GGateTest

Sub-processors

Effective date: September 10, 2026

Every third party that processes customer data on GateTest's behalf, what each receives, where it is, and the terms that bind it. Providers that only run when you switch a feature on are listed separately.

1. About This List

A sub-processor is a company we engage to process personal data on our behalf in order to deliver the service — a database host, a payment processor, an AI provider. Each one is bound by a written data-processing agreement, receives only the data its function needs, and is listed here.

This page is the authoritative list for the purposes of our Data Processing Addendum and Privacy Policy, and it is the mechanism by which we give notice of changes. It is generated from the same record the application uses, so it cannot describe a provider we have quietly stopped using or omit one we have added.

Your git host, when it acts as your git host, is not our sub-processor: it processes your repositories on your instructions under your agreement with it. It appears below because we also read from and write to it on your behalf.

2. Core Sub-processors

Used for every customer as part of running the service.

ProviderEntityPurposeData sharedLocationTerms
AnthropicAnthropic, PBCAI analysis and auto-fix generationFile contents, file paths and finding text for files being reviewed or fixed; prompts. Standard 30-day API retention; not used for model training under Anthropic's commercial terms.United StatesTerms
StripeStripe, Inc.Payments, subscriptions, billing portalE-mail, payment card details (entered on Stripe-hosted pages, never on ours), tier, repository URL, module names and issue counts attached to the payment record.United StatesDPA
NeonNeon, Inc.Managed PostgreSQL databaseAccount e-mail and git-host login, repository URLs, scan findings (messages, file paths, line numbers), payment identifiers, API keys, audit log.United StatesDPA
VultrThe Constant Company, LLCProduction serversEverything processed by the application, including repository contents held on disk for the duration of a scan.United StatesDPA
CloudflareCloudflare, Inc.Domain registration and DNSDNS queries for our domain. Traffic is not proxied through Cloudflare.United StatesDPA
GitHubGitHub, Inc.Git host, sign-in, GitHub AppSign-in identity (login, e-mail), repository contents read for scanning, commit statuses, pull-request comments and auto-fix branches written back.United StatesDPA
SentryFunctional Software, Inc.Error monitoring and session replayError reports with request URL, headers and IP address; sampled browser session replays (10% of sessions, 100% of sessions with an error). Request bodies, source code, prompts, keys and cookies are scrubbed before sending.United StatesDPA

3. Important Sub-processors

Used when the feature is in your plan or connected — for example, when you connect a repository on an alternative git host, when we send you e-mail, or when you run a live-URL scan.

ProviderEntityPurposeData sharedLocationTerms
GluecronGluecronAlternative git hostPush events, repository contents read for scanning, scan results written back. Only when you connect a Gluecron repository.New Zealand / United StatesTerms
ResendResend, Inc.Transactional e-mailRecipient e-mail address and message content (receipts, API keys, scan digests).United StatesDPA
VapronVapronLive-URL scanning dispatchTarget URL, scan id and suite for website / WordPress URL scans only. Never repository contents.United StatesTerms

4. Optional Sub-processors

Only when you turn the feature on. Nothing is sent to these providers by default.

ProviderEntityPurposeData sharedLocationTerms
OpenAIOpenAI, L.L.C.Optional second-opinion consensus on Forensic-tier fixesFile contents and finding text for the files being fixed. Only when you opt in to consensus on a Forensic scan.United StatesDPA
SlackSlack Technologies, LLCScan notifications to a webhook you supplyScan summaries (repository, verdict, counts).United StatesDPA

5. Changes and Objections

  • Before, not after. We update this page before a new sub-processor receives any customer data, and we update the effective date at the top when we do.
  • Notification. E-mail hello@gatetest.ai with the subject "Sub-processor notifications" and we will e-mail you whenever this list changes.
  • Objection. If you have a reasonable data-protection ground to object to a new sub-processor, tell us within 30 days of the notice; the DPA sets out what happens next, including your right to terminate the affected service if we cannot resolve the objection.
  • Replacement. A sub-processor that is replaced or removed is deleted from this page; we do not keep former providers listed.

6. Contact

Questions about any provider on this list, or a request for a copy of the transfer terms we rely on: GateTest, hello@gatetest.ai.