Sub-processors
Sovrnti sells sovereignty, so we publish who we depend on. This is the full list of third parties that process customer data on our behalf.
Where your data lives
| Sub-processor | Purpose | Region | Data reaching it |
|---|---|---|---|
| Scaleway | Application containers, PostgreSQL, Redis | France | All application data |
| Neo4j Aura | The sovereignty graph | European Union | Graph content, no customer PII |
| PostHog | Product analytics, session replay, support inbox | European Union (Frankfurt) | Usage events, support ticket content |
| Lettermint | Transactional email | European Union | Recipient address, message body |
| Stripe | Payments | United States, EU data residency | Billing identity, payment metadata |
| Bunny | Edge WAF and CDN | European Union | Request metadata |
The one we want you to notice
PostHog delivers our replies to support email through a mail transport that is not EU-owned. Ticket content is stored on PostHog's EU instance. The transport carries the reply out.
We chose this deliberately rather than avoiding it. Our own framing calls that a Climber trade-off: approximate the benefit, keep control, state the price. The alternative was two disconnected inboxes and a slower answer to you.
If this matters for your risk assessment, write to us and we will tell you exactly what a given ticket carried.
What never reaches a sub-processor
| Data | Why |
|---|---|
| Security vulnerability reports | They go to a human mailbox only, never to the helpdesk |
| Your Sherpa conversation text in session replay | All text is masked before recording |
| Session replay of the authenticated application | Recording is disabled there |
Changes
We update this page before a new sub-processor starts processing data, not after. Adding one is a decision our founder takes, not an implementation detail.