Subprocessors
The third-party services codingassist.bot relies on to deliver the Service — what each one does, and where it runs.
To run codingassist.bot we rely on a small set of trusted third parties ("subprocessors"). Each one is bound by a Data Processing Agreement that restricts how it may handle data on our behalf. This page is the authoritative list referenced by our Privacy Policy.
Current subprocessors
| Subprocessor | Purpose | Location | Policy |
|---|---|---|---|
| Stripe, Inc. | Payment processing (PCI-DSS Level 1). We receive only a tokenized reference, never full card data. | United States | stripe.com/privacy |
| Microsoft Azure | Hosting for the web application (app.codingassist.bot): compute, database, and CI/CD (Azure DevOps). | United States / EU regions | privacy.microsoft.com |
| Vercel Inc. | Hosting for the landing site and documentation (static site + CDN). | United States (primary); global edge | vercel.com/legal/privacy-policy |
| Cloudflare, Inc. | DNS, edge delivery, DDoS protection, WAF, and TLS termination. | Global edge network | cloudflare.com/privacypolicy |
| Voyage AI | Generates the embeddings used for semantic code retrieval. | United States | voyageai.com/privacy |
| Qdrant | Vector store holding the embeddings behind the CodeGraph index. | EU / United States | qdrant.tech/legal/privacy-policy |
| LLM provider | The reasoning engine that generates reviews. Our DPA forbids training on Customer Data. | Per provider | See note below |
About the LLM provider
The managed Platform AI mode routes review context to a large-language-model provider under a Data Processing Agreement that prohibits training on your Customer Data. If you prefer full control, use Bring your own model (BYOK) — your code is then reasoned over by a model and key you control, and the managed LLM subprocessor is not used for your tenant.
Questions
For DPA requests or questions about this list, contact legal@codingassist.bot. For the broader security overview, see the Security & Trust Center.