Trust center

Subprocessors

This register identifies third parties that may process Customer Personal Data for Sintropyc, the limited purpose of that processing, and the relevant location. A provider receives only the minimum data required for its function.

Last updated: 9 August 2026  ·  Change notice: 30 days

No capability demos

Subprocessor access is limited to delivering or securing the Service. Customer Content, Target identifiers, Findings, and Reports are never shared with investors, prospective customers, advisors, or partners for marketing, demonstrations, case studies, or investor materials.

Current register

Vercel Inc.

Website infrastructure

Purpose & dataHosts the public website and serverless request endpoint. May process scan-request contact fields, submitted Target URL, IP address, request headers, and operational logs. It also stores the website visit log (see the Privacy Policy). It does not receive Findings or Reports through the website form.

LocationUnited States and global edge network
DPA & security

Telegram group companies

Request notification

Purpose & dataDelivers an internal notification when a visitor submits the public scan-request form. May process the submitted name, role, Target URL, and request status. Findings, Reports, credentials, and scan evidence are not sent through this channel.

LocationGlobal cloud infrastructure; group entities include BVI and Dubai
Privacy policy

OpenRouter, Inc.

Conditional · AI routing

Purpose & dataRoutes minimum necessary prompts to the model endpoint approved for an engagement. Cloud AI processing of Customer Personal Data is permitted only where the applicable Order Form authorises it. Prompt logging and provider training are disabled for Customer workloads.

LocationUnited States; optional EU in-region routing by agreement
Privacy & data controls

Approved model endpoint

Engagement-specific

Purpose & dataPerforms inference on the minimum security-testing context needed for the authorised Run. Before processing, the Order Form must name every approved model endpoint and region. Sintropyc will not route Customer Personal Data to an unnamed endpoint or permit training on it.

Current optionsAtlasCloud (US), Novita AI (US), or Xiaomi (China), via OpenRouter. Customer may require a specific provider, ZDR endpoint, EU routing, or no cloud-model processing.

Independent controllers

Some providers determine their own purposes for limited data and are not subprocessors for Customer Personal Data:

Changes, notice & objections

Sintropyc will email the Customer contact at least 30 days before a new subprocessor begins processing Customer Personal Data. During that period Customer may object on reasonable data-protection grounds under Section 7.2 of the DPA. Publishing a change on this page alone does not replace the required email notice.

To confirm the providers authorised for an engagement, subscribe a legal or privacy contact, or raise an objection, email support@sintropyc.com.

Change history

9 August 2026 — Version 1.0. Initial public register. Added named purposes, data categories, locations, 30-day email notice, and Customer objection rights.

← Back to Sintropyc