PricingDocs
LoginStart building
← All legal documents

Subprocessors

Version 2026-09-07 · Draft — not yet in effect

Draft — not yet in effect

This document is published for review and is not yet in force. It is excluded from search engines until it takes effect.

These are the vendors that process data on Volcano's behalf. Under the Data Processing Addendum, publishing a change to this page is how we give notice that the list has changed.

Microsoft, Apple, Vercel, GitHub source import and a customer-chosen SMTP provider only receive data when a customer configures them. They are listed here for completeness, not because every customer's data reaches them. Anthropic and OpenAI are listed ahead of the AI builder shipping; no data reaches either today.

Country Location(s) is pending. Counsel’s Subprocessor List leaves this column blank for every vendor; Volcano has not yet supplied the values, so this page does not invent them.

Last updated 2026-09-07
VendorPurposeCountry Location(s)Data sent
AWSS3 storage, Lambda execution, frontend delivery, build and orchestration, queues and cache, logs and metrics, SES emailPendingFunction and frontend source and build artifacts, environment variables, storage files, Lambda runtime data, logs, transactional email content, resource identifiers
NeonManaged customer PostgresPendingDatabase, project and role names; all customer database schemas, records, queries and connection credentials
PostHog (US)Product/web analytics, session replayPendingUser ID and email, product events, page/URL/UTM data, web vitals, exceptions, and the real client IP for geolocation
DatadogOperational logging, metrics and tracingPendingDeployment and resource identifiers, trace attributes, errors, CloudWatch log contents
StripeSubscriptions, hosted Checkout, invoices, webhook-driven billing statePendingEmail, Volcano user and account ID, payment-method IDs, price and plan, subscriptions, Checkout data, billing events
PlainCustomer support threadsPendingEmail (also used as display name), Volcano organization ID and name, thread metadata, full message text
GitHubVolcano login, repository connection, source import, Git-triggered deploys, and CLI/plugin distributionPendingOAuth codes, account identity, installation and repository metadata, tokens, source archives
GoogleFederated login for the Volcano dashboard and for customer end-user appsPendingOAuth codes, provider identity and profile
AnthropicAI builder — model providerPendingBuilder prompts, generated content and the project context a prompt refers to
Listed ahead of launch. The AI builder has not shipped, so no data reaches Anthropic today.
OpenAIAI builder — model providerPendingBuilder prompts, generated content and the project context a prompt refers to
Listed ahead of launch. The AI builder has not shipped, so no data reaches OpenAI today.
MicrosoftFederated authentication for a customer's own end usersPendingOAuth codes and provider identity
Only when a customer configures Microsoft as an auth provider in their own app.
AppleFederated authentication for a customer's own end usersPendingOAuth codes and provider identity
Only when a customer configures Apple as an auth provider in their own app.
VercelImporting an existing Vercel projectPendingOAuth token, account, project and configuration data
Only when a customer imports a project from Vercel.
Customer-selected SMTP providerTransactional email sent by a customer's own applicationPendingRecipient, sender, subject, body, and confirmation or reset links
Only when a customer configures their own SMTP provider. Volcano does not choose the vendor.
npm registry / GitHub ReleasesDistributionPendingInstall and upgrade traffic for the Volcano CLI and its plugins only, not account or project data
Have I Been Pwned (Superlative Enterprises Pty Ltd)Compromised-password screening during password creation and changesPendingThe first five characters of the password's SHA-1 hash, used for a padded k-anonymity range lookup; the password itself is not sent

Product

HomePricing

Features

Functions & AgentsNext.js FrontendsDatabases & VectorFile StorageAuthenticationRealtime

Resources

Getting startedDocumentation

Legal

Customer AgreementPrivacy PolicyCookie PolicySubprocessorsAll legal documents

Created by Kong to bring production readiness to the AI world