Subprocessor Disclosure (Institutional)¶
Last Updated: February 2026
OmniSentient uses a minimal set of subprocessors to provide our governance and remediation services. Each provider has been vetted for compliance with our internal security standards.
| Provider | Service Category | Data Scope | Residency |
|---|---|---|---|
| Supabase | Managed Database | Metadata, Audit Logs, Users | AWS (US-East-1) |
| Vercel | Application Edge | Frontend Assets, Edge Logic | Global CDN |
| Google Cloud | AI Infrastructure (Gemini) | Manifest Logs (Transient) | US-Central-1 |
| GitHub | Version Control Proxy | Metadata, Webhook Payloads | US-East-1 |
Data Handling Policy¶
- Non-Custodial: We do not store your source code.
- Transient Processing: Code analysis is performed in memory and discarded immediately after PR generation.
- Isolation: Every tenant is isolated via Row-Level Security (RLS) policies.
For a full vendor risk assessment, please contact our security team via the Architecture Review surface.