Sub-processors
Every third party that processes customer data on Denpex's behalf. We give 30 days' notice of changes via email and the changelog RSS feed.
| Sub-processor | Purpose | Data region | Vendor-attested certifications |
|---|---|---|---|
| Cloudflare | Hosting, edge network, KV, D1, Workers, R2 | Global edge (data stored in your selected region) | SOC 2 Type II, ISO 27001, PCI DSS |
| Stripe | Payment processing and subscription management | US, EU (by customer selection) | PCI DSS Level 1, SOC 2 Type II, ISO 27001 |
| SendGrid (Twilio) | Transactional email (signups, alerts, contact replies) | US, EU (region selectable) | SOC 2 Type II, ISO 27001, HIPAA-eligible |
| Google (Gemini, OAuth, Search, YouTube) | Primary AI log analysis via the Denpex proxy (training logs may contain hostnames, paths, and environment details); authentication identifiers; and log-derived search queries sent to Google Search or YouTube when those optional research paths are used | Provider-dependent | Vendor-attested; scope varies by service |
| Anthropic (Claude) | AI-powered log analysis and failure diagnosis, fallback model path via the Denpex proxy when the primary model is rate-limited | US | SOC 2 Type II |
| DeepSeek | AI-powered log analysis, secondary fallback when the primary proxy is exhausted | Provider-dependent | Vendor-attested (provider-dependent) |
| Groq | AI-powered log analysis, optional fallback provider | Provider-dependent | Vendor-attested; review the configured service terms |
| TokenHub | AI-powered log analysis, optional fallback routing service | Provider-dependent | Vendor-attested; review the configured service terms |
| PostHog | Product analytics (opt-in via cookie consent) | US, EU | SOC 2 Type II |
| GitHub | Source code hosting, CI/CD, issue tracking, and optional issue research using log-derived query text | US (data in your selected region) | SOC 2 Type II, ISO 27001 |
| Slack (optional) | Alert delivery when customer configures Slack as a channel | US | SOC 2 Type II, ISO 27001, FedRAMP Moderate |
| PagerDuty (optional) | Incident routing when customer configures PagerDuty as a channel | US, EU | SOC 2 Type II, ISO 27001, HIPAA |
| Vonage / Nexmo (optional) | SMS alert delivery, preferred SMS provider when configured | US, EU | Vendor-attested |
| Twilio (optional) | SMS / iMessage alert delivery, fallback SMS provider when Vonage is not configured | US, EU | SOC 2 Type II, ISO 27001, HIPAA-eligible |
| Stack Exchange | Optional community search using log-derived query text | Provider-dependent | Vendor-attested |
| Algolia (Hacker News search) | Optional Hacker News index search using log-derived query text | Provider-dependent | Vendor-attested |
| Y Combinator (Hacker News) | Optional community-result retrieval using log-derived query text | Provider-dependent | Vendor-attested |
| Lobsters | Optional community search using log-derived query text | Provider-dependent | Vendor-attested |
| Optional community search using log-derived query text | Provider-dependent | Vendor-attested | |
| DEV Community (Forem) | Optional developer-community search using log-derived query text | Provider-dependent | Vendor-attested |
| GitLab | Optional issue and code search using log-derived query text | Provider-dependent | Vendor-attested |
| Exa | Optional web research using log-derived query text | Provider-dependent | Vendor-attested |
| OpenCode | Optional developer research using log-derived query text | Provider-dependent | Vendor-attested |
| Discord | Optional community-result retrieval and linked attachment delivery | Provider-dependent | Vendor-attested |
Certifications listed are each sub-processor's own attestations (vendor-attested), not Denpex certifications.
We give 30 days' notice before adding a new sub-processor via email and the changelog RSS feed. Customers may object in writing; if we cannot resolve the concern you may terminate the affected services for a pro-rated refund.