Subprocessors
Last updated: June 19, 2026
To deliver SBOMVault.ai, we engage the third-party service providers (“subprocessors”) listed below to process customer data on our behalf. Each is bound by a data processing agreement that requires it to protect the data consistent with our obligations under our Data Processing Agreement and Privacy Policy.
Current Subprocessors
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Vercel, Inc. | Application hosting & serverless compute | All application data in transit; operational logs | United States |
| Neon, Inc. | Managed PostgreSQL database | Account, organization, and SBOM metadata; settings | United States |
| Vercel Blob (Vercel, Inc.) | Encrypted object storage for uploaded SBOM files | SBOM file contents | United States |
| Stripe, Inc. | Payment processing & subscription billing | Name, email, billing and payment details | United States |
| Resend | Transactional email delivery | Name, email address, notification content | United States |
| WorkOS, Inc. | Enterprise SSO & SCIM directory sync (only if your organization enables SSO) | Name, email, directory attributes | United States |
| Anthropic, PBC | AI assistant ("Vault AI") responses (only if you use AI features) | The SBOM/vulnerability context you submit to the assistant | United States |
| Google LLC | Website analytics on the public marketing site only | Pseudonymous usage and device data | United States |
Changes & Notifications
We may add or replace subprocessors as the service evolves. When we do, we will update this page and the “Last updated” date. Customers with an executed Data Processing Agreement may subscribe to advance notice of subprocessor changes by emailing privacy@sbomvault.ai, and may object to a new subprocessor as provided in that agreement.
Contact
Questions about our subprocessors can be sent to privacy@sbomvault.ai.