Riscly uses the following subprocessors to provide the Service. They process personal data on our behalf under data processing agreements (Art. 28 GDPR). This list is part of our Privacy Policy; we update it when subprocessors change.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Authentication & database | USA |
| Render | Application / API hosting | USA |
| Vercel | Frontend hosting & delivery | USA |
| Stripe | Payment processing | USA / Ireland (EU) |
| Resend | Transactional email delivery | USA |
| Anthropic | AI analysis & code fixes (when enabled) | USA |
| GitHub / GitLab | Source code access (when connected) | USA / global |
| OSV.dev (Google) | Known-vulnerability data | USA |
| AWS (if you connect it) | Read-only cloud configuration | Your selected region |
International transfers
Where a subprocessor is located outside the EU/EEA, transfers rely on the EU Standard Contractual Clauses and, where certified, the EU-US Data Privacy Framework, with appropriate supplementary measures.
Notice of changes
We maintain this page as the current record of subprocessors. Business customers with a Data Processing Agreement can request advance notice of new subprocessors at datenschutz@riscly.app.