Third parties
Technical subprocessors
This is the intended private-beta provider boundary. The customer-specific service agreement must name the actual configured providers, regions, runner host, and transfer safeguards before a portal is connected.
Last updated 18 July 2026 · Private beta
Provider inventory
| Provider | Purpose | Location / transfer |
|---|---|---|
| Supabase | Database and authentication | Configured project region documented in the service agreement |
| Vercel | Application and API compute | Configured deployment region documented in the service agreement |
| Inngest | Background orchestration | Configured EU environment |
| Scaleway | Independent encrypted dumps | Configured EU region |
| Sentry | Scrubbed error monitoring | Configured EU region |
| PostHog | Aggregate pageviews | Configured EU Cloud project |
| Resend | Operational email | Ireland dispatch; metadata may be stored in the US |
| GitHub | Source, Actions control plane, and environment-secret delivery | Global control plane / potential US transfer; customer dumps use separate ephemeral EU compute |
Payload limits
CRM property values are not intentionally sent to notification email, analytics, or GitHub-hosted compute. Sentry and analytics are scrubbed and limited as described in the signed security schedule. GitHub and the dedicated backup runner still form a credential/live-database trust boundary; workflow and environment changes require controlled review.
Changes
Private-beta subprocessor changes are communicated under the signed service agreement. Questions or objections can be sent to hello@restor.to.