aisecurity.llc
Subprocessors
This page identifies third-party providers that may process data for aisecurity.llc. Some providers are core platform providers, some are conditional feature providers, and some are customer-configured integrations used only when a customer enables or connects them.
Plain-English summary
- We do not sell personal information.
- Customer data is not used to train public AI models.
- Subprocessors vary by feature, agreement, and customer configuration.
- Customer-configured integrations are controlled by the customer or admin where supported.
- DPA, SOW, and private-offer terms may define additional subprocessor rights or restrictions.
How to read this page
Core platform providers are used to run the site and product. Conditional feature providers are used only when a feature is enabled or an engagement requires them. Customer-configured integrations are only connected when a customer enables them. Some tools may be used only for specific professional-services engagements under written scope.
Subprocessor Categories
Core Platform Providers
Providers used to run the public site, product, storage, source control, authentication, and core email or transactional communications.
Conditional Feature Providers
Providers used only when a specific feature, workflow, or engagement requires them, including analytics, diagnostics, billing, file processing, support tooling, or training infrastructure where enabled.
AI Model Providers
Providers used for SecEng Copilot and related analysis, drafting, packet, report, and security-workflow assistance where enabled.
Payment and Billing Providers
Payment processors and billing systems used for checkout, subscriptions, invoices, seats, and entitlements.
Customer-Configured Integrations
Customer-selected services that are only connected when a customer or admin enables them.
Professional Services / Engagement Tools
Engagement-specific portals, file exchange, document processing, and collaboration tooling used under written scope.
Provider Table
| Provider | Category | Purpose | Data processed | Used by default or conditional | Notes |
|---|---|---|---|---|---|
| Vercel, Inc. | Core Platform Providers | Web application hosting, serverless compute, and global edge delivery | Request metadata, session data, application payloads, and operational logs | Default | Core hosting for the public website and web application. |
| Cloudflare, Inc. | Core Platform Providers | CDN, DNS, DDoS protection, and edge security | IP addresses, HTTP metadata, and security event data | Default | Core network protection and edge delivery. |
| Supabase, Inc. | Core Platform Providers | Database hosting, authentication, file storage, and backend services | Account data, organization/workspace records, uploaded files, packet metadata, and auth events | Default | Core platform data store and auth backbone. |
| GitHub, Inc. (Microsoft) | Core Platform Providers | Source control, CI/CD, repository collaboration, and optional OAuth identity flows | Source code, pull request or issue metadata, deployment metadata, and limited auth metadata where enabled | Default | Primarily internal engineering and collaboration data. |
| Resend, Inc. | Core Platform Providers | Transactional email and account notifications | Email addresses, message content, and delivery metadata | Default | Core communications provider. |
| Vercel Analytics | Conditional Feature Providers | Web analytics and performance diagnostics | Page views, device type, and aggregate performance metrics | Conditional | Aggregate telemetry only; enabled where the feature is in use. |
| Stripe, Inc. | Payment and Billing Providers | Checkout, subscriptions, invoices, seats, and entitlements | Billing contact details, transaction metadata, subscription state, customer identifiers, and payment data handled by Stripe | Conditional | Full card data is handled by Stripe, not aisecurity.llc, unless the implementation says otherwise. |
| Anthropic, PBC | AI Model Providers | SecEng Copilot, security analysis, drafting, packet support, and report assistance where enabled | Prompts, selected workspace context, uploaded evidence or artifacts when used, and generated outputs | Conditional | Customer content submitted through approved service or platform pathways is not authorized for provider model training. AI-free or restricted processing may be available where agreed in writing. |
| OpenAI, LLC | AI Model Providers | SecEng Copilot, security analysis, drafting, packet support, and report assistance where enabled | Prompts, selected workspace context, uploaded evidence or artifacts when used, and generated outputs | Conditional | Customer content submitted through approved service or platform pathways is not authorized for provider model training. AI-free or restricted processing may be available where agreed in writing. |
| Customer-configured integrations | Customer-Configured Integrations | Slack, GitHub, Jira, Google Workspace, Microsoft, Okta, AWS, cloud/SaaS providers, LMS/SCORM, ticketing systems, repositories, and other customer systems | Whatever the customer routes and the scopes or permissions allow | Conditional | Customer/admin controlled where supported; third-party terms apply; revocable where supported. |
| Customer-approved engagement tools | Professional Services / Engagement Tools | Secure portals, encrypted file exchange, document processing, support tooling, and collaboration for a specific engagement | Evidence uploads, questionnaires, packet drafts, support messages, and deliverables | Conditional | Used only for a specific engagement under SOW, NDA, DPA, ROE, or similar written instruction. |
Customer-Configured Integration Warning
Connecting a third-party system may allow aisecurity.llc features to process metadata, files, messages, tickets, code, logs, identities, or other data from that system depending on the scopes granted and the feature used. Customers should connect only systems they are authorized to administer or assess and should revoke integrations when no longer needed.
Subprocessor Changes
Material changes may be reflected on this page as the platform evolves. Enterprise agreements may define advance-notice or objection rights for new subprocessors, and those agreement terms control for the applicable engagement.
Feature-specific subprocessors may also be disclosed in the packet or SOW where needed.
Customers should review this page together with the Privacy Policy, the DPA, and any applicable SOW or private-offer terms.
Subprocessors · aisecurity.llc · Effective June 27, 2026 · Version 1.0