Openwake's own subprocessors

The standard we hold vendors to, applied to ourselves: a dated list, 30 days' notice of additions by email to every organisation with a watchlist, and a right to object. Last updated: 2026-09-05.

SubprocessorPurposeDataLocation
Fly.iohosting the API and web applicationall customer data in transit and in memoryAmsterdam (ams)
Managed Postgres provider (Neon or Fly Postgres — stated here at go-live)the databaseall customer data at rest; alert channels sealed with AES-256-GCM before storageEU region
Resendtransactional email: alerts, digests, claim linksrecipient email address, alert content (vendor names, quotes, diffs)United States
Stripepayments and subscriptionsbilling contact, payment details (never stored by Openwake)United States
Slackalert delivery, only where you configure an incoming webhookalert contentper your workspace
GitHubsource code and the public ledger anchorsledger head hashes and signatures only; no customer dataUnited States

Not used: analytics or tracking providers; AI providers on customer data (the default extractor is deterministic and reads only vendors' public documents; a model, when enabled, never sees customer data).