Naitra Subprocessors
These are the third-party services that process customer data on Naitra's behalf to deliver the product. We review this list whenever our vendors change and update it here.
| Service | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic | AI processing of audit content. Customer data is not used to train models and is retained for no more than 30 days. | Evidence content extracted from uploaded files, control descriptions, and finding narratives. | United States |
| Amazon Web Services | Evidence file storage and encryption key management. | Audit evidence files and encrypted connector credentials. | US East (Ohio), us-east-2 |
| Supabase | Authentication and PostgreSQL database, plus a legacy read-only evidence path via Supabase Storage. New evidence writes go to AWS S3. | User credentials, engagement metadata, control matrices, findings, evidence metadata, and audit logs. | United States |
| Vercel | Frontend application hosting and content delivery. | No customer data processed server-side; static assets and client-side code only. | United States, global edge network |
| Railway | Backend API server hosting. | API requests transit Railway; application logs may contain request metadata. | United States |
Naitra gives at least 15 days advance notice to all customers by email to account administrators before adding or replacing a subprocessor.
Naitra