Superagent Technologies, Inc.
Last updated: 8/31/2026
This page identifies third parties that Superagent Technologies, Inc. ("Superagent") may use to process Customer Data or service-related personal information when providing the Services.
Terms used but not defined here have the meanings in our Global Data Processing Addendum. A provider processes Customer Data only when the relevant feature is used. Providers identified as conditional are not involved in every customer's use of the Services.
Locations identify the provider's principal processing location or the locations generally available to Superagent. A provider may use additional locations and downstream subprocessors under its applicable terms. The selected deployment, customer configuration, and availability may affect the actual processing location.
Infrastructure and product operations
| Provider | Location | Processing or service performed | When used |
|---|---|---|---|
| Vercel, Inc. | United States and global edge locations | Application hosting, content delivery, serverless processing, logs, and attachment storage | Core Service |
| Supabase, Inc. | United States; selected hosting region | Authentication, database, object storage, account and organization data, product records, findings, reports, configurations, signatures, and integration metadata | Core Service |
| GitHub, Inc. | United States and provider-operated locations | Authentication; GitHub App and API integration; repository, pull-request, contributor, check-run, advisory, and proposed-fix processing | When Customer connects GitHub or requests a GitHub-based feature |
| PostHog, Inc. | United States or selected cloud region | Product analytics, feature usage, event data, and session replay for authenticated use | Analytics and Service improvement |
| Functional Software, Inc. (Sentry) | United States and provider-operated locations | Error monitoring, diagnostics, performance data, stack traces, and related request or user context | Error and performance monitoring |
| Railway Corporation | United States and provider-operated locations | Hosting for Superagent-operated inference gateway infrastructure, including request routing and service logs | When a sandbox workflow uses the Superagent inference gateway |
| Langfuse | United States, European Union, or selected provider region | AI observability, including prompt, response, tool, trace, run, session, and organization identifiers | When tracing is enabled for an applicable AI workflow |
| Resend, Inc. | United States and provider-operated locations | Transactional and service email delivery, including agreement and notification messages | When the Service sends email |
| Astrodon Corporation (Loops) | United States | Newsletter, lifecycle, and other email communications | When a person subscribes or is enrolled in an applicable communication |
AI inference
Superagent changes models as capabilities, safety, availability, and performance evolve. This list therefore identifies infrastructure and inference providers, not individual models.
| Provider | Location | Processing or service performed | When used |
|---|---|---|---|
| Microsoft Corporation (Microsoft Azure and Microsoft Foundry) | United States, European Union, or global, according to deployment | Cloud AI inference, content filtering, safety and abuse monitoring, and related service operations. Microsoft may retain content selected under its default abuse-monitoring process; Superagent does not represent this service as zero-data-retention. | When a workflow uses a Microsoft-hosted inference deployment |
| Fireworks AI, Inc. | United States or global, according to deployment | AI inference for open models made available through Microsoft Foundry. Request data is processed by Microsoft and Fireworks. Superagent uses stateless inference settings and does not enable optional prompt or generation logging. | When a workflow uses Fireworks on Microsoft Foundry |
| OpenRouter, Inc. | United States and locations of enabled inference providers | AI inference routing. Superagent restricts production routing to eligible endpoints with Zero Data Retention enforced and provider training, prompt publication, and OpenRouter data-use options disabled. | When a workflow uses OpenRouter |
OpenRouter and other routing services may engage downstream inference providers under their terms. Superagent configures eligible providers by data-handling capability and does not publish individual model names because routing changes over time. Plugins, external tools, or customer-configured destinations are separate services and are not covered by an inference provider's Zero Data Retention setting.
Security testing and context analysis
| Provider | Location | Processing or service performed | When used |
|---|---|---|---|
| Daytona Platforms, Inc. | United States and provider-operated cloud regions | Isolated compute environments used to inspect repositories and packages, conduct authorized tests, generate reports, and retain associated execution logs or artifacts | Repository, package, pull-request, or other sandbox-backed assessments |
| Kernel (OnKernel, Inc.) | United States and provider-operated locations | Isolated browser sessions, page rendering, screenshots, and page-content processing | Web-page and package-page analysis |
| Mendable, Inc. (Firecrawl) | United States and provider-operated locations | Web retrieval and extraction of URLs and page content requested by sandbox-based security workflows | When Firecrawl-assisted retrieval is enabled |
| Google LLC (Web Risk and Safe Browsing) | United States and global infrastructure | Malware and phishing reputation checks for URLs submitted to Context Guardrails | When a Google URL-reputation integration is enabled |
| PhishTank | United States and provider-operated locations | URL reputation lookup | Context Guardrails web analysis |
| RDAP service and applicable domain registries | Global | Domain-registration and ownership lookup using domain names submitted for analysis | Context Guardrails web identity analysis |
Billing, authentication, and agreements
| Provider | Location | Processing or service performed | When used |
|---|---|---|---|
| Stripe, Inc. | United States and provider-operated locations | Customer, subscription, invoice, payment, tax, and billing processing. Superagent does not receive complete payment-card details. | Paid plans |
| Dropbox, Inc. (Dropbox Sign) | United States and provider-operated locations | Agreement templates, signer identity, signature requests, signed documents, and status webhooks | When Customer enables Dropbox Sign for Agreements |
| Google LLC | United States and global infrastructure | Optional account authentication and basic profile data | When a user chooses Google sign-in |
| Microsoft Corporation | United States and global infrastructure | Optional account authentication and basic profile data | When a user chooses Microsoft sign-in |
| Cal.com, Inc. | United States and provider-operated locations | Scheduling, contact details, and meeting information | When a person books a call through an embedded scheduling interface |
Customer-directed services
Customer may configure webhook destinations, assessment targets, repositories, model endpoints, or other external services. Superagent sends data to those services only at Customer's direction. Customer is responsible for its relationship with and instructions to those recipients, which are not Superagent subprocessors merely because Customer connects them.
Changes to this list
Superagent may update this list as described in the Global Data Processing Addendum. When a new Subprocessor will process Personal Data under that DPA, Superagent will update this page and provide the notice required by the DPA.
Customers may object on reasonable data-protection grounds within 15 days after receiving notice by emailing privacy@superagent.sh.