← Back to Platform

Sub-processor List

AIZA-HexTyx AI Red Team Security Platform
Effective Date: July 28, 2026  ·  Last Updated: July 28, 2026

This page lists the third-party sub-processors that AIZA-HexTyx engages to process personal data or Customer data in connection with providing the Services. This list is maintained in accordance with our Data Processing Agreement (DPA) and applicable data protection law including the GDPR.

We will provide at least 10 days' prior written notice via email to registered account holders before adding any new sub-processor that processes personal data. Customers with a signed DPA have the right to object to new sub-processors during this notice period by contacting dpo@aiza.ai.

1. Infrastructure and Hosting


Sub-processor Legal Entity Location Purpose Data Shared Privacy Policy
Railway Railway Corp. United States Backend application hosting, compute, Redis cache Encrypted application data, scan metadata (no plaintext PII) railway.app/legal/privacy
Vercel Vercel Inc. United States Frontend and static site hosting (landing pages, SEO content) Anonymous page visit logs, CDN edge data vercel.com/legal/privacy-policy

2. Database and Authentication


Sub-processor Legal Entity Location Purpose Data Shared Privacy Policy
Supabase (Vault A) Supabase Inc. United States (EU residency available) Identity database — accounts, authentication, billing, add-on records Encrypted name, encrypted email, encrypted Stripe customer ID, plan data supabase.com/privacy
Supabase (Vault B) Supabase Inc. United States (EU residency available) Scan data database — security findings, scan results, audit logs Encrypted target URLs, encrypted findings, HMAC-pseudonymised scan owner hashes. Zero plaintext PII. supabase.com/privacy

3. Payment Processing


Sub-processor Legal Entity Location Purpose Data Shared Privacy Policy
Stripe Stripe, Inc. United States (EU Stripe entity available) Payment processing, subscription management, billing portal Name, email, billing address, payment card data (PCI DSS compliant — AIZA never stores raw card numbers) stripe.com/privacy

4. AI Model Providers

AI model providers process scan prompts and AI system descriptions to generate security findings. They do not receive Customer account information or billing data. All inputs are anonymised at the API layer before transmission.


Sub-processor Legal Entity Location Purpose Data Shared Privacy Policy
Anthropic Anthropic, PBC United States Primary AI inference engine — security analysis, finding generation, PoE confirmation (Claude models) Anonymised scan prompts, AI system descriptions. No account identifiers transmitted. anthropic.com/privacy
Google (Gemini) Google LLC United States (global infrastructure) Fallback AI inference — activated only when primary Anthropic API is unavailable (circuit breaker failover) Anonymised scan prompts only, transmitted during failover events. No account identifiers. policies.google.com/privacy

5. Analytics and Monitoring


Sub-processor Legal Entity Location Purpose Data Shared Privacy Policy
Google Analytics Google LLC United States (global) Website traffic analytics (public marketing pages only) Anonymised page views, session data. Only active with cookie consent. Not used in authenticated app. policies.google.com/privacy

6. Changes to This List

AIZA will notify registered users by email at least 10 days before adding a new sub-processor that processes personal data. The notification will include the sub-processor's name, location, purpose, and data shared. The effective date of the change will be included in the notice.

To receive sub-processor notifications, ensure your account email is current. To object to a new sub-processor under a signed DPA, contact dpo@aiza.ai within the notice period.

7. Contact

Trust Center Privacy Terms Acceptable Use