Skip to main content

Sub-processor catalog

Authoritative list of every third-party processor that may receive customer data. Referenced from the Article 28 DPA template of Iru, the company that builds and operates Hyrax; the customer-facing DPA bundle cites this page for sub-processor disclosure.

Active processors

ProcessorData sharedDPA / basisNotes
AWSHosting substrate for all customer code, data, operational logs, transactional email, and AI model inferenceAWS DPA (account-wide)All inference runs on Amazon Bedrock managed by Hyrax. We record request metadata and token counts only — no prompt or completion content is written to our logs. Model-provider retention and training terms are governed by AWS's service terms.
GitHubOrg/repo connection metadata, install metadata, and webhook deliveries (push payloads include commit metadata + diffs visible to the GitHub App's installed repositories)GitHub DPAGitHub is used to connect your organization and repositories. Tokens are short-lived and repo-scoped, never stored long-term.
WorkOSLogin identity — email address, and (for social login) the provider account identifierWorkOS DPAAuthentication provider for customer sign-in (GitHub, Google, or email one-time code).
StripeCard-on-file, invoice records, and subscription / usage events for billingStripe DPA (via Iru's existing Stripe contract)A Stripe customer record is created lazily the first time your workspace touches a billing feature — subscribing to a paid plan, opening the billing portal, or enabling on-demand overage (or when Hyrax grants your workspace a trial) — never at sign-up.
PostHogProduct-usage and job-lifecycle events (workspace id, user id, job id, workflow, outcome). No customer code, no AI model content, no secrets.PostHog DPA (cloud)Session replay masks every input and all rendered text by default.
LinearObservation titles, descriptions, file paths, and severity labels — only when the customer configures the integrationLinear DPA (customer is controller of their Linear workspace)Disable the integration in workspace settings to stop emitting.
Loops.soAccount-owner contact details for lifecycle email — email address, display name, plan tier, workspace name, and last-active date. No source code, no AI model content, no secrets.Loops.so DPA (agreed 2026-06-25, https://loops.so/dpa)Lifecycle email. Rolling out in phases — currently only the account-created welcome email; later lifecycle events (audit summaries, plan-cap nudges) would add per-event properties such as repo names and finding counts, and each expansion is a reviewed change. When fully enabled, lifecycle email will be opt-out.
ResendContact details of consented recipients for outreach email — email address and (where captured at signup) name, as the recipient of the message. Recipients span the GTM feed's allowlisted contact lanes: workspace owners, signed-up prospects, and logged-in workspace members (D1 amendments #2/#3 — every lane rides the account-scoped consent basis; internal-domain addresses never cross). No source code, no AI model content, no secrets.Resend DPADelivery provider for Hyrax's outreach email (for example, onboarding follow-ups), sent from a dedicated sending domain (gtm.hyrax.dev) separate from the app's transactional email.

Advertising and analytics tags

The production web app also loads conversion tags from Google Ads and Reddit Ads. They send a page-visit beacon per session and a one-time sign-up conversion event, carrying cookies, device identifiers, and the address of the page that fired them (which can include your workspace and repository names in the URL) — no page content, source code, or AI model content. When a sign-up arrived through a Reddit ad click, our server additionally sends Reddit a single server-side copy of that same sign-up conversion carrying only the ad-click identifier Reddit itself appended to the landing URL (no email, IP address, or browser details), deduplicated against the browser event. These ad platforms receive that data as independent controllers under their own terms, not as Article 28 sub-processors, which is why they are disclosed here rather than in the table above.

Review cadence

This catalog is reviewed on every new outbound integration, quarterly by the Hyrax team, and on every DPA renewal.

Cross-references

  • Security — what data we keep, how it's protected, and how to delete it.