AIZA-HexTyx AI Red Team Security Platform
Effective Date: July 28, 2026 · Last Updated: July 28, 2026
This page lists the third-party sub-processors that AIZA-HexTyx engages to process personal data or Customer data in connection with providing the Services. This list is maintained in accordance with our Data Processing Agreement (DPA) and applicable data protection law including the GDPR.
We will provide at least 10 days' prior written notice via email to registered account holders before adding any new sub-processor that processes personal data. Customers with a signed DPA have the right to object to new sub-processors during this notice period by contacting dpo@aiza.ai.
| Sub-processor | Legal Entity | Location | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|---|---|
| Railway | Railway Corp. | United States | Backend application hosting, compute, Redis cache | Encrypted application data, scan metadata (no plaintext PII) | railway.app/legal/privacy |
| Vercel | Vercel Inc. | United States | Frontend and static site hosting (landing pages, SEO content) | Anonymous page visit logs, CDN edge data | vercel.com/legal/privacy-policy |
| Sub-processor | Legal Entity | Location | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|---|---|
| Supabase (Vault A) | Supabase Inc. | United States (EU residency available) | Identity database — accounts, authentication, billing, add-on records | Encrypted name, encrypted email, encrypted Stripe customer ID, plan data | supabase.com/privacy |
| Supabase (Vault B) | Supabase Inc. | United States (EU residency available) | Scan data database — security findings, scan results, audit logs | Encrypted target URLs, encrypted findings, HMAC-pseudonymised scan owner hashes. Zero plaintext PII. | supabase.com/privacy |
| Sub-processor | Legal Entity | Location | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|---|---|
| Stripe | Stripe, Inc. | United States (EU Stripe entity available) | Payment processing, subscription management, billing portal | Name, email, billing address, payment card data (PCI DSS compliant — AIZA never stores raw card numbers) | stripe.com/privacy |
AI model providers process scan prompts and AI system descriptions to generate security findings. They do not receive Customer account information or billing data. All inputs are anonymised at the API layer before transmission.
| Sub-processor | Legal Entity | Location | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|---|---|
| Anthropic | Anthropic, PBC | United States | Primary AI inference engine — security analysis, finding generation, PoE confirmation (Claude models) | Anonymised scan prompts, AI system descriptions. No account identifiers transmitted. | anthropic.com/privacy |
| Google (Gemini) | Google LLC | United States (global infrastructure) | Fallback AI inference — activated only when primary Anthropic API is unavailable (circuit breaker failover) | Anonymised scan prompts only, transmitted during failover events. No account identifiers. | policies.google.com/privacy |
| Sub-processor | Legal Entity | Location | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|---|---|
| Google Analytics | Google LLC | United States (global) | Website traffic analytics (public marketing pages only) | Anonymised page views, session data. Only active with cookie consent. Not used in authenticated app. | policies.google.com/privacy |
AIZA will notify registered users by email at least 10 days before adding a new sub-processor that processes personal data. The notification will include the sub-processor's name, location, purpose, and data shared. The effective date of the change will be included in the notice.
To receive sub-processor notifications, ensure your account email is current. To object to a new sub-processor under a signed DPA, contact dpo@aiza.ai within the notice period.