Company · SubprocessorsBrowse
CompanyLegalSubprocessors
Subprocessors
The outside services that receive your data when you use sbomtriage, what each one sees, and when. This list is written from the code that sends the data. If a service is added, it’ll appear here first.
| Service | Role | What it sees | When | Where |
|---|---|---|---|---|
| Vercel | Hosting and running the application | Every request, including your IP address, the paths you open (report addresses included) and the files you upload while they are being analysed. | Always. | Functions in the Dublin region. Pages and static files through Vercel’s global network. |
| Supabase | Database and sign-in | Reports, project inventories and history, your email address, your profile answers and your sign-in identities. | Always. | An EU region. |
| GitHub | Sign-in, and reading repositories you connect | Your GitHub identity when you sign in with it. The repositories you grant the App access to, from which it downloads only recognised dependency files. | Only if you sign in with GitHub or connect a repository. | United States. |
| Sign-in | Your email address and basic profile. | Only if you sign in with Google. | United States. | |
| Resend | Sending monitoring alerts by email | Your email address and the text of the alert, which names packages and findings in your projects. | Only if you turn email alerts on. | Per Resend’s own terms. |
Why the vulnerability data sources aren’t listed
The analysis asks public data sources about what’s in your file. None of them receives anything that identifies you or your organisation. The requests come from our server, not your browser, so they don’t see your IP address either.
- OSV.dev
- Receives package names and versions, as package URLs, to answer which published advisories affect them. Not the file, its name, the document name, or who uploaded it.
- Debian archive
- For Debian packages only, receives a package name to say which source package it was built from (Debian files advisories under source names). Answers are cached for a day.
- FIRST EPSS
- Receives the public CVE identifiers found in a scan, to return their exploit prediction scores. Scores are cached for a day, so a repeat request often isn’t sent at all.
- CISA KEV
- Receives nothing about your scan. The whole catalogue is downloaded about once a day and checked locally.
A set of package versions can still say something about the software it came from. That’s why only the coordinates are sent, with nothing that ties them to you.
Not used at all
No analytics, advertising, error-tracking or session-recording service is loaded on any page or called from the server. Fonts and icons are served from this site.
See also privacy, data processing terms and security.