Trust

Subprocessors

The third-party services dvt relies on to operate the product, what each one processes, and where. Because queries run in your warehouse, none of these services receive your warehouse's data rows or values.

Service Purpose Data processed Region
WorkOS Authentication & identity (sign-in, organizations, directory) Names, email addresses, organization & membership metadata United States
Neon Metadata database (dashboard specs, accounts, roles, audit logs, encrypted credentials) Account metadata and dashboard specs; warehouse credentials as ciphertext; opt-in warehouse catalog structure (names/types/comments only, never data rows or values). United States
Fly.io Application & query-engine hosting (compute) Data in transit during a request; nothing persisted to disk by dvt United States
Cloudflare CDN, DNS, website hosting, and encrypted object storage (R2) for dashboard exports and trial CSV uploads Website traffic; PNG/PDF export artifacts (encrypted, auto-deleted within 30 days); trial CSV uploads (encrypted Parquet, organization-scoped, deleted by an automated job after the trial ends) Global edge (exports & uploads: eastern North America)
Resend Transactional email (sign-in and product notifications) Email addresses and message content United States
Sentry Error tracking (application errors across our services) Diagnostic/error events — may include user IDs, request context, and stack traces United States
Axiom Application logs Application logs and request metadata — may include user/organization IDs United States

This list is kept current as our infrastructure evolves. For a data processing agreement (DPA) or advance notice of subprocessor changes, email [email protected]. See also our security overview.