Trust & Security
Subprocessors
The third-party providers used to operate Oconee Runtime, what each one receives, and where they operate.
Current subprocessors
Each provider receives only what it needs to perform its function.
| Provider | Purpose | Data category | Location | Documentation |
|---|---|---|---|---|
| Render | Application hosting, managed PostgreSQL, managed Redis | Account data, product and security event data, operational metadata | United States (Oregon) | Render security |
| Vercel | Hosting for the web application and marketing site | Request metadata; no product event data is stored here | United States (Washington, D.C. region) | Vercel security |
| Cloudflare | Object storage (R2) for exports, backups and system artifacts | Exported and archived event data, backup artifacts | Configured per bucket | Cloudflare security |
| Stripe | Subscription billing and payment processing | Billing contact and subscription data. Card details go to Stripe directly and are not stored by Oconee | United States | Stripe security |
| Twilio SendGrid | Transactional email (verification, alerts, notifications) | Recipient email address and message contents | United States | Twilio SendGrid security |
| Sentry | Application error and performance monitoring | Error diagnostics and stack traces. Configured not to send personal data by default, with payload redaction applied before transmission | United States | Sentry security |
| Optional Google sign-in for user authentication | Email address and basic profile, only for users who choose Google sign-in | United States | Google security | |
| Google Analytics | Marketing website analytics | Pseudonymous website usage data with IP anonymization enabled. Not used on the authenticated product | United States | Google Analytics security |
Notes on this list
Integrations that a customer configures to their own systems — an identity provider for single sign-on, a Slack workspace or mail server for notifications, or a SIEM receiving exported events — are not listed here. Those are connections you choose and control, not providers Oconee engages on your behalf.
Oconee may update subprocessors as the service evolves.
Last updated: September 7, 2026