toevan
ProduitFonctionnementPreuvesTarifsFAQ
Ouvrir ToevanRéserver un pilote

Legal

Sub-processors

v1.0.0Last updated: 2026-08-25Effective: [to be set]Draft

Draft, pending reviewThis document is not yet in force. Owner-blocked details and clauses pending legal review are highlighted inline.

On this page

On this page

  • Sub-processors we use
  • Planned sub-processors
  • Not sub-processors: self-hosted infrastructure
  • Not sub-processors: customer-directed integrations
  • Changes and subscribing
  • Changelog

A sub-processor is a third party Toevan engages to help process data on behalf of our customers under our Data Processing Agreement. This page lists them, what each one does, the categories of data it handles, where it is located, and its current status. We keep it current and give advance notice before adding or replacing one (see Changes and subscribing, below).

The distinction that matters most for a code-governance product is where your source code goes. The short answer: deterministic analysis never leaves our EU boundary, and the only things that can carry code-derived context to a third party are optional AI features (fix generation, the architecture assistant and chat, and, depending on configuration, code embeddings). The full statement is on the Security page and in the DPA data-flow schedule.

Providers that process Toevan's own controller data rather than customer code (the email, scheduling, and billing tools behind the marketing site and accounts) are not customer sub-processors; they are listed in the Privacy Policy instead.

Sub-processors we use

These are the third parties that process customer product data on our behalf today. Location is where the data sits; status is Live unless noted.

  • Hetzner (Helsinki, EU). Status: Live. Compute and hosting for the application, Postgres, Neo4j, and the append-only evidence store. Handles all product and customer data, including source code processed transiently.
  • Cloudflare (EU configuration). Status: Live. CDN, DNS, Pages, R2 object storage, and Tunnel. Handles site traffic metadata and stored objects, and sets no cookies. Cookieless web analytics on Cloudflare is planned; no analytics tool is enabled yet.
  • OpenRouter (United States, routing to Anthropic Claude models). Status: Live. Backs the optional AI features: fix generation, the architecture assistant and chat, blueprint assistance, and (in a fallback configuration) code embeddings. Today these paths carry code-derived context: the per-violation code context for a requested fix, retrieved symbol identifiers for the assistant and chat, and, in that fallback, embedded symbol text; none receives your whole repository. The default production configuration runs embeddings on an in-boundary EU model instead. The EU-only route for all code-carrying calls is being implemented (see Mistral, below, and the Security page).
  • Object storage (S3-compatible, operator-configured region). Status: Live. Stores project file bytes and evidence and report export ZIPs. Handles source file bytes and generated evidence and report exports.
  • OSV.dev and public package registries (pkg.go.dev, npm, pub.dev). Status: Live. Dependency vulnerability and license lookups. These receive a package name and version only; never your source code, and no personal data.

Planned sub-processors

Designed and being implemented, not yet carrying data. Listed here for transparency so the change is not a surprise.

  • Mistral (Devstral 2) (EU). Status: Planned, being implemented. The intended EU-resident route for code-carrying (sensitive) AI fix calls, under a zero-data-retention agreement (pending signature). Once live, sensitive calls route here only, with no US fallback, replacing the OpenRouter path for code-carrying requests.

Not sub-processors: self-hosted infrastructure

Some functions that vendors commonly outsource, we keep inside our own EU boundary rather than hand to a third party, so there is no sub-processor to list.

  • Error and performance monitoring. There is no external error-tracking vendor. A self-hosted collector (Bugsink or GlitchTip) on our own Hetzner EU infrastructure, with SDK-level scrubbing of source, personal data, and secrets before events are recorded, is being implemented.

Not sub-processors: customer-directed integrations

The following are connected by you, the customer, and governed by your own agreements with those providers. Toevan does not sub-process data to them; we act on your instructions to send data to a destination you chose and control.

  • GitHub (source of record, and the authentication and identity provider: you sign in with your own GitHub account), Slack, Jira, Linear, and Kosli. Data flows to these because you connected them; they are your sub-processors, not ours.
  • The Sigstore Rekor public transparency log (opt-in, off by default). When you enable anchoring, Rekor receives hash-only entries: the existence of an attestation, never your code or any personal data. It is a public log you choose to write to, not a Toevan sub-processor.

Changes and subscribing

Before we add or replace a sub-processor, we give advance notice and you may object, as set out in the DPA. Email is the notice channel.

To be notified of changes to this list, email [email protected] with the subject line Subscribe to sub-processor change notices. This is a working channel today. A dedicated self-serve subscription list at [OWNER: dedicated sub-processor-change list address, e.g. [email protected]] and an RSS feed of this changelog are planned as a convenience on top of the email channel.

The version, the Last updated date, and the full changelog below are the authoritative record of what changed and when.

Changelog

  • v1.0.02026-08-25

    Initial draft, scoped to the Article 28 customer-data chain: live product sub-processors (Hetzner, Cloudflare, OpenRouter, object storage, OSV.dev and package registries), the planned Mistral EU sensitive-AI route, self-hosted error monitoring being implemented (not a sub-processor), the customer-directed-integrations carve-out (GitHub as source and identity provider, Slack, Jira, Linear, Kosli, Rekor), and an email subscribe channel. The controller-data email, scheduling, and billing processors moved to the Privacy Policy, where Toevan is the controller.

On this page

  • Sub-processors we use
  • Planned sub-processors
  • Not sub-processors: self-hosted infrastructure
  • Not sub-processors: customer-directed integrations
  • Changes and subscribing
  • Changelog
toevan

Appliquez les règles. Prouvez-le à chaque commit.

Produit

  • Canvas d'architecture
  • PR Gate
  • Piste de preuves
  • Attestations signées
  • Intégrations
  • Marketplace de blueprints
  • Tarifs

Entreprise

  • Programme design partner
  • Contact

Légal

  • Confidentialité
  • Conditions
  • DPA
  • Sous-traitants
  • Sécurité

© 2026 Toevan. Conçu pour les équipes d'ingénierie en environnement réglementé.