VendorStacks

Subprocessors

Effective 2026-08-09

We built VendorStacks because subprocessor disclosure is useful and under-published. It would be absurd not to publish our own. These are the vendors that process data on our behalf, what they do, and what they see.

SubprocessorPurposeData processedRegion
VercelWebsite and dashboard hosting, CDNRequest metadata, IP addressesUS
RailwayAPI and worker hostingRequest metadata, API logsUS
SupabasePrimary databaseAccount, usage, billing records, indexed disclosuresUS
ClerkAuthentication and session managementEmail, authentication identifiersUS
StripePayment processingBilling contact, payment recordsUS
ResendTransactional and support emailEmail address, message contentsUS
PostHogProduct analyticsPageviews, in-app events, IP addressUS
CloudflareDNS and edge protectionRequest metadata, IP addressesGlobal
FirecrawlPage rendering for public disclosure pagesPublic URLs only — no customer dataUS
SerperSearch index lookups for disclosure discoveryPublic search queries — no customer dataUS
AnthropicGenerating internal discovery queriesNo customer data and no personal dataUS
sent.dmOperational SMS alerts to our own teamOrder amount, our own phone numberUS

Notice of changes

This page is updated when a subprocessor is added or removed. If you want advance notice by email before a new subprocessor starts processing your data, ask us through support and we will add you to the notification list.