← All legal documents
Subprocessors
These are the vendors that process data on Volcano's behalf. Under the Data Processing Addendum, publishing a change to this page is how we give notice that the list has changed.
Microsoft, Apple, Vercel, GitHub source import and a customer-chosen SMTP provider only receive data when a customer configures them. They are listed here for completeness, not because every customer's data reaches them. Anthropic and OpenAI are listed ahead of the AI builder shipping; no data reaches either today.
Country Location(s) is pending. Counsel’s Subprocessor List leaves this column blank for every vendor; Volcano has not yet supplied the values, so this page does not invent them.
| Vendor | Purpose | Country Location(s) | Data sent |
|---|---|---|---|
| AWS | S3 storage, Lambda execution, frontend delivery, build and orchestration, queues and cache, logs and metrics, SES email | Pending | Function and frontend source and build artifacts, environment variables, storage files, Lambda runtime data, logs, transactional email content, resource identifiers |
| Neon | Managed customer Postgres | Pending | Database, project and role names; all customer database schemas, records, queries and connection credentials |
| PostHog (US) | Product/web analytics, session replay | Pending | User ID and email, product events, page/URL/UTM data, web vitals, exceptions, and the real client IP for geolocation |
| Datadog | Operational logging, metrics and tracing | Pending | Deployment and resource identifiers, trace attributes, errors, CloudWatch log contents |
| Stripe | Subscriptions, hosted Checkout, invoices, webhook-driven billing state | Pending | Email, Volcano user and account ID, payment-method IDs, price and plan, subscriptions, Checkout data, billing events |
| Plain | Customer support threads | Pending | Email (also used as display name), Volcano organization ID and name, thread metadata, full message text |
| GitHub | Volcano login, repository connection, source import, Git-triggered deploys, and CLI/plugin distribution | Pending | OAuth codes, account identity, installation and repository metadata, tokens, source archives |
| Federated login for the Volcano dashboard and for customer end-user apps | Pending | OAuth codes, provider identity and profile | |
| Anthropic | AI builder — model provider | Pending | Builder prompts, generated content and the project context a prompt refers to Listed ahead of launch. The AI builder has not shipped, so no data reaches Anthropic today. |
| OpenAI | AI builder — model provider | Pending | Builder prompts, generated content and the project context a prompt refers to Listed ahead of launch. The AI builder has not shipped, so no data reaches OpenAI today. |
| Microsoft | Federated authentication for a customer's own end users | Pending | OAuth codes and provider identity Only when a customer configures Microsoft as an auth provider in their own app. |
| Apple | Federated authentication for a customer's own end users | Pending | OAuth codes and provider identity Only when a customer configures Apple as an auth provider in their own app. |
| Vercel | Importing an existing Vercel project | Pending | OAuth token, account, project and configuration data Only when a customer imports a project from Vercel. |
| Customer-selected SMTP provider | Transactional email sent by a customer's own application | Pending | Recipient, sender, subject, body, and confirmation or reset links Only when a customer configures their own SMTP provider. Volcano does not choose the vendor. |
| npm registry / GitHub Releases | Distribution | Pending | Install and upgrade traffic for the Volcano CLI and its plugins only, not account or project data |
| Have I Been Pwned (Superlative Enterprises Pty Ltd) | Compromised-password screening during password creation and changes | Pending | The first five characters of the password's SHA-1 hash, used for a padded k-anonymity range lookup; the password itself is not sent |