LAST UPDATED 27 AUGUST 2026
To provide ShipGuarde, we engage a small set of third-party sub-processors. Each is bound by contractual data-protection obligations and receives only the data necessary for its function. We keep this list current; for advance notice of changes, contact [email protected].
| Sub-processor | Purpose | Primary region |
|---|---|---|
| Clerk | Authentication and user identity | United States |
| Cloudflare | DNS, TLS termination, CDN, and privacy-preserving web analytics | Global edge network |
| OpenRouter | LLM inference routing for analysis | United States |
| Railway | Application hosting, compute, and managed database | United States |
| Resend | Transactional and notification email | United States |
| Dodo Payments | Billing and payment processing | United States |
Code review sends the diff of changed files to our LLM sub-processor for analysis; visual checks send screenshots of the preview URL you provide. Every request carries an explicit zero-data-retention instruction, so inference is routed only to providers that neither store your content nor train on it. The model that locates elements on screen is published as open weights by ByteDance but is served entirely by a United States provider; no data is sent to ByteDance. If you have specific data-residency or retention requirements, contact us before onboarding.
We may add or replace sub-processors as the service evolves. Material changes are reflected here with an updated date. See our Privacy Policy and Security pages for how we handle your data.
Code review checks the diff. ShipGuarde also checks the running product, so a release does not ship on the hope that nothing broke.
NO CREDIT CARD · CONNECT GITHUB IN UNDER FIVE MINUTES · CANCEL ANY TIME
RELEASE CLEARANCE BUREAU
ISSUING AUTHORITY FOR SOFTWARE RELEASES
[email protected]