Sub-processors
Who processes your data
The third parties we rely on to run Izri, what each of them processes, and how we tell you when the list changes.
Draft — pending legal review. This list is being finalized with counsel.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| OpenAI | LLM test-generation & analysis | Submitted source code & diffs | United States |
| OpenRouter | LLM routing for test-generation & analysis | Submitted source code & diffs | United States |
| Anthropic | LLM test-generation & analysis | Submitted source code & diffs | United States |
| Stripe | Billing & payments | Billing contact, plan, payment status (no card data stored by Izri) | United States / EU |
| GitHub | OAuth identity & repository access | Account identity, repository metadata | United States |
| Railway | Hosting & infrastructure | All service data at rest | United States |
Data-protection controls
On every request that carries your code, providers are instructed not to log prompts or train on your data. Zero Data Retention routing is available and can be enforced per organization in your settings (off by default). For the transfer mechanism backing each US-based provider, see our international-transfer register.
Change notification
Before we add or replace a sub-processor that processes your data, we will update this page and give advance notice so you have the opportunity to object. To receive notifications or raise an objection, contact {{PRIVACY_EMAIL}}.