Skip to content

Subprocessors

Third-party services that process Kliper customer data, what they process, and where.

Updated View as Markdown

This page lists every third-party service Kliper uses to deliver the platform, what each one processes on your behalf, and the region the data is processed in. We commit to maintaining this list as a current, authoritative record — when we add or remove a subprocessor, this page is updated and a corresponding entry is added to the changelog.

If you have signed a Data Processing Addendum (DPA) with Kort Labs, we will notify your designated contact at least 30 days before adding a new subprocessor that processes personal data.

Last updated: 2026-06-17.

What is a subprocessor?

Under GDPR and similar privacy regulations, a subprocessor is any third party Kort Labs (operator of Kliper) engages to process customer personal data on our behalf. This includes infrastructure providers, AI vendors, analytics platforms, and security tooling.

We distinguish three categories below:

  1. Active subprocessors — process customer or end-user data.
  2. Service providers (no customer data) — used to operate Kliper but do not receive customer data.
  3. Own infrastructure — operated by Kort Labs directly; not third-party subprocessors, listed here for transparency.

Active subprocessors

Subprocessor Purpose Data processed Processing region Reference
OpenAI, L.L.C. AI features — the Cortex conversational agent (drafts ROC findings, answers requirement questions, plans remediation), document extraction, autofill drafting, document validation, and file summaries Prompts containing requirement text, your draft responses, evidence file names, and AI-generated summaries, with PII redacted before sending. Raw file content is sent only when Document Validation is invoked (max 30,000 characters of extracted text). United States Enterprise privacy — API data is not used to train models.
PostHog Inc. (US entity; EU data hosted via Hetzner Frankfurt) Product analytics — anonymous event counts (signups, logins, assessments created, evidence uploaded, Cortex messages sent) Pseudonymous user ID, organization ID, organization role, event names, and aggregated event properties (e.g. file size bucket, framework ID). Never file content, file names, requirement text, message bodies, or PII. Session recording and autocapture are explicitly disabled. European Union (eu.i.posthog.com, Hetzner Frankfurt) PostHog DPA — SOC 2 Type II, HIPAA available.
Functional Software, Inc. (Sentry) Error monitoring — captures backend and frontend exceptions for debugging (active when an error-monitoring DSN is configured) Stack traces, request URLs (paths only, query strings scrubbed), and error context. PII scrubbing is enabled at the SDK level; we never attach evidence content or message bodies to error reports. United States Sentry DPA — SOC 2 Type II, ISO 27001.
Chronicle Security Ireland Ltd. (VirusTotal) Malware scanning — checks uploaded files against 70+ AV engines SHA-256 hash only. The file itself is never uploaded to VirusTotal. If the hash is unknown to VirusTotal, the result is treated as clean. European Union / United States (Google Cloud) VirusTotal privacy — hash lookups are not personal data; we do not opt into file submission.
Polar Software Inc. Payment processing (Merchant of Record) — subscription checkout, invoices, and tax/VAT Billing email, organization name, payment method (entered on Polar’s own checkout domain), and invoice line items. Card data never touches Kliper servers — the PCI scope is Polar’s. United States Polar — Merchant of Record.
Stripe, Inc. (legacy) Legacy payment processing — being phased out; retained only for organizations still on Stripe billing rows Billing email, organization name, payment method tokens, invoice line items. Card numbers are tokenized by Stripe and never touch Kliper servers. United States Stripe DPA — PCI DSS Level 1.
Cloudflare, Inc. DNS, CDN, edge TLS termination, DDoS mitigation, and hosting of this documentation site (docs.kliper.dev, a static Worker) All HTTP request metadata (IP, user agent, path, headers) flows through Cloudflare’s edge. Request bodies are passed through but not stored. The documentation site holds no customer data. Global edge network; request body data terminates at our nginx in Cloudflare’s German region. Cloudflare DPA — SOC 2 Type II, ISO 27001.
BetterStack (Better Stack S.R.O.) Status page hosting and uptime monitoring Public health-check requests to app.kliper.dev/health and other public endpoints. Responses are non-sensitive (HTTP status + JSON health body). No customer data is sent to BetterStack. European Union BetterStack DPA

Service providers (no customer data)

Service Purpose Why it’s listed Reference
GitHub, Inc. Source code hosting (private repository) Source code only — no production data ever pushed to GitHub. CI workflows run on GitHub-hosted runners but do not have production credentials. GitHub DPA

Own infrastructure (operated by Kort Labs)

These components are operated directly by Kort Labs on our own infrastructure, not by a third party. They are listed here for full transparency.

Component What it does Location
PostgreSQL (primary database) Stores assessments, evidence metadata, user records EU — Kort Labs infrastructure (supabase.kliper.local, private network)
Supabase Auth + Storage (self-hosted) Authentication backbone and encrypted file storage EU — Kort Labs infrastructure (supabase.kortlabs.xyz)
Redis Session cache, rate-limit counters, queue jobs EU — Kort Labs infrastructure (redis-db.kliper.local, private network)
SMTP relay Transactional email (password reset, magic links, invitations) EU — Kort Labs mail server (mail.kortlabs.com)
Cortex agent (self-hosted profile, optional) Kliper supports an optional self-hosted model profile for deployments that require agent prompts to stay on-infrastructure. The standard cloud deployment uses OpenAI (see External subprocessors above). On-prem / configurable per deployment

How we vet subprocessors

Before engaging a new subprocessor, we verify:

Independent security attestation

SOC 2 Type II, ISO 27001, or equivalent third-party audit report covering the relevant scope.

Signed Data Processing Addendum

The subprocessor must offer a DPA aligned with GDPR Article 28 (or successor framework).

Data minimization design

We design the integration to send the smallest possible payload. Examples: VirusTotal receives only a SHA-256 hash, PostHog never sees file names, Sentry has PII scrubbing enabled at the SDK.

Regional fit

For EU customer data, we prefer subprocessors that offer EU processing regions. The PostHog deployment is on eu.i.posthog.com for this reason.

Changes to this list

Material changes (additions, removals, region changes) are logged in the changelog. Customers under a DPA receive 30 days’ written notice before a new subprocessor receives their data. Object to a new subprocessor by emailing security@kortlabs.com.

Was this helpful?

Report an issue with this page
Navigation

Type to search…

↑↓ navigate↵ selectEsc close