Third parties that process data on DataTap's behalf, by data class (see the classification summary on /security). Planned entries are listed before they go live so the DPA and this page never disagree. Changes are announced on the changelog 30 days ahead.
| Provider | Role | Data | Region | Status |
|---|---|---|---|---|
| Fly.io | Application hosting and managed Postgres | C1 internal, C2 tenant-confidential, C3 regulated records (at rest and in transit) | United States (ord) | active |
| Tigris (via Fly.io) | Object storage for encrypted off-box backups, tenant exports and report delivery | C2/C3 as encrypted archives | United States | active when provisioned per tenant |
| GitHub | Source control and issue tracking | C0 code and public docs only — no tenant data | United States | active |
| Google Fonts | Web fonts on the public pages | Visitor IP address on font fetch (C0 pages only) | Global CDN | active |
| SMTP provider | Notification and contact-form email | User email addresses and notification titles | TBD | planned — ships dark until the owner provisions it |
| ClickHouse Cloud | Analytics store for the event archive at scale (ADR-004 trigger 2) | C2 events, mirrored | TBD | planned — shadow run first |
No advertising, analytics or session-replay vendors. Error capture, rate limiting, the job queue and the object-store client are in-repo. Questions: the contact form on the home page, marked "security".