---
title: "Subprocessors"
description: "Third-party services that process Kliper customer data, what they process, and where."
version: "en"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.kliper.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Subprocessors

This page lists every third-party service Kliper uses to deliver the platform, what each one processes on your behalf, and the region the data is processed in. We commit to maintaining this list as a current, authoritative record — when we add or remove a subprocessor, this page is updated and a corresponding entry is added to the [changelog](/changelog).

If you have signed a Data Processing Addendum (DPA) with Kort Labs, we will notify your designated contact at least **30 days before adding a new subprocessor** that processes personal data.

Last updated: **2026-06-17**.

## What is a subprocessor?

Under GDPR and similar privacy regulations, a *subprocessor* is any third party Kort Labs (operator of Kliper) engages to process customer personal data on our behalf. This includes infrastructure providers, AI vendors, analytics platforms, and security tooling.

We distinguish three categories below:

1. **Active subprocessors** — process customer or end-user data.
2. **Service providers (no customer data)** — used to operate Kliper but do not receive customer data.
3. **Own infrastructure** — operated by Kort Labs directly; not third-party subprocessors, listed here for transparency.

## Active subprocessors

| Subprocessor | Purpose | Data processed | Processing region | Reference |
|---|---|---|---|---|
| **OpenAI, L.L.C.** | AI features — the **Cortex conversational agent** (drafts ROC findings, answers requirement questions, plans remediation), document extraction, autofill drafting, document validation, and file summaries | Prompts containing requirement text, your draft responses, evidence file names, and AI-generated summaries, with **PII redacted before sending**. **Raw file content is sent only when Document Validation is invoked** (max 30,000 characters of extracted text). | United States | [Enterprise privacy](https://openai.com/enterprise-privacy) — API data is not used to train models. |
| **PostHog Inc.** (US entity; EU data hosted via Hetzner Frankfurt) | Product analytics — anonymous event counts (signups, logins, assessments created, evidence uploaded, Cortex messages sent) | Pseudonymous user ID, organization ID, organization role, event names, and aggregated event properties (e.g. file size bucket, framework ID). **Never** file content, file names, requirement text, message bodies, or PII. Session recording and autocapture are explicitly disabled. | European Union (`eu.i.posthog.com`, Hetzner Frankfurt) | [PostHog DPA](https://posthog.com/dpa) — SOC 2 Type II, HIPAA available. |
| **Functional Software, Inc. (Sentry)** | Error monitoring — captures backend and frontend exceptions for debugging (active when an error-monitoring DSN is configured) | Stack traces, request URLs (paths only, query strings scrubbed), and error context. **PII scrubbing is enabled at the SDK level**; we never attach evidence content or message bodies to error reports. | United States | [Sentry DPA](https://sentry.io/legal/dpa/) — SOC 2 Type II, ISO 27001. |
| **Chronicle Security Ireland Ltd. (VirusTotal)** | Malware scanning — checks uploaded files against 70+ AV engines | **SHA-256 hash only**. The file itself is never uploaded to VirusTotal. If the hash is unknown to VirusTotal, the result is treated as clean. | European Union / United States (Google Cloud) | [VirusTotal privacy](https://docs.virustotal.com/docs/how-it-works) — hash lookups are not personal data; we do not opt into file submission. |
| **Polar Software Inc.** | Payment processing (**Merchant of Record**) — subscription checkout, invoices, and tax/VAT | Billing email, organization name, payment method (entered on Polar's own checkout domain), and invoice line items. **Card data never touches Kliper servers** — the PCI scope is Polar's. | United States | [Polar](https://polar.sh) — Merchant of Record. |
| **Stripe, Inc.** *(legacy)* | Legacy payment processing — being phased out; retained only for organizations still on Stripe billing rows | Billing email, organization name, payment method tokens, invoice line items. Card numbers are tokenized by Stripe and never touch Kliper servers. | United States | [Stripe DPA](https://stripe.com/legal/dpa) — PCI DSS Level 1. |
| **Cloudflare, Inc.** | DNS, CDN, edge TLS termination, DDoS mitigation, and hosting of this documentation site (`docs.kliper.dev`, a static Worker) | All HTTP request metadata (IP, user agent, path, headers) flows through Cloudflare's edge. Request bodies are passed through but not stored. The documentation site holds no customer data. | Global edge network; request body data terminates at our nginx in Cloudflare's German region. | [Cloudflare DPA](https://www.cloudflare.com/cloudflare-customer-dpa/) — SOC 2 Type II, ISO 27001. |
| **BetterStack (Better Stack S.R.O.)** | Status page hosting and uptime monitoring | Public health-check requests to `app.kliper.dev/health` and other public endpoints. Responses are non-sensitive (HTTP status + JSON health body). **No customer data is sent to BetterStack.** | European Union | [BetterStack DPA](https://betterstack.com/dpa) |

## Service providers (no customer data)

| Service | Purpose | Why it's listed | Reference |
|---|---|---|---|
| **GitHub, Inc.** | Source code hosting (private repository) | Source code only — no production data ever pushed to GitHub. CI workflows run on GitHub-hosted runners but do not have production credentials. | [GitHub DPA](https://docs.github.com/en/site-policy/privacy-policies/github-data-protection-agreement) |

## Own infrastructure (operated by Kort Labs)

These components are operated directly by Kort Labs on our own infrastructure, not by a third party. They are listed here for full transparency.

| Component | What it does | Location |
|---|---|---|
| **PostgreSQL (primary database)** | Stores assessments, evidence metadata, user records | EU — Kort Labs infrastructure (`supabase.kliper.local`, private network) |
| **Supabase Auth + Storage (self-hosted)** | Authentication backbone and encrypted file storage | EU — Kort Labs infrastructure (`supabase.kortlabs.xyz`) |
| **Redis** | Session cache, rate-limit counters, queue jobs | EU — Kort Labs infrastructure (`redis-db.kliper.local`, private network) |
| **SMTP relay** | Transactional email (password reset, magic links, invitations) | EU — Kort Labs mail server (`mail.kortlabs.com`) |
| **Cortex agent (self-hosted profile, optional)** | Kliper supports an optional self-hosted model profile for deployments that require agent prompts to stay on-infrastructure. The standard cloud deployment uses OpenAI (see External subprocessors above). | On-prem / configurable per deployment |

## How we vet subprocessors

Before engaging a new subprocessor, we verify:

1. **Independent security attestation**

   SOC 2 Type II, ISO 27001, or equivalent third-party audit report covering the relevant scope.
2. **Signed Data Processing Addendum**

   The subprocessor must offer a DPA aligned with GDPR Article 28 (or successor framework).
3. **Data minimization design**

   We design the integration to send the smallest possible payload. Examples: VirusTotal receives only a SHA-256 hash, PostHog never sees file names, Sentry has PII scrubbing enabled at the SDK.
4. **Regional fit**

   For EU customer data, we prefer subprocessors that offer EU processing regions. The PostHog deployment is on `eu.i.posthog.com` for this reason.

## Changes to this list

Material changes (additions, removals, region changes) are logged in the [changelog](/changelog). Customers under a DPA receive 30 days' written notice before a new subprocessor receives their data. Object to a new subprocessor by emailing [security@kortlabs.com](mailto:security@kortlabs.com).

> **Note**
>
> This page is the authoritative record. If you have a contractual subprocessor list bundled with your DPA, that list points to this URL.

Source: https://docs.kliper.dev/subprocessors/index.mdx
