Subprocessor List
Breachday LLC · breachday.io
Version 1.4 · Effective Date: October 5, 2026
Breachday LLC uses third-party service providers ("subprocessors") to host, operate, secure, and support the Breachday platform. This list describes providers that may Process Personal Data or Customer Data on Breachday's behalf in connection with the Service.
This list applies to app.breachday.io, authenticated organization users, Exercise Participants, and transient public /build export processing. Some providers may also process account, billing, or security information under their own legal roles and privacy terms.
Data location: Breachday configures its primary application database, application deployment, and designated disaster-recovery storage for U.S. regions where supported. Some subprocessors operate distributed or global infrastructure, and transient network, security, support, payment, or AI inference processing may occur in other locations depending on the provider endpoint and service configuration. Breachday does not represent that all transient processing occurs exclusively in the United States.
MSP-managed organizations: Where an MSP or consultant uses Breachday for a Client under an MSP agreement, Breachday generally acts as the MSP's subprocessor and the providers below may act as further subprocessors for Client Personal Data. MSPs are responsible for providing Clients required notices and authorizations.
Material Changes Notice
Breachday will provide at least 30 days' advance notice before a new Subprocessor begins Processing Customer Personal Data, ordinarily through in-Service notice and/or email to registered Account contacts. If an emergency replacement or new provider is reasonably necessary to maintain security, legal compliance, or Service continuity and 30 days' advance notice is not practicable, Breachday will provide notice as soon as reasonably practicable. Objection rights are governed by the DPA.
Subprocessors
| Subprocessor | Role | Data Processed | Processing Location |
|---|---|---|---|
| Supabase | PostgreSQL database, authentication, realtime messaging, object storage | Application Customer Data; hashed authentication credentials managed by Supabase Auth; organization logos and playbook files; real-time session events and presence | United States project region as configured by Breachday; provider infrastructure may include supporting global services |
| Vercel | Application hosting and serverless compute | HTTP request metadata and application request/response data passing through the hosting layer; no intended persistent Customer Data storage as part of normal application operation | Primary deployment configured for the United States; Vercel network/edge infrastructure may be globally distributed |
| Cloudflare | Off-site backup and disaster-recovery storage (Cloudflare R2) | Encrypted backup copies of application database content and stored files; retained up to 7 days on a rolling basis and used solely for disaster recovery | Breachday-designated storage configuration; Cloudflare network and infrastructure are globally distributed |
| Stripe | Payment processing, subscription billing, customer portal | Billing contact information, invoices, subscription records, payment-method tokens, and payment card data held by Stripe; Breachday stores limited Stripe identifiers and subscription status | United States and other locations used by Stripe under its global infrastructure and legal terms |
| Resend | Transactional email delivery | Recipient email addresses and transactional message content, including verification, password reset, invitations, support notifications, payment notices, renewal/lifecycle notices, and deletion warnings | Provider infrastructure locations applicable to the email delivery service |
| OpenRouter | AI model routing for AI Scenario Builder and Weekly Scenario Recommendations | AI Scenario Builder prompt and response content is routed only to ZDR-eligible provider endpoints under Breachday configuration; OpenRouter may retain non-content request metadata. Weekly Scenario Recommendations use public threat-intelligence headlines and internal template metadata. | OpenRouter and eligible inference-provider processing locations may vary by endpoint unless Breachday uses a region-specific routing option |
AI privacy note: ZDR governs provider-side persistence of prompt and response content; it does not prevent transient inference processing or establish processing location. Other enabled tools and Breachday application logs are outside OpenRouter ZDR. Breachday does not intentionally log AI prompt or response content for model training.
What Is Not a Subprocessor
Exercise Participants and Customer-controlled downloaded exports are not Breachday subprocessors. Third-party services independently chosen by Customer are not Breachday subprocessors unless Breachday engages them to Process Customer Personal Data on Breachday's behalf.
Security and Contracts
Breachday requires subprocessors to operate under contracts or terms imposing privacy, confidentiality, and security obligations appropriate to their processing and remains responsible to the extent required by the DPA and applicable law. Privacy and security inquiries: compliance@breachday.io.