Draft. This document is under review by counsel and is not yet in force (version 2026-10-03.1).
Sub-processors
DRAFT for counsel review. Not legal advice.
Version: 2026-10-03.1
Annex to the DPA (dpa.md section 7). Part 1 lists sub-processors: they store or process customer case data or account data for us. Part 2 lists data sources: they receive query terms (a name, company number, email, domain or username) when a case runs, and answer from their own data. A source is used only when its connector is on for the case and, for keyed sources, when its key is set (uv run ot connectors list shows which are live).
Part 1. Sub-processors
| Provider | Service | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase Inc. | Auth, Postgres database, file storage | all account and case data, evidence files, reports | EU (eu-central-1, Frankfurt) | EU hosting; SCCs for support access |
| Vercel Inc. | Web app hosting and edge network | requests and responses in transit, request logs (IP, path) | EU (fra1, Frankfurt) for functions; global edge | DPF / SCCs |
| (none: operated by OSINTTotal) | Worker machines (collection, analysis, report rendering) run in Docker on computers OSINTTotal controls, each with its own revocable login | case data while a job runs, local copies of case files | where the operating staff are (list the countries before go-live) | operator controls; counsel to confirm transfer basis per location |
| Paddle.com Market Ltd | Merchant of record: checkout, payments, invoices, sales tax | billing name, email, address, payment details (held by Paddle, not by us) | UK / global | UK adequacy; SCCs |
| Resend (Plus Five Five Inc.) | Transactional email (sign-in links, org approved, report ready) | recipient email, message text (no case data beyond the case code) | US | DPF / SCCs |
| Anthropic PBC | LLM analysis of collected evidence and report drafting, when analysis is on for the job | excerpts of collected evidence, subject names and identifiers in prompts | US | DPF / SCCs; commercial API terms, inputs not used for training |
| Cloudflare Inc. | Turnstile bot check on signup and login | IP address, browser signals | global | DPF / SCCs |
SerpAPI LLC (if SERPAPI_KEYS is set) | web search results for dorks | search queries (names, identifiers) | US | SCCs |
Brave Software Inc. (if BRAVE_API_KEY is set) | web search, last resort route | search queries | US | SCCs |
Firecrawl (Mendable Inc.) (if FIRECRAWL_API_KEY is set) | fetch and render public pages | page URLs found for the subject | US | SCCs |
Self-hosted components (SearXNG, OCR server when OT_UNLIMITED_OCR_URL points at our own host) run on our infrastructure and are not sub-processors. Customer-supplied proxies (OT_PROXY_URLS) are the customer's choice and processor; the free proxy pool (OT_PROXYPOOL=1) routes queries through unknown third parties and must stay off in production.
Part 2. Data sources that receive query terms
Keyed (an account and API key with the provider; terms of each provider apply):
| Source | Key | Data sent | Licence note |
|---|---|---|---|
| OpenCorporates | OPENCORPORATES_API_TOKEN | company names and numbers, officer names | commercial use needs a paid licence |
| UK Companies House | COMPANIES_HOUSE_API_KEY | company names and numbers, officer names | open government licence |
| OpenSanctions | OPENSANCTIONS_API_KEY | person and company names | commercial use needs a licence |
| UK FCA register | FCA_API_KEY, FCA_API_EMAIL | firm and person names | |
| SAM.gov | SAM_API_KEY | company names | |
| US FEC | FEC_API_KEY | person names | |
| Portal da Transparencia (Brazil) | PORTAL_TRANSPARENCIA_KEY | names, CPF/CNPJ where supplied | |
| Arkham Intelligence | ARKHAM_API_KEY | wallet addresses | |
| Etherscan | ETHERSCAN_API_KEY | wallet addresses | |
| AbuseIPDB | ABUSEIPDB_API_KEY | IP addresses of subject-owned infrastructure | |
| abuse.ch | ABUSECH_AUTH_KEY | domains, IPs | |
| Have I Been Pwned | HIBP_API_KEY | email addresses | |
| OCCRP Aleph | OCCRP_ALEPH_API_KEY | person and company names | |
| US Senate LDA | LDA_API_KEY | person and company names | |
| World Bank debarment list | WORLDBANK_API_KEY | company names | |
| Europeana, Trove, Google Books, PatentsView | EUROPEANA_API_KEY, TROVE_API_KEY, GOOGLE_BOOKS_API_KEY, PATENTSVIEW_API_KEY | person and company names | |
| GitHub | GITHUB_TOKEN | usernames, emails |
Keyless public sources (no account; queries still leave our worker): official sanctions lists (OFAC, UN, EU, UK OFSI, Canada, Interpol notices), GLEIF, Wikidata, OpenAlex, SEC EDGAR, CourtListener, GDELT, Internet Archive Wayback Machine, crt.sh, WHOIS and DNS, Gravatar, Hudson Rock (email or username breach exposure lookup), public web search through SearXNG or DuckDuckGo, and the public pages those searches return.
The full catalog is workers/ot/ot/sources/catalog.yaml and workers/ot/ot/sources/api_templates/. Before a source is used for a paying customer, check its terms allow commercial use and automated access.
Changes
New sub-processors are announced 30 days ahead (dpa.md section 7). Data sources in part 2 are added or removed with the catalog and listed here at the next version.