Subprocessors
NestLab uses subprocessors to operate our products and infrastructure. This page lists the entities that may process customer data on our behalf. Per the credential tier strategy (Rule 154), we use the most scoped credential available for each integration.
Edge & hosting
- Cloudflare, Inc. — CDN, edge compute, DNS, bot detection. EU edge. DPA in place.
_cfuvidcookie. - OVH SAS — VPS hosting for Dokploy-managed app runtimes (EU, by default Frankfurt or Strasbourg). DPA in place.
Identity & authentication
- Better Auth — self-hosted auth library. No third-party subprocessor beyond Cloudflare's edge.
- Supabase Auth (CheckCV only) — JWT-based auth. DPA in place.
Payments
- Polar.sh — Merchant of Record for all paid tiers. Stripe Connect under the hood for payouts. DPA in place. Polar acts as the data controller for payment data; we receive only the customer ID and subscription state.
- Brevo (Sendinblue) — transactional email (signup confirm, password reset, receipts). EU-hosted. DPA in place.
AI providers
- Anthropic (Claude) — LLM via Vercel AI SDK + OpenRouter. No fine-tuning; zero data retention flag enabled where available.
- OpenAI (GPT-4) — LLM via Vercel AI SDK + OpenRouter. No fine-tuning; zero data retention flag enabled where available.
- Google Gemini — LLM via Vercel AI SDK + OpenRouter. No fine-tuning.
- OpenRouter — multi-provider LLM gateway. EU routing where available. DPA in place.
Code & CI/CD
- GitHub, Inc. — source code, GitHub Actions, GHCR for container images. Standard Contractual Clauses apply.
- Cloudflare R2 — object storage for backups and static assets. EU jurisdiction option.
Observability
- Beszel — self-hosted server monitoring. No third-party.
- Uptime Kuma — self-hosted uptime monitoring. No third-party.
- restic + Koofr / Backblaze B2 — encrypted backups. Self-hosted client.
Email aliases
- Gmail (Google Workspace) — mail reception for admin@ / support@ / noreply@ / catch-all. Workspace DPA in place.
Adding a new subprocessor
Before adding a new subprocessor that processes customer data, we:
- evaluate the data they handle and the legal basis for transfer;
- enter a DPA with EU SCCs if the subprocessor is outside the EEA;
- add them to this page with a 30-day notice for substantial changes;
- update the per-product DPA.
Changelog
- 2026-07-31 — Initial publication.