Subprocessors
The canonical, dated list of every third party that processes data on audytx's behalf — generated from the deployed configuration, not a compliance questionnaire. Governing terms: our Data Processing Addendum.
Current subprocessors
Each row is verified against the deployed configuration — Cloudflare bindings in
wrangler.toml and the GitHub call surface — not a vendor questionnaire.
| Subprocessor | What it does for audytx | Location | Terms |
|---|---|---|---|
| Cloudflare, Inc. | Edge compute (Workers) serving every request, the D1 scan-metadata store, Queues carrying usage-counter and outbound-email jobs, and Email Sending for transactional mail from audytx.com | Global edge network; scan metadata stored in the US region | Cloudflare DPA |
| GitHub, Inc. | Source of the scanned files (Contents API) and destination of the results: pull-request comments, check runs, and Code Scanning (SARIF) uploads | GitHub-managed infrastructure | GitHub DPA |
That is the complete list. No analytics vendor, no email-marketing platform, no error-tracking SaaS — the same two rows appear on the trust page.
Changes to this list
We publish a dated entry below at least 30 days before any new subprocessor begins processing. If you object, your remedy is to stop using the service before the change takes effect — removing the GitHub App immediately and permanently revokes audytx's access (see the DPA, section 7).
- 2026-07-13 — Initial published list: Cloudflare, GitHub.
Start free during the open beta
Install on GitHub and get your next pull request reviewed. Two subprocessors, a click-through DPA, and your source code parsed in memory and discarded.