SourceTrust

Legal

Sub-processors

Third-party vendors that process personal data on our behalf when you use the application.

Last updated: July 16, 2026

These third-party service providers (“sub-processors”) process personal data on our behalf when you use the SourceTrust application or related services. We remain responsible for their performance under our Data Processing Agreement.

This list forms part of our Data Processing Agreement. We update this list when we add or replace sub-processors. Material changes are reflected here and communicated to application customers as described in our DPA.

We give application customers at least fourteen (14) days' notice before adding or replacing a sub-processor that processes application customer data, by updating this page and - where practicable - emailing organization administrators associated with the account. You may object on reasonable data-protection grounds as described in our DPA.

Location means where the sub-processor stores customer data by default - not necessarily where every operation runs. For email providers, a sending region (for example Resend eu-west-1) controls dispatch routing only; account data, logs, and metadata may still be stored elsewhere.

Where a sub-processor stores data outside the European Economic Area or United Kingdom, we rely on appropriate transfer safeguards such as Standard Contractual Clauses in the vendor’s published DPA where applicable.

  • Purpose
    Hosting, CDN, security, and Turnstile (CAPTCHA) for the marketing site, public scan, and published attestation pages (including customer-branded hostnames)
    Personal data processed
    IP addresses, request metadata, URLs submitted to the site scan, visitor logs for published compliance pages on default or customer-branded hostnames, Turnstile verification signals, and related technical logs needed to deliver and protect our sites
    Location
    United States and other regions where Cloudflare operates
  • Purpose
    Application database and backend hosting
    Personal data processed
    Account, organization, and project data you store in the application — including inventory, compliance pages, and related metadata
    Location
    European Union (Ireland — Convex deployment region eu-west-1)
  • Purpose
    Transactional email
    Personal data processed
    Email addresses and message content for account, security, and service notifications we send on your behalf or to your users
    Location
    United States (customer account data, email metadata, and logs)

    We may send from eu-west-1 (Ireland); that region affects dispatch only. Resend stores customer data in the United States regardless. Resend's own infrastructure sub-processors include PlanetScale, Inc. (database hosting, United States); see https://resend.com/legal/subprocessors.

  • Purpose
    Payment processing and subscription billing
    Personal data processed
    Billing contact details, payment method metadata, transaction records, and tax-related information for paid subscriptions
    Location
    United Kingdom / European operations as applicable; processing may involve other jurisdictions Paddle uses
  • Purpose
    Repository connections and code import
    Personal data processed
    Authentication tokens, repository and organization metadata, watched branch configuration, webhook or sync event metadata, and file contents you authorize us to import (for example lockfiles and SBOMs). Commit history may include contributor identifiers present in imported data
    Location
    United States
  • Purpose
    Repository connections and code import
    Personal data processed
    Access tokens, project and namespace metadata, watched branch configuration, webhook or sync event metadata, and file contents you authorize us to import (for example lockfiles and SBOMs). Commit history may include contributor identifiers present in imported data
    Location
    United States
  • Purpose
    Repository connections and code import
    Personal data processed
    Personal access tokens, organization/project/repository metadata, watched branch configuration, service-hook event metadata, and file contents you authorize us to import (for example lockfiles and SBOMs). Commit history may include contributor identifiers present in imported data
    Location
    United States
  • Purpose
    Authentication and organization sign-in
    Personal data processed
    Account identity data, email address, organization membership, and authentication events when you sign in through WorkOS
    Location
    United States
  • Purpose
    Application error monitoring and performance diagnostics
    Personal data processed
    Error events, stack traces, request method and URL path, performance traces, browser and device metadata, and related technical identifiers needed to diagnose application failures
    Location
    European Union for configured event ingestion; other operational data may be processed in the United States
  • Purpose
    AI-assisted classification of license text
    Personal data processed
    License and notice text extracted from imported software artifacts, declared license identifiers, deployment context, and any personal data contained in the supplied text
    Location
    United States
  • Purpose
    Open-source vulnerability advisory lookups for the optional security monitoring add-on
    Personal data processed
    Package ecosystem, name, and version coordinates submitted for advisory matching. Queries do not include account, organization, or project identifiers
    Location
    United States (Google Cloud infrastructure hosting osv.dev)

    Public OSV API operated by Google. Advisory matching only; not a penetration test or security audit.

Change log

  • July 16, 2026Added Google LLC (OSV.dev) for vulnerability advisory lookups used by security monitoring. Also noted that Resend engages PlanetScale, Inc. (United States) for database hosting as part of Resend's own infrastructure (not a SourceTrust direct sub-processor; see Resend's published sub-processor list).
  • July 14, 2026Added Functional Software, Inc. (Sentry) for application monitoring and OpenAI, L.L.C. for AI-assisted license classification.
  • July 9, 2026Added GitLab Inc. and Microsoft Corporation (Azure DevOps) as sub-processors for repository connections and code import, mirroring the existing GitHub entry.
  • June 13, 2026Expanded GitHub data categories for webhook and branch configuration metadata; clarified Cloudflare processing for customer-branded hostnames.
  • May 31, 2026Clarified Convex EU (Ireland) storage and Resend US storage with SCC-based transfers; added residency notes, vendor DPA links, and change-notification details.

The marketing website at sourcetrust.dev may also use Google Tag Manager / Google Analytics when you choose Accept analytics in the cookie banner. That processing is consent-based, website-only, and described in our cookie policy — not in application customer data flows below.

Questions about sub-processors or to object to a change as described in our DPA: hello@sourcetrust.dev