Subprocessors and Data Residency
Status: v1.4 disclosure. Effective at general availability.
The v1.4 hosted service is designed for London-region processing and local-first analysis. Provider contracts, support access, routing, and model processing can create international transfers; contractual safeguards and provider data controls are used where applicable.
| Provider | Purpose | Expected region or transfer |
|---|---|---|
| Fly.io | Control plane, authenticated web application, and local-node coordination | London (lhr) |
| Neon | Postgres operational and derived evidence | London region |
| Cloudflare | DNS, encrypted backup objects, purge registry | Global edge; configured R2 account |
| Clerk | Authentication and account identity | Provider-managed regions |
| Stripe | Billing and payment records | Provider-managed global service |
| Anthropic and enabled model providers | Agent inference for user-requested sessions | The configured Aletheia Anthropic workspace uses the US data location; customer-selected provider accounts follow their selected provider regions and terms |
| Sentry | Opt-in, filtered error diagnostics | Configured Aletheia project uses Germany; provider terms govern support access and transfers |
| PostHog | Bounded product analytics when enabled | Configured Aletheia project uses PostHog EU |
| Grafana Cloud | Aggregate operational metrics and alerting, including readiness, backup freshness and spending counters | Configured Aletheia stack uses London (prod-gb-south-1) |
| GitHub | Signed release distribution and operational workflows | Provider-managed regions |
Raw customer binaries remain encrypted on the customer's device. Analysis decrypts them only into an owner-only ephemeral local session directory and bind-mounts them read-only into a signed, networkless Docker worker on that device. Raw binaries, recognizable binary fragments, local paths, and file names do not enter the Fly control plane, model prompts, logs, metrics, Neon, R2, or other subprocessors. Only bounded derived evidence permitted by the data-class policy may enter Postgres.
Model prompts and evidence sent during an agent session depend on the selected provider and customer action. Provider capabilities, retention, and zero-data-retention status are surfaced separately and should be evaluated before using sensitive material.
Material subprocessor changes will be published here. DPA and transfer requests may be sent to privacy@arbitersec.com.
Configuration facts checked: 2026-09-07. Legal approval remains a separate release checkpoint.