Skip to content

Subprocessors

Subprocessors

Effective May 14, 2026 · Sodasoft LLC (30 N Gould St, Sheridan, Wyoming 82801, United States)

NANOTESTING, operated by Sodasoft LLC, engages the third-party subprocessors listed below to deliver the Service. Every subprocessor is bound by written terms that flow down the obligations of the Data Processing Agreement at /legal/dpa.

We post material changes to this inventory at least 30 days before the change takes effect and notify the billing contact on every account by email. To object, follow the process in section 3.4 of the DPA. Latest update: May 14, 2026.

Active subprocessors

VendorServiceData categoriesRegionTransfer mechanism
Vercel Inc.Edge hosting, serverless compute for the marketing site + dashboardAccount email, session cookies, audit-log row id, HTTP request metadataGlobal (US-primary), with EU + AP edgesEU SCCs Module Two + UK IDTA Addendum
Supabase Inc.Managed Postgres (data storage), Row-Level Security, encrypted object storage for raw scan output + PDF reports, magic-link auth issuerAccount data, audit log, billing-profile metadata, findings, scan_jobs, customer-supplied secrets (sealed)EU (eu-central-1) primary; US (us-east-1) for read replicasEU SCCs Module Two + UK IDTA
Fly.io Inc.Scanner worker fleet + isolated sidecar services (Mythril, Echidna, Playwright screenshot)Scan output before it lands in object storage; transient processing onlyEU (Amsterdam) primary; US fallback regionsEU SCCs Module Three (onward sub-processor)
Stripe Payments Europe, Ltd. + Stripe, Inc.Subscription billing, payment-card processing, tax calculationBilling email, name, billing address, payment method, tax idIreland (EEA) + United StatesEU SCCs (Stripe's data-processing terms)
Resend Labs, Inc.Transactional email delivery (magic-link, scan complete, billing receipts)Recipient email, message body, delivery statusUnited StatesEU SCCs Module Three
Cloudflare, Inc.DNS + edge proxy + DDoS mitigation when fronting the marketing site; Cloudflare Turnstile for bot protection on public preview scansIP address (hashed for our persistence), user-agentGlobal anycastEU SCCs Module Three
Functional Software Inc. d/b/a SentryServer + client error monitoring with PII scrubbing in beforeSend and request-payload scrubbing on the Stripe webhook pathStack traces with PII scrubbed, request-context idEuropean Union (Frankfurt - ingest.de.sentry.io)n/a (EU-to-EU); EU SCCs Module Three for any cross-region replication
GitHub, Inc.Source repository hosting for the Service; ingestion of customer-authorised public + private repositories for repo-deep-scanCustomer-pasted GitHub PAT (sealed) + the repo's own contentsUnited StatesEU SCCs Module Three (GitHub Standard DPA)

Threat-intelligence feeds (no personal data)

We consume the following public threat-intel feeds. These do not receive any customer or visitor personal data; they are listed for transparency.

  • CISA Known Exploited Vulnerabilities catalog (cisa.gov)
  • FIRST.org EPSS (first.org/epss)
  • NIST National Vulnerability Database (nvd.nist.gov)
  • U.S. Treasury OFAC SDN list (Web3 add-on only)

How to follow changes

Subscribe to privacy@nanotesting.com with subject line “Subscribe to subprocessor updates”. We will email any material change at least 30 days before it takes effect.