Sub-processors
Everyone who processes data on Maskbreak's behalf, what they do, and where they sit. New sub-processors that process customer data are announced at least 30 days in advance, with right to object — the change log below is the public record.
Last updated 19 July 2026 · maintained by Sentinel Edge Networks LTD
Current sub-processors
| Provider | Purpose | Data touched |
|---|---|---|
| Cloudflare | CDN, TLS termination, edge caching, first-pass scanner verdict at the edge | Request metadata (IP, headers) in transit |
| Railway | Application hosting | All application traffic and data in transit |
| Turso | Primary database (managed libSQL), encrypted at rest | Account data, hashed lookup records |
| Resend | Transactional email (verification, notices) | Email address, message content |
| Upstash | Durable rate-limit state (Redis) for authentication and abuse-sensitive endpoints | Client IP addresses as short-TTL rate-limit keys — no account data |
| Amazon Web Services (S3) | Encrypted nightly database backups for disaster recovery — EU Stockholm region (eu-north-1) | Full encrypted database snapshots, 60-day rolling retention |
| Sign-In only (OAuth) — no analytics, no advertising | OAuth identity assertion | |
| GitHub | Sign-In only (OAuth) — no analytics, no advertising | OAuth identity assertion |
| Have I Been Pwned | Password breach check via k-anonymity | 5-character SHA-1 prefix only — never the password |
| Network & device intelligence providers | VPN/proxy classification and device-integrity signals for evaluations | Request network metadata; named to customers under DPA |
Fonts are self-hosted. There are no advertising or analytics providers on this list because there are none — see the Privacy Policy and Cookie Policy for the full data-handling picture.
Change log
| Date | Change |
|---|---|
| 2026-08-02 | Added and removed Dreamdata (business-to-business marketing attribution) on the same day. It was live on public marketing pages for approximately 30 minutes. During that window its account-level component sent page URL, page title, canonical URL, referring URL and the requesting IP address to Dreamdata, which uses them to estimate the organisation a visit came from. Its visitor-level component was gated behind analytics consent, which this site does not grant — with one exception we want to be explicit about: the gate is read from Google’s consent framework, so a visitor whose browser blocked Google Tag Manager would have had the visitor-level component, including form tracking, initialise normally. It never ran on the console or on any signed-in page, and it received no customer API or evaluation data at any point. It has been fully removed; no Dreamdata code, endpoint or Content-Security-Policy entry remains. Recorded here for completeness rather than because any obligation attaches to a provider that is no longer used. |
| 2026-07-19 | Added GitHub (Sign-In only, OAuth) — an optional “Sign in with GitHub” for Maskbreak accounts. It touches only the account holder’s own OAuth identity assertion, never customer end-user evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §3 were updated in the same change. |
| 2026-07-18 | Added Upstash (rate-limit state) and Amazon Web Services / S3 (encrypted nightly backups). Both were already live infrastructure — this is a completeness correction to the published list, not a new-processor onboarding, so the 30-day advance-notice clause does not apply. Privacy Policy §5 and the security whitepaper were updated in the same change. |
| 2026-07-16 | Page published. List matches the sub-processors already disclosed in the Privacy Policy — no additions or removals. |
Getting notified
Enterprise customers under a signed DPA receive direct notification of sub-processor changes. Everyone else can watch this page or the changelog — any change lands in both at least 30 days before a new data-processing sub-processor goes live.
Questions or objections: [email protected].