Last Updated: 15.07.2026
At Superhack, we use a small set of trusted third-party service providers to help us operate our platform reliably, securely, and at scale. Some of these partners process customer data in order to provide infrastructure, customer support, analytics, or product functionality. When they do so on our behalf, they qualify as Subprocessors under the GDPR. Each one is contractually bound by obligations that match or exceed those in our Data Processing Agreement (DPA).
Most of our Subprocessor tenants are located in the European Union. Where a Subprocessor processes personal data outside the EEA, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs), for the transfer.
In addition to SCCs, Superhack performs a risk-based due diligence process before engaging any non-EEA Subprocessor. This includes:
This ensures we only work with vendors who meet our internal standards and customer expectations.
The table below lists our Subprocessors, the purpose for which each is engaged, the data it processes, whether it processes Customer data, and the region in which processing takes place.
| Subprocessor | Purpose of Processing | Data Processed |
|---|---|---|
| Neon | Managed Postgres — the primary application database | Stores all tenant, asset, scan, finding, and user data |
| Render | Hosts the worker service that runs the scan agents | Processes target and scan data during authorized testing |
| Vercel | Hosts the web application; object storage via Vercel Blob | End-user data in transit; asset screenshots stored in Blob |
| Anthropic | Claude models via the Agent SDK — the core scan engine | Reads target and scan data to drive testing |
| OpenAI | CVE embeddings and small parsing calls | Reads target and scan data to drive testing |
| Resend | Transactional email delivery | Recipient email addresses and message content |
| PostHog | Product analytics (EU cloud) | Usage events, identifiers, IP addresses |
| Notion | Internal documentation and knowledge base | Business and operational data |
| Google Workspace | Email, calendar, and internal collaboration | Internal business communications |
| Slack | Internal team communication | Internal business communications |
| 1Password | Credential and secret management | Internal access credentials and secrets |
This list may evolve as Superhack grows. All changes will follow the notification process described above.