Legal
Sub-processors
Last updated August 22, 2026
PermitUSB uses a small number of infrastructure vendors to run the service. Each processes customer data only as needed for the purpose listed here, under contractual terms consistent with our privacy policy. All are US-based. We update this page when the list changes.
The list
| Vendor | Purpose | Data handled |
|---|---|---|
| Supabase | Database and authentication | All application data (events, endpoints, policies, audit logs) and admin sign-in identities, including password hashes and sign-in history. US region. |
| Stripe | Payments and subscription billing | Company name, billing contact, billing address and payment instrument. Card data never touches PermitUSB servers. |
| Vercel | Web app and API hosting | All request and response traffic transits Vercel infrastructure. Standard request logs. US region. |
| DigitalOcean | Force check-in relay hosting (nudge.permitusb.com) | Endpoint and tenant identifiers, both opaque UUIDs, carried in the agent access token, plus the agent’s source IP and connection metadata in the relay’s runtime logs. No device events, no policy content and no account identities: the relay stores nothing and the nudge itself carries only a timestamp. US region. |
| Resend | Transactional email | Recipient email address plus the subject and body of alert, billing and account emails. |
| Cloudflare | DNS and TLS | Connection metadata only: DNS queries and TLS handshake data. No payload access. |
| Sentry | Application error monitoring | Error reports tagged with internal user ID and tenant ID only, and browser security-policy violation reports, which carry the page address and the address of the blocked resource. Both are relayed through our own servers rather than sent from the browser, so no visitor IP address reaches Sentry. Configured to exclude IP addresses, headers and cookies, with session replay disabled. |
What is not a sub-processor
Destinations you configure yourself are not sub-processors: outbound webhooks to Slack, Teams, PagerDuty, a SIEM and similar; the on-premises SIEM relay; and CSV or JSON exports. They receive data at your direction and under your own agreements with those services.



