Openwake's own subprocessors
The standard we hold vendors to, applied to ourselves: a dated list, 30 days' notice of additions by email to every organisation with a watchlist, and a right to object. Last updated: 2026-09-05.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Fly.io | hosting the API and web application | all customer data in transit and in memory | Amsterdam (ams) |
| Managed Postgres provider (Neon or Fly Postgres — stated here at go-live) | the database | all customer data at rest; alert channels sealed with AES-256-GCM before storage | EU region |
| Resend | transactional email: alerts, digests, claim links | recipient email address, alert content (vendor names, quotes, diffs) | United States |
| Stripe | payments and subscriptions | billing contact, payment details (never stored by Openwake) | United States |
| Slack | alert delivery, only where you configure an incoming webhook | alert content | per your workspace |
| GitHub | source code and the public ledger anchors | ledger head hashes and signatures only; no customer data | United States |
Not used: analytics or tracking providers; AI providers on customer data (the default extractor is deterministic and reads only vendors' public documents; a model, when enabled, never sees customer data).