Trust Center

Subprocessor list

← Trust Center

Counsel review pending: This page lists core infrastructure subprocessors only. External threat-intelligence APIs (e.g. exposure and breach data providers configured in your deployment) will be added after legal review. Notify security@scrypex.com to receive updates when the list changes.

Core subprocessors (published)

ProviderPurposeData categoriesLocation
SupabasePrimary database, authentication, and file storage for the SCRYPEX applicationAccount email, workspace configuration, findings, audit logs, encrypted integration secretsUnited States (provider region; confirm in order form)
VercelDashboard and API hosting, serverless execution, edge deliveryHTTP request metadata, application logs, environment configurationUnited States / global CDN (provider)
RailwayBackground detection workers and scheduled scan jobsWorker configuration, operational logs, queued job metadata (tenant-scoped)United States (provider)
AnthropicAI-assisted finding enrichment and remediation narrative generationFinding titles, severity, and contextual metadata sent for enrichment (not full credential plaintext)United States (provider)
ResendTransactional email delivery (alerts, account, and product notifications)Recipient email addresses, alert subject/body contentUnited States (provider)
SentryApplication error monitoring and performance diagnosticsScrubbed stack traces, request paths, release metadataUnited States (provider)
StripeSubscription billing and one-time add-on paymentsBilling contact, payment method tokens (handled by Stripe), invoice metadataUnited States (provider)

Threat-intelligence & scan providers (not yet enumerated)

SCRYPEX queries external threat-intelligence and exposure APIs (configured per deployment) using your monitored domains and IPs. Those providers are not listed here until counsel completes a subprocessor review. No customer portal passwords are sent to intel APIs.

Operators configure API keys per deployment (see deployment environment documentation). Queries use monitored domains, hostnames, and IPs — not end-user portal passwords.