Sub-processors

Who processes your data

The third parties we rely on to run Izri, what each of them processes, and how we tell you when the list changes.

Draft — pending legal review. This list is being finalized with counsel.
Sub-processorPurposeData processedLocation
OpenAILLM test-generation & analysisSubmitted source code & diffsUnited States
OpenRouterLLM routing for test-generation & analysisSubmitted source code & diffsUnited States
AnthropicLLM test-generation & analysisSubmitted source code & diffsUnited States
StripeBilling & paymentsBilling contact, plan, payment status (no card data stored by Izri)United States / EU
GitHubOAuth identity & repository accessAccount identity, repository metadataUnited States
RailwayHosting & infrastructureAll service data at restUnited States

Data-protection controls

On every request that carries your code, providers are instructed not to log prompts or train on your data. Zero Data Retention routing is available and can be enforced per organization in your settings (off by default). For the transfer mechanism backing each US-based provider, see our international-transfer register.

Change notification

Before we add or replace a sub-processor that processes your data, we will update this page and give advance notice so you have the opportunity to object. To receive notifications or raise an objection, contact {{PRIVACY_EMAIL}}.