Subprocessors
Subprocessors
Effective · Sodasoft LLC (30 N Gould St, Sheridan, Wyoming 82801, United States)
NANOTESTING, operated by Sodasoft LLC, engages the third-party subprocessors listed below to deliver the Service. Every subprocessor is bound by written terms that flow down the obligations of the Data Processing Agreement at /legal/dpa.
We post material changes to this inventory at least 30 days before the change takes effect and notify the billing contact on every account by email. To object, follow the process in section 3.4 of the DPA. Latest update: May 14, 2026.
Active subprocessors
| Vendor | Service | Data categories | Region | Transfer mechanism |
|---|---|---|---|---|
| Vercel Inc. | Edge hosting and serverless compute for the marketing site + dashboard; Vercel Blob private object storage for PDF reports, raw scan output, scan evidence, uploaded mobile binaries and verification documents | Account email, session cookies, audit-log row id, HTTP request metadata, and the stored objects listed above | Hosting: global (US-primary) with EU + AP edges. Object storage: United States (iad1 / us-east-1) | EU SCCs Module Two + UK IDTA Addendum |
| Neon, LLC (a Databricks, Inc. company) | Managed Postgres - the primary data store - with Row-Level Security enforced per organisation | Account data, audit log, billing-profile metadata, findings, scan_jobs, customer-supplied secrets (sealed) | United States (AWS us-east-1) | EU SCCs Module Two and Module Three, plus the UK International Data Transfer Addendum (ICO version B1.0), per the Databricks Data Processing Addendum |
| Fly.io Inc. | Scanner worker fleet + isolated sidecar services (Mythril, Echidna, Playwright screenshot) | Scan output before it lands in object storage; transient processing only | EU (Amsterdam) primary; US fallback regions | EU SCCs Module Three (onward sub-processor) |
| Stripe Payments Europe, Ltd. + Stripe, Inc. | Subscription billing, payment-card processing, tax calculation | Billing email, name, billing address, payment method, tax id | Ireland (EEA) + United States | EU SCCs (Stripe's data-processing terms) |
| Resend Labs, Inc. | Transactional email delivery (magic-link, scan complete, billing receipts) | Recipient email, message body, delivery status | United States | EU SCCs Module Three |
| Cloudflare, Inc. | DNS + edge proxy + DDoS mitigation when fronting the marketing site; Cloudflare Turnstile for bot protection on public forms | IP address (hashed for our persistence), user-agent | Global anycast | EU SCCs Module Three |
| Functional Software Inc. d/b/a Sentry | Server + client error monitoring with PII scrubbing in beforeSend and request-payload scrubbing on the Stripe webhook path | Stack traces with PII scrubbed, request-context id | European Union (Frankfurt - ingest.de.sentry.io) | n/a (EU-to-EU); EU SCCs Module Three for any cross-region replication |
| GitHub, Inc. | Source repository hosting for the Service; ingestion of customer-authorised public + private repositories for repo-deep-scan | Customer-pasted GitHub PAT (sealed) + the repo's own contents | United States | EU SCCs Module Three (GitHub Standard DPA) |
Recent changes
3 September 2026 - database subprocessor replaced. Managed Postgres moved from Supabase Inc. to Neon, LLC. Object storage for reports, scan output, scan evidence and uploaded binaries moved from Supabase Storage to Vercel Blob, and magic-link authentication is now issued by our own application rather than by a third party - so Supabase Inc. no longer processes any customer data and has been removed from the inventory above.
Two things about this change we would rather state than have you discover. First, it took effect immediately and was not posted 30 days in advance as this page otherwise commits to; the previous provider was being decommissioned and the migration could not wait out the notice period. Second, the primary database region changed: the previous entry recorded EU (eu-central-1) as primary, and the database now runs in the United States (AWS us-east-1), as does the object storage (iad1). Transfers are covered by the mechanisms named in the table. If your use of the Service depends on EU-resident storage, contact us at privacy@nanotesting.com and we will tell you exactly where your data sits.
Threat-intelligence feeds (no personal data)
We consume the following public threat-intel feeds. These do not receive any customer or visitor personal data; they are listed for transparency.
- CISA Known Exploited Vulnerabilities catalog (cisa.gov)
- FIRST.org EPSS (first.org/epss)
- NIST National Vulnerability Database (nvd.nist.gov)
- U.S. Treasury OFAC SDN list (Web3 add-on only)
How to follow changes
Subscribe to privacy@nanotesting.com with subject line “Subscribe to subprocessor updates”. We will email any material change at least 30 days before it takes effect.