BleedWatch
00 // SUB-PROCESSORS

Sub-processors and data flow.

This register lists the external providers that may process BleedWatch customer data, the purpose for each provider, the categories of data involved, and the region or transfer mechanism in use.

Last updated 2026-05-07EU-first processingReviewed quarterly
CHANGE NOTIFICATIONS

Advance notice before processor changes.

We notify customers at least 30 days in advance of any new sub-processor or material change in sub-processor scope. Notification includes the provider, purpose, data category, region, transfer mechanism, and objection window.

Subscribe to changes

RSS change feed
01 // ACTIVE SUB-PROCESSORS

Current providers by processing purpose.

The table is intentionally explicit. Optional integrations only process data when the customer connects that integration.

Sub-processorPurposeData categoriesRegionDPA in placeActive since
Hetzner Online GmbHPrimary infrastructureAll customer data, scans, assets, findings, queues, and database storageEU (Germany)SCC + GDPR2025-09
Cloudflare IncKMS proxy, DNS, DDoS protection, edge routingEncrypted master-key mediation, DNS records, edge request telemetryEU edgeSCC2025-09
Anthropic PBCLLM compute for runtime semantic validationSanitized prompts, truncated snippets, no plaintext secretsPer Anthropic configurationZero-retention2025-10
Resend IncTransactional emailEmail address, message content, delivery metadataEUSigned DPA2025-12
Stripe IncBilling and invoicingBilling details only, invoices, payment metadataEUSigned DPA2025-11
Self-hosted Umami (analytics.bleedwatch.com)Privacy-first product analytics, self-hosted by BleedWatch (no third-party processor)Aggregate page views, custom events, no cookies, no PII, no cross-site trackingEU (Hetzner, our own infrastructure)Not applicable - operated by BleedWatch on its own infra2026-05
Cal.com IncBooking and demo schedulingEmail address, company name, scheduling detailsEUSigned DPA2026-04
GitHub IncOAuth integration and repository metadata syncOAuth tokens encrypted at rest, repository metadata, webhook payloadsUS with SCCsSigned DPA2025-10
Slack Technologies LLCOAuth integration and alert deliveryOAuth tokens encrypted at rest, channel IDs, alert payloadsUS with SCCsSigned DPA2025-11
Atlassian Pty LtdJira integrationOAuth tokens, issue metadata, remediation ticketsUS with SCCsSigned DPA2026-02
Linear Orbit IncLinear integrationOAuth tokens, team IDs, remediation ticketsUS with SCCsSigned DPA2026-02
ServiceNow IncServiceNow integrationOAuth tokens, incident records, routing metadataUS with SCCsSigned DPA2026-04
02 // REMOVED SUB-PROCESSORS

No removals since launch.

No sub-processors have been removed since the public launch of this register. If a provider is removed, this section will retain the provider name, removal date, affected purpose, and replacement reason for audit continuity.

03 // CUSTOMER RIGHTS

Objections and enterprise review.

Customers may object to a new sub-processor under their DPA. Enterprise customers can also request a sub-processor audit, transfer-safeguard summary, and data-flow explanation for their connected integrations.

04 // DATA FLOW DIAGRAM

Primary data stays in the EU; AI prompts are sanitized.

The diagram shows the default processing path. LLM providers receive only minimized prompts after secret redaction, hashing, and truncation.

BleedWatch sub-processor data flowCustomer data flows to BleedWatch primary infrastructure on Hetzner EU, then sanitized prompts move through a zero-retention boundary to LLM providers.Customer scopedomains, repos, packagesauthorized scanBleedWatch primaryHetzner EUPostgreSQL RLSAES-256-GCM envelope encryptionhashes + truncated previewssanitized promptsLLM providerAnthropic APIzero-retention boundaryno plaintext secretsno customer credentialsreports and alerts return through BleedWatch only
05 // AUDIT & VERIFICATION

Quarterly register review

Every active processor is reviewed quarterly for purpose, data category, transfer mechanism, and whether the integration is still required.

Change notification

Customers receive at least 30 days advance notice before a new processor is added or a processor materially changes scope.

Enterprise audit support

Customers can request the current processor audit, DPA status, and transfer-safeguard summary through enterprise support.

Questions about a specific sub-processor?

Email [email protected] or open the enterprise contact form with your processor, jurisdiction, and procurement deadline.

Back to Trust Center