Trust

Sub-processors

Serge relies on a small set of vetted third parties to deliver the product. This page lists every sub-processor that touches customer data, where it sits, the legal mechanism for any cross-border transfer, and a link to that provider's Data Processing Agreement. Customers under our DPA receive 30 days' notice before any sub-processor is added or replaced.

Last updated

ProviderPurposeRegionTransfer mechanismCertificationsDPA
VercelApplication hosting, edge runtime, CDN, and Blob storage for replay screenshots.EU (Frankfurt) + US control planeEU residencySOC 2 Type II · ISO 27001View DPA →
NeonPrimary Postgres database — workspace data, scans, snippet events, replay metadata.EU-Central (Frankfurt)EU residencySOC 2 Type IIView DPA →
Auth0 (Okta)Authentication, session management, and identity provisioning.EU (Frankfurt)EU residencySOC 2 Type II · ISO 27001 · ISO 27018View DPA →
AnthropicClaude API for the active replay (Investigate Mode) — runs the agent against the customer's site.US (EU residency requires Enterprise / Bedrock)SCCsSOC 2 Type IIView DPA →
BrowserbaseManaged headless Chrome instance for replay sessions.EU (eu-central-1 Frankfurt)EU residencySOC 2 Type IIView DPA →
Fly.ioReplay worker compute — runs the agent loop and streams steps to the dashboard.EU (Frankfurt)EU residencySOC 2 Type IIView DPA →
StripePayments, subscriptions, and tax / billing record-keeping.US (control plane) + EU (data)DPFPCI-DSS Level 1 · SOC 1 · SOC 2 Type II · ISO 27001View DPA →
UpstashRedis for rate limiting, ephemeral state, and short-lived attribution storage.EU (eu-west / Ireland)EU residencySOC 2 Type IIView DPA →
SentryError tracking and performance monitoring (PII scrubbed in beforeSend).EU (Frankfurt)EU residencySOC 2 Type II · ISO 27001View DPA →
PostHogProduct analytics and session replay on serge.ai (input fields masked).US (EU migration planned)SCCsSOC 2 Type II · ISO 27001View DPA →
ResendTransactional email delivery — verification, billing receipts, replay-ready notifications.EUEU residencySOC 2 Type IIView DPA →
Change notice

Customers receive at least 30 days' notice before any sub-processor is added or replaced, with the right to object on reasonable data-protection grounds. Subscribe via privacy@serge.ai to receive change notices by email.

Questions

Reach the privacy team at privacy@serge.ai. We respond within five business days.