process personal data on our behalf when you use the SourceTrust application or related services. We remain responsible for their performance under our Data Processing Agreement.
This list forms part of our Data Processing Agreement. We update this list when we add or replace sub-processors. Material changes are reflected here and communicated to application customers as described in our DPA.
We give application customers at least fourteen (14) days' notice before adding or replacing a sub-processor that processes application customer data, by updating this page and - where practicable - emailing organization administrators associated with the account. You may object on reasonable data-protection grounds as described in our DPA.
Location means where the sub-processor stores customer data by default - not necessarily where every operation runs. For email providers, a sending region (for example Resend eu-west-1) controls dispatch routing only; account data, logs, and metadata may still be stored elsewhere.
Where a sub-processor stores data outside the European Economic Area or United Kingdom, we rely on appropriate transfer safeguards such as Standard Contractual Clauses in the vendor’s published DPA where applicable.
- Purpose
- Hosting, CDN, security, and Turnstile (CAPTCHA) for the marketing site, public scan, and published attestation pages (including customer-branded hostnames)
- Personal data processed
- IP addresses, request metadata, URLs submitted to the site scan, visitor logs for published compliance pages on default or customer-branded hostnames, Turnstile verification signals, and related technical logs needed to deliver and protect our sites
- Location
- United States and other regions where Cloudflare operates
- Purpose
- Application database and backend hosting
- Personal data processed
- Account, organization, and project data you store in the application — including inventory, compliance pages, and related metadata
- Location
- European Union (Ireland — Convex deployment region eu-west-1)
- Purpose
- Transactional email
- Personal data processed
- Email addresses and message content for account, security, and service notifications we send on your behalf or to your users
- Location
- United States (customer account data, email metadata, and logs)
We may send from eu-west-1 (Ireland); that region affects dispatch only. Resend stores customer data in the United States regardless. Resend's own infrastructure sub-processors include PlanetScale, Inc. (database hosting, United States); see https://resend.com/legal/subprocessors.
- Purpose
- Payment processing and subscription billing
- Personal data processed
- Billing contact details, payment method metadata, transaction records, and tax-related information for paid subscriptions
- Location
- United Kingdom / European operations as applicable; processing may involve other jurisdictions Paddle uses
- Purpose
- Repository connections and code import
- Personal data processed
- Authentication tokens, repository and organization metadata, watched branch configuration, webhook or sync event metadata, and file contents you authorize us to import (for example lockfiles and SBOMs). Commit history may include contributor identifiers present in imported data
- Location
- United States
- Purpose
- Repository connections and code import
- Personal data processed
- Access tokens, project and namespace metadata, watched branch configuration, webhook or sync event metadata, and file contents you authorize us to import (for example lockfiles and SBOMs). Commit history may include contributor identifiers present in imported data
- Location
- United States
- Purpose
- Repository connections and code import
- Personal data processed
- Personal access tokens, organization/project/repository metadata, watched branch configuration, service-hook event metadata, and file contents you authorize us to import (for example lockfiles and SBOMs). Commit history may include contributor identifiers present in imported data
- Location
- United States
- Purpose
- Authentication and organization sign-in
- Personal data processed
- Account identity data, email address, organization membership, and authentication events when you sign in through WorkOS
- Location
- United States
- Purpose
- Application error monitoring and performance diagnostics
- Personal data processed
- Error events, stack traces, request method and URL path, performance traces, browser and device metadata, and related technical identifiers needed to diagnose application failures
- Location
- European Union for configured event ingestion; other operational data may be processed in the United States
- Purpose
- AI-assisted classification of license text
- Personal data processed
- License and notice text extracted from imported software artifacts, declared license identifiers, deployment context, and any personal data contained in the supplied text
- Location
- United States
- Purpose
- Open-source vulnerability advisory lookups for the optional security monitoring add-on
- Personal data processed
- Package ecosystem, name, and version coordinates submitted for advisory matching. Queries do not include account, organization, or project identifiers
- Location
- United States (Google Cloud infrastructure hosting osv.dev)
Public OSV API operated by Google. Advisory matching only; not a penetration test or security audit.
Change log
- July 16, 2026 — Added Google LLC (OSV.dev) for vulnerability advisory lookups used by security monitoring. Also noted that Resend engages PlanetScale, Inc. (United States) for database hosting as part of Resend's own infrastructure (not a SourceTrust direct sub-processor; see Resend's published sub-processor list).
- July 14, 2026 — Added Functional Software, Inc. (Sentry) for application monitoring and OpenAI, L.L.C. for AI-assisted license classification.
- July 9, 2026 — Added GitLab Inc. and Microsoft Corporation (Azure DevOps) as sub-processors for repository connections and code import, mirroring the existing GitHub entry.
- June 13, 2026 — Expanded GitHub data categories for webhook and branch configuration metadata; clarified Cloudflare processing for customer-branded hostnames.
- May 31, 2026 — Clarified Convex EU (Ireland) storage and Resend US storage with SCC-based transfers; added residency notes, vendor DPA links, and change-notification details.
The marketing website at sourcetrust.dev may also use Google Tag Manager / Google Analytics when you choose Accept analytics in the cookie banner. That processing is consent-based, website-only, and described in our cookie policy — not in application customer data flows below.
Questions about sub-processors or to object to a change as described in our DPA: hello@sourcetrust.dev