Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free
Trust Center

Subprocessors and third-party services

Last updated: August 31, 2026. Every third-party service the platform uses, what data flows to it, and how long that data is kept.

Core infrastructure

Where the platform runs and where your workspace data lives.

Supabase

Primary database (managed Postgres) and user authentication.

Data flow: Account profile (email, name, optional Telegram chat ID), canary identities, monitored email addresses, threat and tripwire events, subscription and billing records, privacy-request tokens, and authentication credentials.

Retention: Stored until account deletion. Threat events follow the account retention window (default 365 days).

Amazon Web Services (EC2, SES, S3, SNS)

Backend API hosting (EC2), alert and transactional email delivery (SES), inbound tripwire email receipt and storage (SES + S3), and delivery notifications (SNS).

Data flow: Outbound alert emails to your address; inbound email sent to tripwire canary addresses (attacker contact) is received via SES and stored in S3 for processing.

Retention: Email delivery is transient; inbound tripwire messages are processed into trigger events.

Vercel

Hosting and CDN for the web application.

Data flow: Standard web-request metadata (IP address, user agent) processed by the hosting layer.

Retention: Subject to the hosting provider's standard request-log handling.

Payments and AI inference

Billing runs through PayPal. Prompts and documents you submit for inspection are processed by an inference provider.

PayPal

Subscription billing for paid plans.

Data flow: Subscription identifiers, plan, and billing event data (amount, currency, status). Card details are entered on PayPal, never on CanaryVaults; full card numbers are not stored by CanaryVaults.

Retention: Billing records are kept until account deletion. Deleting your account also cancels any active PayPal subscription.

Groq

LLM inference for CanaryShield prompt inspection, CanaryRAG document and leak analysis, and CanaryAgent skill scanning.

Data flow: The prompts and document text you submit to those product surfaces are sent to the Groq API to produce the inspection or analysis result.

Retention: Used for inference; results are stored in your workspace, not by reference to the provider.

Threat intelligence

These services see attacker IP addresses captured by tripwires and honeypots — never your account data.

AbuseIPDB

IP reputation lookups on attacker IPs that hit tripwires and honeypots; optional automatic reporting of attacker IPs.

Data flow: Attacker IP addresses only. No account data.

Retention: Lookup results are cached for about 15 minutes.

IPInfo

Geolocation of attacker IP addresses for alert context.

Data flow: Attacker IP addresses only. No account data.

Retention: Lookup results are cached for about 15 minutes.

Shodan (InternetDB)

Exposure lookup on attacker IP addresses.

Data flow: Attacker IP addresses only. No account data, no API key required by this service.

Retention: Lookup results are cached for about 15 minutes.

VirusTotal

Reputation lookup on attacker IP addresses.

Data flow: Attacker IP addresses only. No account data.

Retention: Lookup results are cached for about 15 minutes.

Intelligence X

Breach monitoring for the email addresses you ask the platform to watch. Only active when configured for the deployment.

Data flow: The monitored email addresses you add are queried against breach data.

Retention: Findings are stored as breach events in your workspace.

Alert delivery and monitoring

Optional channels you enable, plus operational error monitoring.

Telegram

Optional alert delivery to a Telegram chat you link to your account.

Data flow: Your chat ID and the content of alerts you have routed to Telegram.

Retention: Messages persist in your Telegram chat under Telegram's terms. Unlink the chat in settings to stop delivery.

Sentry

Optional backend error monitoring. Only active when configured for the deployment.

Data flow: Error and stack-trace data, sent under four redaction settings applied at SDK initialisation. send_default_pii is disabled, so the SDK attaches no user id, IP address or cookies. include_local_variables is disabled, so captured stack frames carry no local variables — this is what keeps prompt and document text out of an error report. max_request_body_size is set to never, so request bodies are not captured at all. And a before_send hook redacts every email address anywhere in the outgoing event, keeping only addresses at the platform's own domain, which are needed to tell one email-delivery failure from another; if that redaction ever fails, the event is dropped rather than sent.

Retention: Subject to the configured Sentry project retention.

Public data flows that are not subprocessors

One product mechanism intentionally places data in a public location today, and one more would if it were enabled. Both are listed here because anything published this way cannot be recalled.

Base (public blockchain) — not currently enabled

On-chain proof anchoring is not enabled on this deployment. No content hash, transaction, or any other data has been written to Base or to any other public blockchain. The capability exists in the codebase but is inert. If it is ever switched on, it would write content hashes and transaction references to a public network where they are permanent and cannot be deleted; raw document content would still never be placed on-chain. This page is updated before anchoring is enabled, not after.

Canary seeding surfaces (Pastebin, GitHub Gists, similar paste services)

The canary seeding pipeline plants synthetic decoy identities in public locations so attacker pickup can be detected. Only fabricated decoy data is seeded. Real customer content is never posted to these surfaces.

Notes on this list

How to read the entries above.

  • This list reflects the codebase as of August 31, 2026 and is maintained alongside it. Material changes to this list are announced before they take effect.
  • Threat-intelligence services receive attacker IP addresses only; they never receive your account data, documents, or prompts.
  • Services marked optional are only active when the deployment operator has configured them.
  • Questions about any entry on this page can go to the security mailbox, which also handles privacy requests.

Related trust pages

Privacy policyCookie policySecurity centerAsk a question
CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS